What you receive
A record of reviewed devices and controls, identified gaps and prioritised recommendations.
A record of reviewed devices and controls, identified gaps and prioritised recommendations.
Your IT team or MSP provides fleet evidence and implements configuration changes.
A further review of changes is arranged separately; sampling limits remain explicit.
A clearly defined scope. A review covers only the devices, evidence and settings in the agreed scope. It is not incident response, continuous device monitoring or a certification assessment.
For examining laptop and mobile protection, including encryption, locking, updates and loss. A vulnerability scan answers a different question about known technical weaknesses. Explore vulnerability scanning.
We’ll agree a written proposal and obtain authorisation before the assessment begins.
A device security review is an endpoint configuration assessment of the protection applied to business laptops and mobile devices. It helps establish whether the settings and practices protecting business information need attention.
Review encryption and screen-lock settings on the agreed devices or representative sample.
Examine update practices and relevant device protection settings against the objectives agreed for the review.
Review the controls and processes intended to protect information when a device is lost or stolen.
A written policy describes the intended protection. Device evidence shows what is applied on the reviewed laptops and mobiles. Compare both, and retain the device identifier and observation date so findings can be followed up.
| Control | Evidence to examine | Question to resolve |
|---|---|---|
| Encryption | Encryption status for the device and the organisation’s recovery arrangements. | Is storage protection active, and can authorised staff recover access when needed? |
| Screen locking | Applied lock settings and relevant management-policy records. | Does the device enforce the intended locking behaviour, including any exceptions? |
| Updates | Installed versions, update status and recent management check-in information. | Is the device receiving updates, or is an apparently compliant record stale? |
| Lost-device protection | Ownership, management enrolment and the process for reporting and responding to loss. | Who can take protective action, and what depends on the device reconnecting? |
Prepare a fleet list grouped by device type, operating-system version, ownership and management approach. This helps determine compatibility and a representative sample without assuming that one reviewed device proves the state of every operating system or configuration in use. Local administrator rights, firewalls, secure boot and endpoint-protection settings should be named explicitly if you need them assessed; they are not assumed to be included.
Understand differences across device types and management arrangements after recruitment, an acquisition or a change of IT provider.
Review protection on the devices staff rely on away from the office, including encryption, screen locks and lost-device considerations.
Give your IT team a basis for prioritising configuration changes, update work and device replacement. A review informs decisions; benefits depend on implementing the changes.
Review whether encryption and locking settings match the agreed requirements. These controls address different situations: a screen lock limits casual access to an active session, while storage encryption protects stored data when the relevant keys are unavailable, for example on a correctly configured powered-off device. Disconnecting a device from the network does not lock an active session.
Identify inconsistencies in the update evidence available for the devices reviewed. A centrally defined policy is useful, but your team also needs to know whether devices are receiving and applying it, particularly for remote or infrequently connected users.
Review the agreed arrangements for reporting loss and protecting business information. Device ownership, management capability and connectivity affect the actions available; remote wiping should not be treated as a substitute for protection already on the device.
Use findings about unsupported software or inconsistent protection to inform replacement priorities. This helps distinguish devices that need a configuration change from those that no longer fit the organisation’s requirements.
Document the reviewed fleet, management approach and outstanding gaps when changing IT providers or taking on an MSP client. Clear ownership makes it easier to agree which team will address each recommendation.
A practical action list helps your IT team standardise settings across the reviewed device groups. Plan changes around users and business applications so improvements can be introduced with appropriate support.
Agree device types, operating systems, ownership and whether the review covers every device or a sample. Record exclusions and the limits of sampling.
Confirm access and the configuration records needed. Use approved channels for sharing information and identify any restrictions concerning personal devices.
Examine the agreed encryption, locking, update and lost-device controls. Consider differences between centrally managed and individually configured devices.
Review identified gaps with your IT team or MSP. Assign owners and consider the impact of configuration changes on users and business applications.
Keep records of changes and agree any follow-up review separately. Review coverage again when the fleet or management approach changes.

