C://SECURE31Endpoint Security
Every device,
accounted for.
Endpoint security covers protection, patching, encryption, and configuration on every laptop, desktop, and mobile device your organisation uses. It is for organisations whose devices are protected inconsistently, which usually means whichever ones IT set up personally.
THE PROBLEM
It only takes one unpatched, unencrypted, unmanaged laptop. An attacker only has to find it once.
The cost of leaving this alone is rarely one visible failure. It is the slow accumulation: the workaround that became the process, the thing only one person knows, the renewal nobody questioned.
Our starting point is always the same: establish what is actually true today, then decide what to change. Work scoped against an assumption tends to solve a problem you do not have.
- 01Nobody owns itIt sits with whoever touched it last, which is not the same as being managed.
- 02No current pictureWhat you have, what it costs, and who has access are all slightly out of date.
- 03Only handled when it breaksAttention arrives after the disruption rather than before it.
WHAT YOU GET
What the engagement covers
Scoped before it starts, so you know what is included and what is not.
- 01
Managed protection
Endpoint detection and response deployed everywhere and actually monitored, rather than installed once and forgotten about.
- 02
Patching
Operating system and third-party applications updated on a schedule, with compliance reported so you can see which machines are behind and why.
- 03
Encryption
Full-disk encryption enforced and its status evidenced. It is the control that turns a laptop left in a taxi into an inconvenience rather than a notifiable privacy breach.
- 04
Configuration baseline
One agreed build applied to every device, so exceptions are visible instead of accumulating quietly.
HOW WE WORK
Baseline, remediate, monitor, evidence
Four stages with a written output at each one. You always know which stage you are in and what comes next.
- 01Week 1
Baseline
What is configured today, measured against a recognised standard, with gaps ranked by real-world risk rather than vendor score.
- 02Weeks 2 – 6
Remediate
Gaps closed in the order that buys the most safety fastest, with each change recorded.
- 03Ongoing
Monitor
Tuned to your environment so alerts mean something, and every alert has a named owner.
- 04Quarterly
Evidence
A written report you can hand to an insurer, a customer, or your board without translating it first.
WHAT CHANGES
What you should expect
- Someone other than you owns it, with that written down.
- The current state is documented and stays documented.
- Cost is planned ahead rather than discovered at renewal.
- Decisions are made against evidence rather than assumption.
FAQ
Questions we get asked
01What is endpoint security?
Endpoint security covers protection, patching, encryption, and configuration on every laptop, desktop, and mobile device your organisation uses. It is for organisations whose devices are protected inconsistently, which usually means whichever ones IT set up personally.
02Is the antivirus built into Windows good enough?
Microsoft Defender is genuinely capable and, properly configured and managed centrally, it is a reasonable foundation. The gap is not the software, it is that nobody is watching it. An alert on a laptop at nine on a Friday night is only useful if a person sees it. That is the difference between antivirus and managed detection and response, and it is the difference that matters.
03What is EDR, and how is it different from antivirus?
Traditional antivirus compares files against a list of known bad ones. Endpoint detection and response watches behaviour instead, so it notices a legitimate program being used in an illegitimate way, which is how most modern attacks work. It also records what happened, so after an incident you can establish what was reached rather than guessing. The trade-off is that it produces alerts somebody has to triage.
04How quickly should security patches be applied?
Critical and actively exploited vulnerabilities within a couple of weeks at the outside, and many frameworks now ask for forty-eight hours on internet-facing systems. The more useful question is whether you can prove it happened. Most organisations patch reasonably well and cannot produce evidence, which becomes a problem the moment an insurer or a customer asks.
05What happens if a staff laptop is lost or stolen?
With full-disk encryption and device management, you remotely wipe it, revoke the sessions, and treat it as a hardware loss. Without encryption, you have to assume everything on it is readable by whoever has it, which under the Privacy Act 2020 may be a notifiable breach if it held personal information. The control costs nothing beyond configuring it, and it is switched off more often than you would expect.
06Do we need to manage staff personal phones?
You need to manage the work data on them, which is not the same thing. App-level policies protect company email and files in a container that can be wiped on its own, with no visibility of anything personal. Staff generally accept this once it is explained, because the alternative they usually imagine is you being able to see their photographs.
07How much does endpoint security cost in New Zealand?
We quote after scoping rather than before. Anyone pricing this work without looking at your environment is guessing, and the guess is rarely in your favour. Scoping itself is quick, and we tell you what it costs before we start it.
08How long does it take to get started with endpoint security?
A first conversation takes about half an hour and costs nothing. Scoping is usually a week or two of our time depending on the size of the environment, and we agree the delivery dates with you before anything is booked in.
09Can you deliver endpoint security alongside our existing IT team or provider?
Yes, and it is common. We are happy to work as an extra pair of hands under your internal team, or alongside an incumbent provider on a defined piece of work. We will set out in writing where the responsibilities split, so nothing falls between us.
10Do we have to move our whole IT contract to Atlas?
No. This can be delivered as a standalone piece of work for an organisation we have never worked with before, or folded into a managed agreement if you already have one with us. Plenty of clients use us for one thing and keep everything else where it is.
11Can you support us if we are not based in Auckland?
Our team is based in Auckland and we attend sites across the wider region. Most of this work is delivered remotely, so we support organisations throughout New Zealand, and we will say up front where being on site genuinely matters.
12Who will we be dealing with when something actually happens?
Named people, not a queue. You get a lead who knows your environment and stays with it, which is the difference between explaining your business once and explaining it every time you make contact.
13What happens after it is in place?
You keep the documentation regardless, and anything registered in your name stays in your name. Whether we stay involved is your call. Some clients take it in house from there, others move it onto an ongoing agreement with us. We would rather you left cleanly than stayed because leaving was difficult.
Start with a conversation.
Tell us what you are dealing with and we will tell you whether this is the right service for it, and what it would take.
← All services