N-sight reporting condition, what is installed, and patch level over Linux, macOS, and Windows, and charge of whichever tablets and phones share that register.
Filtering by category, blocking by reputation, and a complete history of where the browser went, incognito windows counted, on every device under management.
Addigy pushes configuration, installs software, and runs unattended compliance checks over the iPads and Macs that arrived one purchase at a time and were never written down.
Behavioural cover from Zimperium, resident on the handset and beholden to no cloud lookup, aimed at rooted or jailbroken hardware, hostile wireless, phishing, and mobile malware.
Almost every firm is wrong about what it owns.
Put the question to a twenty-person advisory practice and the count comes back quickly, confidently, and too low. Left out: the laptop an adviser took with them in March, the back-office box running one obsolete application nobody dares touch, the iPad bought so clients could sign things, and the personal handset that has quietly collected firm mail since 2019.
Tidiness is the least of it. Every other control sold on this site is applied to a list, and applying a control to a list with gaps in it produces a control with gaps in it. The rule sees this plainly, which is why it asks a firm to identify and manage the data, people, devices, systems, and premises it depends on. Everything else in the program stands on that register, and the register is the cheapest item on this page.
Patch state is risk management written down.
N-sight keeps a running account of condition, of what hardware and software are installed, and of patch level, over Linux, macOS, and Windows, and it takes charge of the handsets and tablets listed beside them. It answers the version of the question an examiner tends to ask, which is not whether a patching policy exists but which machines are behind today and by how many weeks.
That distinction is the whole point. A policy asserts an intention. A report showing that thirty-eight of forty machines took the January update within nine days, and naming the two that did not and why, is a fact. Facts are what the annual written report to your board is supposed to be built from.
Patch and configuration state also feeds the change management element of the rule. What changed, on which machine, in which week, is a question the platform can answer without anybody keeping a parallel spreadsheet.
Filtering, and the record it leaves.
Installed alongside the management agent, the web protection line sees online activity at the application level as well as inside the browser, and private windows do not hide from it. Filtering runs on category and on reputation, and bandwidth is measured per site.
For a regulated firm the record is often worth more than the blocking. When a machine is suspected of having reached something it should not have, the difference between an investigation that takes a morning and one that takes three weeks is whether anybody was keeping a per-device history of where it went.
Two estates that grew without being asked.
Addigy takes the Apple estate: enforcing configuration, installing software, holding security baselines, keeping inventory, and running compliance checks without supervision over iOS and macOS. Hardly any firm set out to run an Apple estate. It assembled itself one purchase at a time, and by the point anyone counted it was material.
Zimperium defends tablets and phones from inside the handset, running behavioural models locally and asking nothing of the network to do it. In scope: phishing and malware aimed at mobile, handsets that have been rooted or jailbroken, interception including hostile wireless, and applications of doubtful character pulled from the public stores.
Mobile deserves its own line in this industry because of where the mail is read. The message asking to change a wire destination is very often first seen on a phone, in a lift, between meetings, on the smallest screen with the least context available.
The register as evidence, and where the evidence runs out
The rule asks a firm to identify and manage the data, personnel, devices, systems, and facilities that let it meet its business objectives, ranked by relative importance. Keeping a live register over Linux, macOS, Windows, Apple kit, and handsets answers the device half of that sentence directly.
It also asks for procedures for change management. Patch state, configuration baselines, and enforced profiles produce a dated record of what changed and when, which is materially better evidence than a change log somebody maintains by hand.
Lock and timeout profiles pushed down onto managed hardware feed the access control element. They are imposed rather than suggested, and that distinction is the whole difference between a preference and a safeguard.
| Platforms | N-sight from N-able, with Addigy and Zimperium, all three run for your firm by Fortify 24x7 |
|---|---|
| Operating systems | Linux, macOS, and Windows on the hygiene line; iOS and macOS for Apple governance; iOS and Android for handset defence |
| Inventory | Per device: hardware held, software installed, condition, and patch level |
| Mobile management | Tablets and phones managed from the hygiene line |
| Web protection | Filtering on category, blocking on reputation, bandwidth measured per site, and sight of application as well as browser activity, private windows included |
| Apple governance | Enforced configuration, software installation, security baselines, unsupervised compliance checks, remediation from a distance |
| Mobile defence | Behavioural models resident on the handset, covering phishing and malware aimed at mobile, rooted or jailbroken hardware, interception and hostile wireless, and doubtful store applications |
| Evidence produced | Device register, patch and configuration history, filtering records, and compliance check results |
| Counted by | Each managed device, each Apple device, or each phone or tablet, monthly |
Where these lines stop
Reporting condition is not the same as judging behaviour. These lines describe state and hold configuration in place. Nothing here forms a view about what a process is doing, and none of it stands in for the watchkeeping family.
We can only deploy what a vendor ships. Where a manufacturer has stopped issuing updates, or where a line of business application pins a machine to an old version, the platform reports the gap accurately and cannot close it. That gap belongs in your risk assessment, which is the honest place for it.
Web filtering is not data loss prevention. It records and restricts where a device goes. It does not classify the material leaving on that connection.
Enrolment requires the right to enrol. A personally owned handset can only be protected with the owner's participation, and the terms on which your firm asks for it belong in an employment policy rather than in a configuration.
The words we are careful about
An FTC certification does not exist for any product, and no supplier is able to put a firm into compliance with the Safeguards Rule. That rule reaches financial institutions, and its duties settle on the Qualified Individual your own firm appoints. We sell technical services, plus the operating evidence those services leave behind, set out against the elements of 16 CFR Part 314 so that whoever signs the written program has something dated and specific to point to.
None of it promises a compliance verdict, a clean examination, or freedom from a security event, and none of it is legal advice. Which supervisor reaches your firm, what the written program has to contain as a result, and whether an event carries any duty to notify are all matters for your Qualified Individual and your lawyers.
Heads up: card statements show FORTIFY 24X7 - MoneyGuard Solutions is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.