Work is authorised in writing before any assessment begins, and stays within the agreed scope.
Related services answer different questions. Confirm which scope you are buying before you compare quotes.
| Approach | What it tells you | Scope to confirm |
|---|---|---|
| Device security review | Examines agreed laptop and mobile protection settings and supporting evidence. | Coverage may be a fleet or a sample; the report needs to state which. |
| Vulnerability scanning | Checks agreed systems for known, detectable vulnerabilities. | A scan does not by itself review lost-device procedures or fleet management practices. |
| Endpoint protection and monitoring | Provides operational prevention or detection according to the product and service deployed. | A separate ongoing capability; buying a review does not install or operate endpoint protection. |
Illustrative example, not a client case study
This is a teaching example of a finding record, not an extract from a customer report or a promise of a particular report template.
Fleet size, operating-system variety, management tools, the sample design and evidence availability affect the quote. Include personal-device requirements and any separate follow-up review in the discussion. A sample review and a full-fleet review provide different coverage.
Bring a device inventory, operating-system list, ownership model and overview of how settings are managed. Identify remote users, older devices and business applications that may constrain changes. Agree what evidence can be shared without collecting unnecessary personal information.
Allow for access preparation, the assessment, report delivery and your team’s remediation work. Confirm the delivery format, dates and any follow-up checks in your quote so each team knows when its input is needed.

Practical answers about scope, cost and what happens next.
Compare all six security servicesA device security review is an endpoint configuration assessment of the protection applied to business laptops and mobile devices. It helps establish whether the settings and practices protecting business information need attention.
Link to this answerThat depends on your objectives and how consistently devices are managed. We agree whether the review covers the full fleet or a sample, and make any sampling limits clear in the scope and findings.
Link to this answerPotentially, where appropriate permissions and practical access arrangements can be agreed. Identify ownership, privacy constraints and business use during scoping; personal devices are not assumed to be included.
Link to this answerNo. This is a scoped review, not continuous monitoring, software deployment or incident response. We can discuss the wider Fig platform separately where ongoing oversight is needed.
Link to this answerDo not assume remediation is included. We agree the review activities in advance; your IT team or MSP remains responsible for implementing changes unless separate support is expressly agreed.
Link to this answerNo. Antivirus or endpoint protection addresses only part of device security. Encryption, locking, updates and management arrangements still matter. A device review examines the agreed controls and available evidence; it does not guarantee that a device is free of compromise.
Link to this answerA sample can reveal issues in the devices and configuration groups reviewed. It cannot establish the state of every unreviewed device. Agree how the sample represents your fleet and expand the investigation if the findings suggest inconsistent management or wider gaps.
Link to this answerFleet size, operating-system variety, management tools, the sample design and evidence availability affect the quote. Include personal-device requirements and any separate follow-up review in the discussion. A sample review and a full-fleet review provide different coverage.
Link to this answerNo. Security testing and reviews can help identify gaps, but certification requires a separate assessment under the relevant scheme. Buying this service does not guarantee certification.
Link to this answerExplore a different assessment, manage remediation or prepare for certification.
Related service
Review AWS, Azure or Google Cloud configurations, including access permissions, exposed storage, account protection and logging.
ExploreRelated service
Automated checks of agreed websites and systems for known weaknesses, helping you prioritise what needs attention.
ExploreSoftware
Manage compliance gaps, remediation and supporting evidence.
ExploreCertification
Explore certification options for your organisation.
ExploreIndependent sources that explain the methods and controls behind the review.
Independent guidance
Guidance on maintaining device security, software updates and obsolete products.
Work with Fig directly or through your MSP. Your proposal identifies the contracting entity, assessment scope and delivery responsibilities.
The companies
See the entities, licences and people behind the platform and our assessments.
ExploreMSP partners
Offer these services under your own brand and retain the client relationship.
ExplorePublished evidence
Verify our company details, licences and the claims we make in public.
ExploreContent updated .
Tell us what you need from device security reviews, the systems involved and any deadline. We’ll discuss the options and provide a quote.