Skip to content
0800 374 775

The device fleet nobody owns

Nobody knows how many laptops the business has, which ones are encrypted, or who has the tablet that was in the ute. That is not carelessness. It is what happens when devices are bought as expenses rather than managed as an estate.

Ask a business of forty people how many computers it has and you will usually get a range rather than a number. Ask which of them are encrypted, patched and able to be wiped remotely, and the range gets wider.

This is one of the most common gaps we find, and it is rarely anyone’s fault. Devices get bought one at a time, when someone needs one, out of whatever budget is nearest. Each purchase is a small decision. The result of five years of small decisions is an estate nobody designed.

Why it matters more than it looks

A lost device is a data incident or it is not, and the difference is configuration. An encrypted laptop left in a car is an insurance claim for a laptop. An unencrypted one holding client files is a privacy matter, potentially a notifiable one. Same event, entirely different consequence, decided months earlier by whether disk encryption was turned on and recorded.

You cannot patch what is not enrolled. Patch compliance reported as a percentage of known devices is meaningless if the denominator is wrong. The machines that are not in the console are the ones running last year’s browser.

Onboarding cost compounds. Setting up a new starter’s machine by hand takes hours, and produces a slightly different configuration each time. Multiply that by turnover.

Leavers keep working devices. Without an estate register there is no reliable list of what a departing person had, so the phone or tablet quietly stays in a drawer, still signed in.

What “managed as an estate” actually means

It is less than people fear. Four things.

A register that is generated, not maintained. A spreadsheet of assets is out of date the day after it is written. The device management platform should be the register, because it knows what actually checked in this week. If it is not in there, it does not exist as far as the business is concerned, and that is a useful rule.

Enrolment before the device reaches the user. Modern hardware can be shipped to a staff member, and configure itself against your tenancy on first boot: policies, applications, encryption, the lot. This is the single change that most improves both security posture and onboarding time, and it removes the build-by-hand variance entirely.

A baseline, applied to everything. Encryption on, screen lock, patching schedule, endpoint protection, no local administrator for ordinary users. Written down once and enforced by policy rather than by good intentions.

A remote wipe you have tested. On a device you do not mind wiping, before you need it on a device you do.

The standardisation argument

There is a temptation to let everyone choose their own hardware. It is a nice gesture and it is expensive in ways that do not appear on the purchase order: every model has its own driver quirks, its own spare parts, its own failure modes, and its own support conversation.

A short standard list, two or three models covering the roles you have, makes support faster, spares practical, and replacement a decision nobody has to think about. Field roles are the exception worth making deliberately, because a rugged device for someone on a wharf or a site is not a preference, it is fitness for purpose.

Where to start if none of this exists

Get the count. Enrol everything you can find. Apply a baseline. Accept that you will discover two or three machines nobody remembered, and that one of them is doing something important.

Then buy the next device already enrolled, and the problem stops growing.

Next step

Recognise any of this? Let's talk.

We respond within one business day.