# Secure My Devices

No organisation is immune from today’s cyber threats – and the costs of a breach are escalating each year. The impacts can cripple business performance, damage customers and partners, and tarnish reputations. Are you willing to let it happen on your watch?

Remote workstations are targeted as much as your servers. Given today’s threats, it’s never been so important to have a multi-pronged endpoint security strategy.

## How we can help:

#### [EDR: Endpoint Detection & Response](/content/services/secure-my-devices/#6ea2237d715d684cb/index.html)

With file-less and malware-less attacks becoming prevalent, staying safe hinges on a great Endpoint Detection & Response solution. It requires monitoring every action, tracking behaviours, and even watching actions between devices – no easy task. Plus built-in tools to allow safe remediation of a compromised device. We stand behind the CrowdStrike Falcon suite, along with many happy customers. [**See why we recommend CrowdStrike**](https://www.linkedin.com/pulse/5-reasons-ditch-your-endpoint-protection-suite-dave-stagg/)

#### [Patch Management and Vulnerability Monitoring](/content/services/secure-my-devices/#e21f9587356c755fc/index.html)

Threat Actors are better resourced and moving faster. As a result, published vulnerabilities are being weaponised very quickly. To keep your organization protected, it’s critical to have an efficient strategy for deploying OS patches, third party software updates, and device driver and firmware updates.

#### [Vulnerability Management Service](/content/services/secure-my-devices/#fd5a04712726171f1/index.html)

Reporting on vulnerabilities in your environment is useful only if you’re actioning the changes to address them. This service keeps your endpoints current – OS, software and firmware – along with recommended changes to keep your defences strong. [More information](/content/wp-content/uploads/2025/06/EF6511-VMS-brochure_final.pdf)

#### [Complete 24/7 Endpoint Security Service](/content/services/secure-my-devices/#3519077ec8754d1fa/index.html)

Since breaches can happen while you sleep, a 24/7 monitoring and response service will ensure the fastest response. We recommend the CrowdStrike Falcon Complete service – a global team that undertakes threat hunting and breach remediation. You’ll also receive cybersecurity breach warranty covering up to $1M worth of damages, which to date has never been claimed.

#### [Secure OS Configuration](/content/services/secure-my-devices/#4f0dbf2541bd4548f/index.html)

Unfortunately, Windows does not ship with the most secure options enabled. Microsoft / CIS Security Baselines provide recommendations for a hardened system. Similarly, ACSC make recommendations for hardening Office macro security. If you haven’t reviewed these recently, we can assist in implementing a more secure baseline, testing with your business critical apps, and then releasing to all devices.

#### [Essential Eight Maturity Model](/content/services/secure-my-devices/#8d79ca7415f68b36c/index.html)

The ASCS has developed an [Essential Eight Maturity Model](https://www.cyber.gov.au/acsc/view-all-content/publications/essential-eight-maturity-model) to help organisations protect themselves against cyber threats. We can align your security strategy to the Essential Eight, and help you move to higher maturity levels.

## **Navigating the Essential Eight Maturity Model**

**How we help you address each mitigation strategy outlined in the [Essential Eight](https://www.cyber.gov.au/acsc/view-all-content/publications/essential-eight-maturity-model).**

| Mitigation Strategy | EF Solution |
| :-- | :-- |
| Application Control | Our partner [Airlock Digital](https://airlockdigital.com/) provides best of breed application allow-listing and control |
| Patch Applications | Our partners [Patch My PC](https://patchmypc.com/) and [Automox](https://automox.com/) automate third-party application patching, removing the need to manually package and deploy application updates |
| Configure Microsoft Office macro settings | We use Group Policy or Device Configuration Profiles in Microsoft Endpoint Manager (Intune) to implement ASCS compliant Microsoft Office macro settings |
| User Application Hardening | We use Group Policy or Device Configuration Profiles in Microsoft Endpoint Manager (Intune) to implement ASCS compliant Application Hardening settings for Office, Web Browsers and PDF software |
| Restrict Administrative Privileges | We use Group Policy or Device Configuration Profiles in Microsoft Endpoint Manager to restrict the use of Windows administrative privileges.<br>CrowdStrike Falcon Discover helps our customers identify local administrator accounts in real-time, and enforce compliance rules |
| Patch Operating Systems | Operating System patches can be delivered via Microsoft SCCM, Microsoft Endpoint Manager (Intune), or via our partner Automox.<br>CrowdStrike Spotlight provides real-time insights into operating system and third-party application vulnerabilities, allowing our customers to prioritise which patches are deployed, and visibility into how many devices are affected |
| Multi Factor Authentication | We control and enforce Multi Factor Authentication using Conditional Access rules in Microsoft Azure, or via a third-party identity providers such as Okta.<br>We have helped organisations tailor their Multi Factor Authentication configuration to follow the ‘north star’ recommendation of ’only one prompt, per user, per device, per password change’ |
| Regular Backups | While we do not specialise in backups, we partner with several consulting firms who do, and can help you comply with this mitigation strategy |

## Securing your endpoints is now more important than ever

Make sure your project goals consider:

#### Automation

Automate software updates and third-party application updates to remove reliance on manual intervention, providing faster reaction time to vulnerabilities and a reduced surface attack vector.

#### Visibility

Invest in an Endpoint Detection and Response (EDR) Platform that will provide you real-time insights and alerts to potential threats and suspicious activity in your environment. Legacy AV providers cannot protect against modern file-less and malware-less attack techniques.

#### Essential Eight

Ensure your workstations have current apps, patches, and firmware; and are compliant with security standards before they’re out in the wild.

### 24/7/365

#### Threat Hunting &   Incident Response

powered by CrowdStrike’s global SOC

## Learn How We Have Helped Leading Organizations

## [Mercy Health cures its vulnerability backlog with Endpoint Focus](/content/case-study/mercy-health-cures-vulnerability-backlog/index.html)

## [Buloke Shire Council implements a modern workplace utilising Microsoft 365 services](/content/case-study/buloke-shire-council-implements-a-modern-workplace-utilising-microsoft-365-services/index.html)

## [McConnell Dowell modernises device deployment saving $72,000 annually](/content/case-study/mcconnell-dowell-modernises-device-deployment-saving-72000-annually/index.html)

# Let’s Make Things Happen

We’re always happy to chat about our latest projects, new advancements, and what’s working well for our clients.

_“The support from Endpoint Focus is always reliable and timely. Our annual notebook replacements run like clockwork, and we’ve continually improved our security thanks to their advice. We can turnaround new applications to teachers and students in days, where it previously took much longer.”_

###### James Sze

IT Systems Admin, Marymede Catholic College

### Save time,   reduce costs,   and minimise risk.
