Skip to content
For UK businesses and MSPs

Device security reviews
Confidence in every laptop and mobile.

Fig reviews laptop and mobile-device encryption, screen locks, updates and lost-device protection. You receive a record of the devices and controls examined, identified gaps and prioritised recommendations for your IT team or MSP.

At a glance

Your engagement at a glance

What you receive

A record of reviewed devices and controls, identified gaps and prioritised recommendations.

Your team’s part

Your IT team or MSP provides fleet evidence and implements configuration changes.

Follow-up arrangements

A further review of changes is arranged separately; sampling limits remain explicit.

A clearly defined scope. A review covers only the devices, evidence and settings in the agreed scope. It is not incident response, continuous device monitoring or a certification assessment.

For examining laptop and mobile protection, including encryption, locking, updates and loss. A vulnerability scan answers a different question about known technical weaknesses. Explore vulnerability scanning.

Start with a scope discussion

We’ll agree a written proposal and obtain authorisation before the assessment begins.

Request a device review
The scope

What do Fig device security reviews cover?

A device security review is an endpoint configuration assessment of the protection applied to business laptops and mobile devices. It helps establish whether the settings and practices protecting business information need attention.

Protection at rest

Review encryption and screen-lock settings on the agreed devices or representative sample.

Updates and configuration

Examine update practices and relevant device protection settings against the objectives agreed for the review.

Lost-device risks

Review the controls and processes intended to protect information when a device is lost or stolen.

Assessment detail

What evidence shows that device protection is working?

A written policy describes the intended protection. Device evidence shows what is applied on the reviewed laptops and mobiles. Compare both, and retain the device identifier and observation date so findings can be followed up.

Examples of useful device protection evidence
ControlEvidence to examineQuestion to resolve
EncryptionEncryption status for the device and the organisation’s recovery arrangements.Is storage protection active, and can authorised staff recover access when needed?
Screen lockingApplied lock settings and relevant management-policy records.Does the device enforce the intended locking behaviour, including any exceptions?
UpdatesInstalled versions, update status and recent management check-in information.Is the device receiving updates, or is an apparently compliant record stale?
Lost-device protectionOwnership, management enrolment and the process for reporting and responding to loss.Who can take protective action, and what depends on the device reconnecting?

Prepare a fleet list grouped by device type, operating-system version, ownership and management approach. This helps determine compatibility and a representative sample without assuming that one reviewed device proves the state of every operating system or configuration in use. Local administrator rights, firewalls, secure boot and endpoint-protection settings should be named explicitly if you need them assessed; they are not assumed to be included.

When to book

When to book device security reviews

Review a growing or inherited fleet

Understand differences across device types and management arrangements after recruitment, an acquisition or a change of IT provider.

Support remote working

Review protection on the devices staff rely on away from the office, including encryption, screen locks and lost-device considerations.

Plan practical improvements

Give your IT team a basis for prioritising configuration changes, update work and device replacement. A review informs decisions; benefits depend on implementing the changes.

Security benefits

Security benefits of device security reviews

Check protection of information on devices

Review whether encryption and locking settings match the agreed requirements. These controls address different situations: a screen lock limits casual access to an active session, while storage encryption protects stored data when the relevant keys are unavailable, for example on a correctly configured powered-off device. Disconnecting a device from the network does not lock an active session.

Find gaps in update coverage

Identify inconsistencies in the update evidence available for the devices reviewed. A centrally defined policy is useful, but your team also needs to know whether devices are receiving and applying it, particularly for remote or infrequently connected users.

Understand lost-device readiness

Review the agreed arrangements for reporting loss and protecting business information. Device ownership, management capability and connectivity affect the actions available; remote wiping should not be treated as a substitute for protection already on the device.

Commercial value

The commercial value for your organisation

Plan device replacement with evidence

Use findings about unsupported software or inconsistent protection to inform replacement priorities. This helps distinguish devices that need a configuration change from those that no longer fit the organisation’s requirements.

Make IT handovers more precise

Document the reviewed fleet, management approach and outstanding gaps when changing IT providers or taking on an MSP client. Clear ownership makes it easier to agree which team will address each recommendation.

Support consistent working practices

A practical action list helps your IT team standardise settings across the reviewed device groups. Plan changes around users and business applications so improvements can be introduced with appropriate support.

How it works

Your device security reviews engagement

  1. Define the fleet

    Agree device types, operating systems, ownership and whether the review covers every device or a sample. Record exclusions and the limits of sampling.

  2. Agree the evidence

    Confirm access and the configuration records needed. Use approved channels for sharing information and identify any restrictions concerning personal devices.

  3. Review protection

    Examine the agreed encryption, locking, update and lost-device controls. Consider differences between centrally managed and individually configured devices.

  4. Prioritise changes

    Review identified gaps with your IT team or MSP. Assign owners and consider the impact of configuration changes on users and business applications.

  5. Plan verification

    Keep records of changes and agree any follow-up review separately. Review coverage again when the fleet or management approach changes.

A phone and laptop on a working desk

Work is authorised in writing before any assessment begins, and stays within the agreed scope.

Compare approaches

Device review, vulnerability scan or endpoint protection?

Related services answer different questions. Confirm which scope you are buying before you compare quotes.

