Almost every business I sit down with for a HIDDEN Assessment is certain that their laptops, mobiles and tablets are secure. After all, they have antivirus and Microsoft Defender installed, and an IT provider keeping an eye on things. That’s a reasonable place to start. But when I start asking how those devices are managed (i.e., who's checking them, who's updating them, who'd notice if one was compromised), they’re not as confident anymore.
As a cyber security specialist at Babble, I spend my days in the detail: the tools, the configurations, the small technical questions that turn out to matter a lot more than they first appear to. What I care about most is taking that complexity and making it simple enough to act on, because a gap you can't see clearly is a gap you can't close.
In this article, I'll walk through what "protected" should really mean for the devices your business already has, where the weak spots usually turn up, and the three questions I ask every business to answer with confidence before they assume they're covered.
–
What this article covers:
- Installed vs. working: the gap that matters
- What “fully managed” really means
- Where Microsoft Defender fits
- BYOD: the blind spot nobody's created on purpose
- Policy vs. MDM: why you need both
- What happens when the owner leaves
- MFA and zero trust, explained simply
- Three questions to ask this week
Security software installed isn't the same as protected
If you’re like most businesses I meet, you may already have the basics covered: laptops, phones, some form of security software, and an IT provider or internal team keeping things running. That’s great, but this is rarely where I find the real risk hiding.
Security software installed. Problem solved? Not quite.
In the HIDDEN assessment, I look for whether that software is configured correctly, whether it's being monitored and updated on a regular basis, and whether it covers the everyday devices people use to access company data (not just the ones IT remembers to check). Miss any one of those three and the software can be up and running but not doing its job.
This isn’t a result of poor decision-making catching up with a business. Most of the gaps I find come from sensible decisions made reactively or in isolation: a laptop bought before a policy existed, a phone added to email access because it was faster than saying ‘no’, an IT provider who inherited a tool nobody fully documented. Each choice made sense in the moment. But over time, they add up to a patchwork of coverage that appears to be complete from a distance, until I take a closer look.
What “fully managed” should actually mean
Ask a business whether their devices are managed and most will say yes. Ask me what that covers, and I'll tell you the answer isn’t quite so simple.
A device that's genuinely managed has someone accountable for:
- Patching applied on a schedule, not when remembered
- Security settings checked, not assumed
- Access to company data controlled and reviewed
- Activity reported, so someone sees it in real time
That last point matters more than it sounds. A tool that quietly logs activity nobody reviews isn't giving you visibility; it's giving you a record you'll only read after something has already gone wrong.
The size of the business often shapes how this plays out. Many SMBs don't have a dedicated IT team, and device management sometimes falls to whoever has time: finance, operations, occasionally the business owner directly. This is even more of a reason to get clear policies and ownership agreed on before an incident forces the conversation.
Where Microsoft Defender fits
A lot of the businesses I work with already run on Microsoft Defender, often because it came bundled with existing licensing. It’s an excellent solution and the technology is a solid foundation.
However, I always tell people that the effectiveness of any security tool, including Defender, isn't only about the product itself. It depends on whether it's the right fit for how your business operates: configured properly, deployed across every relevant device, and actively managed over time. A tool that's installed but not tuned to your organisation won't close the gaps it's capable of closing, whatever the product.
The personal devices businesses forget about
SMBs tend to allow some form of bring your own device (BYOD) use, even without a formal policy behind it. It is the more convenient option, after all. Someone can check their emails on their own phone or approve an invoice from a personal laptop over the weekend.
Here's something I like to be clear about: monitoring a BYOD device for security purposes is not snooping around someone's personal data. It's about securing the access that device has to company applications and company information; not what someone's browsing, sending, or storing personally. Drawing that line clearly is what lets me help a business write policies that people understand and trust.
This distinction really comes into play when the worst happens. If a personal device used for work is compromised, the business can remove its access and delete company data from it (sometimes called a corporate wipe), without touching anything personal on that device. The organisation secures its data. The individual's personal data stays exactly that: personal.
Policy and MDM are not the same thing, and you need both
Mobile device management (MDM) is the system used to manage and secure company devices on the technical side: enforcing passwords, encryption, and software updates, whether that device is a laptop or a phone. A written device policy is different. It sets out what's expected of the people using those devices, and shows the business is following good practice and, where relevant, compliance requirements.
One should not exist without the other, in my opinion. MDM without a policy has no rules to enforce. A policy without MDM has no way to check it's being followed.
Ownership of that policy ultimately sits with the business: drawing on input from IT, a cyber security specialist like me, and HR where relevant. Your managed service provider (MSP) may help, but they cannot write it on the business's behalf. A typical device policy covers requirements like multi-factor authentication (MFA) and the use of a device management platform such as Intune, alongside clear expectations for anyone connecting a personal device.
What happens when the person who owned it leaves
Most of the time, it's not the technology that lets a security tool down, but a change in who's looking after it.
A platform gets bought, configured and monitored by one person. That person leaves the business. The tool keeps running in the background, but nobody is checking its reports, tuning its settings, or acting on what it flags. The investment is still there, but the value it was bought for isn't.
This is exactly the kind of gap a HIDDEN Assessment is built to surface. It validates what a business already suspected while uncovering what it didn't know to ask about. Where I find a tool that's fallen out of active use, my focus is on getting value back from what's already there: restoring the training, ownership and reporting around a tool the business has already paid for.
Locking the door behind every login
MFA (i.e., requiring more than a password to confirm someone is who they say they are) is one of the most basic protections, and one I still see overlooked more often than I'd like. Anyone in cyber security will tell you that it should be applied across every device without exception.
Zero trust takes the same principle a step further. It assumes nothing should be automatically trusted, even a device already connected to the corporate network, and checks identity every time access is requested. The two work together: you could have the best endpoint protection available, and it still wouldn't confirm that the person using the device is the person who's supposed to be using it.
Three questions worth asking this week
Before assuming your current setup has this covered, here are the three questions I ask every business I work with:
- Do we know every device that can access company data?
- How do we know those devices are secure (i.e., patched, encrypted, and configured to company standards)?
- How do we know those devices are actively managed (i.e., who checks them, who responds to alerts, and who removes old devices when they're no longer in use)?
Think your work devices are secure? Ask these three questions.
Where to go from here
You can't secure what you can't see. If you can answer those three questions with confidence, your devices are in better shape than most of the businesses that come to me for a HIDDEN Assessment. If you can’t, that's not a verdict on your existing tools or even your provider. It's simply where I'd tell you to look first.
Having security software installed isn't the same as being protected. In my experience, that's usually where the risk sits; not through anyone's fault, just things nobody's had reason to check yet.
As a cyber security specialist at Babble, closing gaps like this (practically, without fear tactics, one honest conversation at a time) is what I do every day. If any of this struck a chord, we can walk you through it further.
Join our live webinar: Managed Cyber Security: What to Buy, and How to Buy It, for clarity on what you already have versus who's watching and responding when it matters, plus a practical way to compare your options before you buy.
