Challenges
The assessment centered on the policies that protect end-user devices, govern enrolment, and control which applications and accounts can reach corporate resources. While no single critical or high-severity issue was uncovered, the review identified a number of lower-impact opportunities to strengthen the configuration that, taken together, expanded the organization’s overall attack surface.
The most significant theme was incomplete protective rules on managed devices. A set of safeguards designed to limit risky behaviour at the endpoint — such as blocking suspicious code, restricting which applications can launch sensitive actions, and controlling how documents interact with external content — was only partially in place. The result was a wider window for a piece of malicious content to take hold on a corporate device before any centralized defence noticed.
Other recurring themes included:
- Weak hygiene around inactive devices and dormant user accounts that still retained corporate access
- Limited enforcement of basic device controls, such as screen lock timing, password complexity, and lockout thresholds
- Missing centralized detection and response capability across the managed device fleet
Together, these gaps reduced confidence that a single compromised laptop, phone, or unused account could be contained quickly.
Objectives
The company wanted a clear, independent picture of how its managed device environment stood up to a realistic attacker, with prioritised guidance on what to fix first. The brief was to identify the practical exposure, not to produce a long catalogue of theoretical concerns.
The main questions were:
- How resilient was the managed device environment to a single compromised endpoint or account?
- Were enrolment, sign-in, and offboarding flows trustworthy from end to end?
- Which gaps carried the highest real-world risk and deserved the first remediation cycle?
Cloud Security Assessment Services Provided
CyberGlobal delivered a cloud security assessment focused on the configuration of the platform used to enrol, manage, and protect corporate devices and accounts. The work measured the actual posture against industry best practice for centrally managed environments, rather than against a paper-only checklist.
The team examined the following:
- Protective rules and compliance enforcement applied to managed devices
- Account lifecycle, sign-in, and device enrolment controls
- Application deployment, patching, and data protection on end-user devices
CyberGlobal delivered a cloud security assessment focused on the configuration of the platform used to enrol, manage, and protect corporate devices and accounts. The work measured the actual posture against industry best practice for centrally managed environments, rather than against a paper-only checklist.
The team examined the following:
- Protective rules and compliance enforcement applied to managed devices
- Account lifecycle, sign-in, and device enrolment controls
- Application deployment, patching, and data protection on end-user devices
Execution and Outcomes
The engagement was structured around the organization’s real working environment: a mix of corporate laptops, mobile devices, and personal equipment used by a small but expanding research and operations team. The security team reviewed how the management platform was configured in practice and how those settings translated into protection for each class of device.
Particular attention was given to the protective rules that limit what an attacker can do once a piece of malicious content lands on a corporate machine. Several of these rules were either incomplete or inconsistently applied, which would let an attacker move further than expected before being noticed. The team also checked the lifecycle of devices and accounts, flagging equipment that had been offline for long periods and accounts that no longer matched any active employee.
Sign-in and enrolment flows were reviewed next. An additional verification step was not consistently required when adding a new device to the corporate environment, which would let an attacker with a stolen password register a fresh foothold. Stronger sign-in alternatives that bind a user to a specific trusted device were available on the platform but had not yet been adopted across the fleet.
Finally, the assessment looked at what would happen after a device went missing or an employee left. There was no consistent procedure to wipe corporate data from a lost, stolen, or returned device, and data stored on end-user mobile equipment was not encrypted at rest.
By the end of the engagement, the organization had a clear, ranked view of where its managed device environment was strongest and where small policy adjustments would deliver the most immediate risk reduction.
Solutions
CyberGlobal recommended a coordinated tightening of the device management configuration, anchored on the protective rules that govern endpoint behaviour. Activating and consistently enforcing the full set of those rules across all managed devices was the single highest-value action.
Key actions included:
- Enabling the complete set of protective endpoint rules, with logging in place to confirm coverage
- Deploying a centralized detection and response capability across the managed fleet
- Encrypting data at rest on all end-user laptops, tablets, and phones used for corporate work
The team also recommended tightening the account and device lifecycle. Inactive devices and dormant accounts should be removed on a fixed schedule, and non-compliant devices should be blocked from reaching corporate resources until they meet the required configuration.
Sign-in and enrolment were the third focus area. A stronger verification step was advised whenever a new device is added to the environment, alongside the wider rollout of a sign-in method that ties each user to a specific trusted device. Lockout, screen-timeout, and password complexity settings should be aligned across all platforms in scope.
Finally, the organization was advised to put a standard procedure in place for wiping corporate data from any device that is lost, stolen, or returned during offboarding, and to limit installed applications to a maintained, approved catalogue.
Results: A Hardened Cloud-Managed Environment
Acting on these recommendations is expected to materially shrink the organization’s attack surface at the endpoint, the layer where most real-world incidents begin. With protective rules consistently enforced, detection and response in place, and end-user data encrypted, a single lost laptop or compromised account becomes far less likely to translate into a wider incident.
The combined effect is a more controlled, more observable, and more resilient managed device environment, better matched to the value of the research and operational data it protects.
Secure your business with CyberGlobal
Clean energy and other deep-tech innovators hold sensitive research and operational data that attackers actively look for. Our specialists help similar organizations measure the real posture of their cloud-managed environments and close the gaps before they are exploited.
Secure your business with CyberGlobal
Clean energy and other deep-tech innovators hold sensitive research and operational data that attackers actively look for. Our specialists help similar organizations measure the real posture of their cloud-managed environments and close the gaps before they are exploited.