A Fortify 24x7 brand. Security controls built for firms the Safeguards Rule applies to.Account sign inAsk an engineer
Equity IT Solutions
Register 04 / Device oversight

An estate nobody has counted cannot be defended by anybody.

Every information security program opens with an asset list, and at almost every small practice that list is a spreadsheet somebody quietly stopped updating in 2023. These entries replace it with a record that maintains itself: which hardware exists, who carries it, what build it runs, what updated overnight, and what has failed to report for nineteen days.

N-able N-sightAddigyZimperium
An asset record that stays true / 4 entries / Windows, Apple, handsets
Entries here4
UnderneathN-able N-sight, Addigy, Zimperium
Billed againstEach managed device
ReachesWindows, macOS, iOS, Android

The asset record is the actual deliverable

Updating attracts the attention, but the record underneath is what a programme runs on. Without it a risk assessment is invention, disposal cannot be evidenced, and nobody at the practice can answer the plainest question an examiner asks, namely how much hardware holds client information and where each piece of it sits.

N-able N-sight assembles that record from the agent instead of from memory. Hardware, build, installed programs, update status, disk encryption state, and the last time each machine reported, all refreshed without anybody maintaining it and all exportable the moment somebody asks.

Nobody at the practice can answer the plainest question an examiner asks, namely how much hardware holds client information.

Updating, and the honest half of updating

Approved updates roll out against a calendar you set, third party programs included, because the reader and the browser and the archiving tool are where the interesting trouble lives. Just as valuable as the rollout is the list of what declined to install, since that list is exactly where a genuine hole is hiding.

Certain machines resist. An elderly workstation carrying a package its vendor abandoned will sit there failing forever, and automation does not repair that. You will be shown the list and told which pieces need replacing, rather than having them quietly coloured green on a dashboard.

Apple hardware, and the phones nobody counts

Mac fleets in this industry tend to have accumulated rather than been deployed, one purchase at a time, managed by nobody in particular. Addigy brings them under configuration, insists on disk encryption, delivers software, and reports state beside everything else.

Handsets are the part practices leave out. A phone that reads client mail and holds the authenticator is inside your programme whether or not anybody wrote it down. Zimperium runs on the handset, which means it keeps working on networks you neither own nor can see, and those are most of the networks a phone will ever join.

Entries on this register

Specification and rate for each one

Rates below are read live from the billing service. Anything you record sits on your order sheet while you carry on reading the rest of the register.

Fortify-RMMRate and detail

Remote Monitoring and Management

A single agent keeping the asset record true, delivering approved updates, running maintenance, and letting an engineer take a machine over when somebody is stuck and losing an afternoon.

Asset record, updates, and remote sessions, held by N-able N-sight
  • Hardware, programs, and update status gathered continuously from the agent.
  • Build updates and third party programs delivered against a calendar you set.
  • Health checks on disk, memory, running services, and gaps in reporting.
  • Remote sessions taken with the person present rather than behind their back.
  • Asset and update reporting that exports for whoever has asked to see it.
Supplied byN-able N-sight, licensed through us
Machines it reachesWindows and macOS, with Linux servers on request
What it updatesThe build itself plus supported third party programs
What it reportsAssets, update status, and reporting gaps
Remote sessionsAttended, run by Fortify 24x7 engineers
Charged againstEach managed device, every month
Readingper managed device
collected monthly, ahead of the period
UNITS
Fortify-RMM-DNSRate and detail

Web and DNS Filtering

Name lookups and web requests filtered at the agent, so a machine leaving your office carries its policy along instead of shedding it at the door.

Filtering from N-able N-sight, carried on the agent already present
  • Category rules covering the places a working machine has no cause to visit.
  • Domains known to be hostile, and freshly registered ones, refused at lookup.
  • Rules travel with the hardware onto any network it happens to join.
  • Nothing to rack, no certificate to push out, no traffic to reroute anywhere.
  • Reporting on what was asked for and what was refused, machine by machine.
Supplied byWeb protection from N-able N-sight
How it worksLookups and requests filtered at the agent itself
Off the office networkRules apply exactly the same way
Hardware neededNone. It uses the agent that is already installed
What it reportsRequests and refusals, machine by machine
Charged againstEach managed device, every month
Readingper managed device
collected monthly, ahead of the period
UNITS
Fortify-ControlRate and detail

Apple Fleet Management

Configuration, software, and reporting across Apple hardware, which at a practice this size has generally been bought a machine at a time and looked after by nobody.

Addigy holding Mac, iPhone, and iPad under one set of rules
  • Enrolment through Apple Business Manager or begun by the user, whichever suits.
  • Profiles governing encryption, screen locking, updating, and general settings.
  • Software delivery and version reporting across the whole Apple estate.
  • FileVault state visible and insisted upon instead of assumed to be on.
  • Locking and wiping from a distance when hardware departs earlier than planned.
Supplied byAddigy
Machines it reachesmacOS, iPadOS, and iOS
How it enrolsApple Business Manager, or started by the user
EncryptionFileVault state insisted upon and reported
At disposalLocking and wiping from a distance
Charged againstEach Apple device, every month
Readingper Apple device
collected monthly, ahead of the period
UNITS
Fortify-MobileRate and detail

Mobile Threat Defense

Detection running on the phone, for whichever iOS or Android hardware reads client mail, approves logins, and carries the authenticator guarding everything else.

Zimperium living on the handset rather than on a network you control
  • Detection on the handset, independent of whichever network it has joined.
  • Hostile applications, hostile networks, and phishing spotted on the device.
  • Build and configuration weaknesses reported instead of assumed away.
  • Sits alongside whatever mobile management platform your practice already runs.
  • Its alerts join the same case flow as everything else we keep an eye on.
Supplied byZimperium
Machines it reachesiOS and Android
How it worksDetection sits on the handset, nothing gets rerouted
What it studiesApplications, networks, device state, and phishing
AlongsideAny mobile management platform you already operate
Charged againstEach handset, every month
Readingper mobile device
collected monthly, ahead of the period
UNITS
Honest scope

Exactly what this register does and does not reach

Two columns, both of them written to be relied on. The right hand column is the one worth reading twice, because a firm that misreads it will believe an obligation is covered when it is still open.

What is included

  • An asset record for every enrolled device, gathered from the agent and exportable.
  • Delivery of approved build and third party updates against a calendar you set.
  • Reporting on what updated, what declined, and what stopped reporting altogether.
  • Filtering of name lookups and web requests, wherever the hardware happens to be.
  • Configuration, encryption state, and software delivery across Apple hardware.
  • Threat detection running on enrolled iOS and Android handsets.

What is not included

  • Hardware nobody enrols. A personal laptop outside the agent is outside every claim.
  • Network equipment. Firewalls, switches, and access points are a separate engagement.
  • A promise that every update lands. Some machines decline, and you get shown which.
  • Replacement hardware, licences for what we update, or your Microsoft subscriptions.
  • Writing your acceptable use policy, or enforcing it against a member of staff.
  • Physical custody. Wiping from a distance helps at disposal, but the chain of custody is a procedure your firm writes and then follows.
BILLING ENTITY

Heads up: card statements show FORTIFY 24X7 - Equity IT Solutions is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.

Equity IT Solutions raises no separate charge of its own, so a second line will never turn up beside that one.