Cyber Essentials evidence for managed devices | Firemind
Cyber Essentials

Every managed laptop, checked.And the ones we cannot check, said so.

Patching inside fourteen days, operating system in support, firewall on. Answered honestly across the fleet.

Fourteen-day patching window
Laptops separated on model evidence
End-of-life flagged separately
Firewall checked every available way
Unable to assess, never assumed
Run on our own fleet
The problem

Cyber Essentials asks a simple question of every device. Answering it across a fleet, honestly, is where most organisations struggle.

Are critical and high-severity vulnerabilities patched within fourteen days, is the operating system in support, and is the firewall on?

The IT Operations Engine answers it from the device-management and endpoint-protection data your tenant already holds, and says plainly where the data does not exist.

What an honest fleet report has to do

  • Separate laptops from phones, tablets and desktops on model evidence rather than on a naming convention
  • Apply the in-scope definition and the fourteen-day window as the scheme states them
  • Record a device as unable to assess when the data cannot be retrieved, rather than assuming it compliant
  • Name the missing permission when one blocks the check, so it can be granted and the run repeated
  • Flag end-of-life operating systems separately from patching failures
How we approach it

Read the tenant you already have, and be honest about the gaps.

The engine enumerates every managed device, separates laptops from phones, tablets and desktops on model evidence, and records operating system, version, last check-in, compliance state and encryption state for each. It then pulls per-device vulnerability exposure from your endpoint-protection service, applies the Cyber Essentials in-scope definition and the fourteen-day patching window, and reports each device as compliant, non-compliant, or unable to assess. Devices on end-of-life operating systems are flagged separately. Host firewall status is checked by every available method before it is reported.

Where data cannot be retrieved, the device is recorded as unable to assess and never assumed compliant. Where a permission is missing, the report names it, and the assessment can be re-run once it is granted.

Device management
Endpoint protection
Patch exposure
Encryption state
Host firewall

What the assessment produces

    • A fleet, enumerated honestly - Every managed device enumerated, with laptops separated from phones, tablets and desktops on model evidence. Operating system, version, last check-in, compliance state and encryption state recorded for each.
    • Three answers, not two - Each device is reported as compliant, non-compliant, or unable to assess. Where data cannot be retrieved the device is never assumed compliant, and where a permission is missing the report names it so the run can be repeated once it is granted.
    • The things that fail quietly - Devices on end-of-life operating systems are flagged separately from patching failures, and host firewall status is checked by every available method before it is reported.

Can you answer it honestly across the whole fleet today?

Read-only access to your device-management and endpoint-protection tenant. First report usually within days.

Scope a pilot →
How it starts

Read-only on your tenant. The first fleet report within days.

We have run this on our own fleet. On yours, we would run it read-only first, then agree the remediation path for the devices that fall short.

  • Read-only tenant access

    Access to your device-management and endpoint-protection tenant. The engine reads what is already held there rather than installing anything.

    • Nothing installed on any device
    • First fleet report usually within days
    • Missing permissions named, not worked around
  • Every device, three answers

    Compliant, non-compliant, or unable to assess. The fourteen-day window and the in-scope definition applied as the scheme states them.

    • Laptops separated on model evidence
    • End-of-life operating systems flagged separately
    • Firewall checked by every available method
  • Then the remediation path

    A prioritised list of the devices that fall short, worked by your device team or ours under your approval.

    • Prioritised rather than alphabetical
    • Your approval governs any change
    • Re-runnable once permissions are granted
What stays with you

Granting the permissions the assessment needs, and the remediation decisions.

The engine produces the evidence and the prioritised list. Your device team or ours acts on it under your approval.

You gain:

  • This covers the device-level technical controls that live in your management and protection tooling. The organisational controls remain yours to evidence.
  • A device whose data cannot be retrieved is recorded as unable to assess. It is never assumed compliant.
  • We have run this on our own fleet before proposing it for yours.

FAQ

Questions.

It covers the device-level technical controls that live in your management and protection tooling. The organisational controls remain yours to evidence.

Start with read-only access to your tenant.

The first fleet report is usually available within days, with every device reported as compliant, non-compliant, or unable to assess.

Your benefits:

  • Never assumed - unretrievable data is reported, not guessed.
  • Model evidence - laptops separated properly, not by naming.
  • End-of-life - flagged separately from patching failures.
  • Run on our own - fleet before we proposed it for yours.

What happens next?

Talk.

A focused discussion about your fleet and the tooling that manages it.

Assess.

Read-only across the tenant, with the first report within days.

Remediate.

A prioritised list, worked under your approval.

No obligation. Just a focused discussion about your managed device fleet.

We'll only use your details to respond to your enquiry. No newsletters unless you ask for them.