Fortify 24x7 stands behind this storefront. Controls presented, worked, and reconciled entry by entry.Open your recordWrite to an engineer
FinShield Tech
Session 04 / The device book

Three lists of your hardware, and none of them agree.

Most practices carry a device count in the payroll system, a second one in whichever tool got installed last, and a third that exists only in somebody's head. These four entries replace all three with one book: the hardware that exists, the condition each item is in, and whatever has gone silent.

N-able N-sightAddigyZimperiumOne reconciled list
4 entries / Windows, Apple, handsets / counted, current, filtered
Entries here4
Carried onAddigy and Zimperium alongside N-able N-sight
Rate basisPer machine, per Apple device, per handset
DeskAnswered around the clock

Counting comes before controlling

Every control in this book is priced against a unit, so each of them rests on the practice knowing how many units exist. That figure is usually wrong, and wrong in the same direction every time: the machine bought in a rush, the laptop that went home with a leaver, the handset added to the mail tenant without a word to anybody.

N-able N-sight produces the figure and then keeps it honest, because hardware that stops checking in turns into an item on a list rather than a silent absence. Addigy does the equivalent for Apple hardware, which behaves differently enough to deserve tooling of its own instead of a checkbox.

A device that stops reporting becomes an item on a list, instead of a silent absence.

Patching, filtering, and the handset nobody tallied

Patching is unglamorous and it is where most of the difference gets made. The entry schedules it, applies it, and then confirms it, and confirmation is the part that counts, because a patch policy nobody verifies is a document rather than a control.

The filtering rides the agent already there, which is how a control leaves the building inside a laptop bag. The mobile entry covers whatever your staff read client mail on, which is an endpoint whoever bought it and whatever any policy says about it.

Entries in this session

Entry specifications

Billing hands over every figure below at page load. Present while you read; a quantity stands until you alter it.

Fortify-RMMEntry

Remote Monitoring and Management

N-able N-sight, one agent doing several jobs

Patching, health, inventory, scripting, and remote hands carried on one agent. A machine nobody observes is a machine nobody can honestly describe as patched.

  • Operating system patching and third party patching, scheduled then confirmed.
  • Hardware and software inventory answering what the practice actually owns.
  • Remote support that does not begin with reading a serial number aloud.
Settles onN-able N-sight agent, installed once per machine
NetsOne managed device, observation and patching on one unit
Value dateInventory lands the day the agent enrolls
Cleared byThe patch schedule is held by Fortify 24x7 engineers
Reconciled byPatch and inventory reporting, dated per device
Reading the rateper managed device
settled monthly, in advance
QTY
Fortify-RMM-DNSEntry

Web and DNS Filtering

N-able N-sight filtering, riding the same agent

Resolution and web requests are filtered at the device, which is why the control goes home in the bag instead of halting at your office door. Nothing needs racking.

  • Category and reputation filtering, holding up on home broadband and in hotels.
  • A request aimed at a destination already known bad is refused before any connection opens.
  • Per device request and bandwidth records, which is how a refusal gets evidenced.
Settles onN-able N-sight agent with filtering enabled
NetsOne managed device, on your network or well away from it
Value dateApplies from the first policy push onward
Cleared byCategory policy is held by Fortify 24x7 engineers
Reconciled byRequest and refusal records, device by device
Reading the rateper managed device
settled monthly, in advance
QTY
Fortify-ControlEntry

Apple Fleet Management

Addigy holding the Apple estate to a written profile

Apple hardware managed rather than taken on trust. Configuration is enforced, updates are scheduled, and a device is either compliant or it is named on a list.

  • Enrollment, configuration profiles, and update scheduling across Mac and iOS.
  • FileVault state and recovery keys held somewhere you can actually reach.
  • Compliance checks that name a device instead of quoting a percentage.
Settles onAddigy, one enrollment for each Apple device
NetsOne Apple device, configuration and updates on one unit
Value dateApplies at the first enrollment check in
Cleared byConfiguration is held by Fortify 24x7 engineers
Reconciled byPer device compliance state, carrying a date
Reading the rateper Apple device
settled monthly, in advance
QTY
Fortify-MobileEntry

Mobile Threat Defense

Zimperium, living on the phone

Whoever paid for it, a phone that client mail gets read on is an endpoint. This entry runs detection on the handset instead of trusting the platform to have covered it.

  • On device detection of hostile apps, network attacks, and unwanted profiles.
  • Runs across iOS and Android, and keeps deciding with nothing to connect to.
  • Findings arrive at the desk everything else arrives at, not a console of its own.
Settles onZimperium, one app for each handset
NetsOne mobile device, practice owned or personal
Value dateOpens when the handset activates the app
Cleared byHandset findings are read by Fortify 24x7 analysts
Reconciled byHandset findings, filed with the rest of your record
Reading the rateper mobile device
settled monthly, in advance
QTY
Unmatched items

What this session does not settle

The device book tells you what exists and holds it in a known condition. What it will not do:

  • Hardware is not ours to buy or own. Procurement, warranty, leasing, and disposal stay with the practice. Where a machine has aged past patching we will say so. Replacing it is not our job.
  • Patching is not a promise about vulnerabilities. A patch must exist before it can be applied, and plenty of software has none. Reporting names which machines are behind and why, which is the honest form of the claim.
  • Filtering works on categories. Destinations are refused on category and on reputation. Intent cannot be read, and a determined person on a network of their own will get around it.
  • Personal devices need a decision, not a tool. Whether staff may read client mail on a handset the practice does not manage is a policy question. We can enforce whichever answer you choose. Choosing is not something we can do for you.
  • Managing a device is not copying it. None of these four entries keeps a copy of anything at all. That is another session and another line on the invoice.
TICK 01

Heads up: card statements show FORTIFY 24X7 - FinShield Tech is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.