Compare the purpose and scope of related approaches
ApproachWhat it tells youScope to confirm
Device security reviewExamines agreed laptop and mobile protection settings and supporting evidence.Coverage may be a fleet or a sample; the report needs to state which.
Vulnerability scanningChecks agreed systems for known, detectable vulnerabilities.A scan does not by itself review lost-device procedures or fleet management practices.
Endpoint protection and monitoringProvides operational prevention or detection according to the product and service deployed.A separate ongoing capability; buying a review does not install or operate endpoint protection.

Illustrative example, not a client case study

The management policy and device evidence disagree

How to read a finding: evidence, decision and next action
Scope
A representative group of centrally managed laptops used by remote staff.
Intended policy
Storage encryption should be enabled on each device in this group.
Observed evidence
One sampled device has stale management check-in information, so its current encryption state cannot be confirmed. This is an evidence gap, not proof that encryption is disabled.
Owner and action
The IT owner checks enrolment, policy assignment and current device state, verifies recovery arrangements and records any exception owner.
Follow-through
Keep refreshed evidence and the observation date. Investigate the wider device group if inconsistent management is suspected; do not extrapolate a sample to every device.

This is a teaching example of a finding record, not an extract from a customer report or a promise of a particular report template.

Cost and preparation

What affects the scope and cost?

Fleet size, operating-system variety, management tools, the sample design and evidence availability affect the quote. Include personal-device requirements and any separate follow-up review in the discussion. A sample review and a full-fleet review provide different coverage.

What to prepare for your enquiry

Bring a device inventory, operating-system list, ownership model and overview of how settings are managed. Identify remote users, older devices and business applications that may constrain changes. Agree what evidence can be shared without collecting unnecessary personal information.

Plan the engagement around your deadline

Allow for access preparation, the assessment, report delivery and your team’s remediation work. Confirm the delivery format, dates and any follow-up checks in your quote so each team knows when its input is needed.

A person planning an engagement with a notebook and laptop
Questions

Device security reviews questions

Practical answers about scope, cost and what happens next.

Compare all six security services
What are device security reviews?

A device security review is an endpoint configuration assessment of the protection applied to business laptops and mobile devices. It helps establish whether the settings and practices protecting business information need attention.

Link to this answer
Do you need to review every device?

That depends on your objectives and how consistently devices are managed. We agree whether the review covers the full fleet or a sample, and make any sampling limits clear in the scope and findings.

Link to this answer
Can the review include personally owned devices?

Potentially, where appropriate permissions and practical access arrangements can be agreed. Identify ownership, privacy constraints and business use during scoping; personal devices are not assumed to be included.

Link to this answer
Is this a managed endpoint protection service?

No. This is a scoped review, not continuous monitoring, software deployment or incident response. We can discuss the wider Fig platform separately where ongoing oversight is needed.

Link to this answer
Will you change device settings during the review?

Do not assume remediation is included. We agree the review activities in advance; your IT team or MSP remains responsible for implementing changes unless separate support is expressly agreed.

Link to this answer
Does installing antivirus mean a device is secure?

No. Antivirus or endpoint protection addresses only part of device security. Encryption, locking, updates and management arrangements still matter. A device review examines the agreed controls and available evidence; it does not guarantee that a device is free of compromise.

Link to this answer
What can a sample review tell us about the whole fleet?

A sample can reveal issues in the devices and configuration groups reviewed. It cannot establish the state of every unreviewed device. Agree how the sample represents your fleet and expand the investigation if the findings suggest inconsistent management or wider gaps.

Link to this answer
How much do device security reviews cost?

Fleet size, operating-system variety, management tools, the sample design and evidence availability affect the quote. Include personal-device requirements and any separate follow-up review in the discussion. A sample review and a full-fleet review provide different coverage.

Link to this answer
Does this service provide compliance certification?

No. Security testing and reviews can help identify gaps, but certification requires a separate assessment under the relevant scheme. Buying this service does not guarantee certification.

Link to this answer
Your next step

Choose the support you need.

Explore a different assessment, manage remediation or prepare for certification.

Related service

Cloud security reviews

Review AWS, Azure or Google Cloud configurations, including access permissions, exposed storage, account protection and logging.

Explore

Related service

Vulnerability scanning

Automated checks of agreed websites and systems for known weaknesses, helping you prioritise what needs attention.

Explore

Software

The Fig platform

Manage compliance gaps, remediation and supporting evidence.

Explore

Certification

Cyber Essentials

Explore certification options for your organisation.

Explore
Further reading

Further technical guidance

Independent sources that explain the methods and controls behind the review.

Accountability

Working with Fig

Work with Fig directly or through your MSP. Your proposal identifies the contracting entity, assessment scope and delivery responsibilities.

The companies

Meet the companies behind Fig

See the entities, licences and people behind the platform and our assessments.

Explore

MSP partners

Security services for MSP partners

Offer these services under your own brand and retain the client relationship.

Explore

Published evidence

Company details and published evidence

Verify our company details, licences and the claims we make in public.

Explore

Let’s agree the right scope.

Tell us what you need from device security reviews, the systems involved and any deadline. We’ll discuss the options and provide a quote.

Request a device review