ConstitutionComputing
Article IV of VI

The Managed Estate

Patch level, disk health, web egress, Apple configuration, and the phones nobody counts as computers until one of them holds the only unlocked session.

IV
Schedule · Article IV4 lines · charged monthly in advance
Remote MonitoringFortify-RMM · billed per managed device
Loading
Qty
Web ProtectionFortify-RMM-DNS · billed per protected device
Loading
Qty
Apple ManagementFortify-Control · billed per Apple device
Loading
Qty
Mobile DefenseFortify-Mobile · billed per phone or tablet
Loading
Qty
Monitoring and managementFortify-RMM · Fortify-RMM-DNS
PlatformN-able N-sight, deployed as a lightweight agent.
Systems coveredMachines running Windows, macOS, or Linux. Basic management of tablets and handsets rides along on the same line.
VisibilityHardware and software inventory, disk and health indicators, service state, and patch status for the operating system and the third-party software that is usually the way in.
Web ProtectionA separate line. Filtering by category and site reputation, applied on the device rather than at one office router, so it follows a laptop to the airport.
Private browsingWeb activity is visible whether it is programmatic or in a browser, including sessions opened in private or incognito mode.
BandwidthWeb bandwidth consumption per device, which is generally how a quiet problem announces itself.
How it billsMonthly, against each device, on the two lines separately.
Apple estatesFortify-Control
PlatformAddigy, purpose-built for Apple rather than adapted from a Windows tool.
Systems coveredmacOS and iOS.
ConfigurationBaseline enforcement, profile and policy management, and software deployment across a distributed fleet.
ComplianceContinuous checking against the baseline with automated remediation, and evidence an auditor will accept.
Remote workInventory and remediation reach devices wherever they are, which for Apple fleets is generally not an office.
How it billsMonthly, against each Apple device.
Phones and tabletsFortify-Mobile
PlatformZimperium, running detection on the device itself.
IndependenceDetection does not depend on a cloud lookup, so a phone on hostile or absent connectivity is still defended.
Threats coveredZero-day mobile malware, phishing aimed at the handset, applications that demand far more than their function needs from either store, and compromise through jailbreaking or rooting.
Network attacksMachine-in-the-middle interception, rogue wireless access points, and tampering with supposedly secure communications.
Both platformsAndroid and iOS.
How it billsMonthly, against each handset or tablet.
01The problem

Nothing can be defended until it has been counted

Ask a business how many machines it runs and you get an estimate, usually low, and usually missing exactly the machines that matter: the workstation in the back office running an application nobody will let anyone upgrade, the laptop of the employee who left in June, the tablet on the shop floor.

An agent that reports in daily converts that guess into a list. Everything else in this catalog depends on the list being right, because every other Article is priced and deployed per unit, and a unit nobody knows about is protected by nothing at all.

02Patching

The dullest control, and still the one that pays best

Patching is unglamorous, gets deferred for reasons that always sound sensible in the moment, and remains the intervention with the best return in security. The exploits used against small and midsize businesses are overwhelmingly against flaws with a fix already published, frequently one published a long time ago.

Monitoring reports the patch level of the operating system and of the third-party software that is realistically the way in: browsers, runtimes, document readers, conferencing clients. The value is not only that things get patched. It is that you can prove what is patched on the day somebody asks.

03Egress

The cheapest place to stand is the way out

Web Protection applies filtering on the device, by category and by the reputation of the destination. That placement matters more than the rule set: a control living in the office firewall protects a laptop only while the laptop is in the office, which for most of your people is now a minority of the week.

Visibility extends to private and incognito sessions, which sounds intrusive until the first time you are investigating an incident and need to know where a machine went in the minutes before it started behaving strangely. Bandwidth figures per device are the other quiet signal: exfiltration and unauthorized services both tend to show up as a number that does not belong.

04Apple

Managing Apple with a Windows tool produces Windows-shaped failures

Apple devices enroll differently, update differently, encrypt differently, and report differently. Generic management platforms cover them in the sense that a checkbox exists, and then leave you discovering at the wrong moment that the encryption key was never escrowed or the profile never applied.

Fortify-Control is a purpose-built Apple line: configuration profiles, security baselines, software deployment, and continuous compliance checking with automated remediation. Take it wherever Apple is a real part of the estate rather than one designer's laptop.

05Mobile

The device holding the session everybody forgot to protect

The phone in your CFO's pocket approves the multi-factor prompts, reads the mail, and holds an authenticated session to everything. It is a full computer treated as an accessory, and in most estates it carries no security software of any kind.

Mobile defense runs its detection on the device. Zero-day mobile malware, phishing links that open outside the mail client, applications that ask for far more than their function requires, jailbroken or rooted devices, hostile wireless networks, and interception attempts are all handled locally, so a phone on a conference center network with no usable connectivity is still defended.

Inventory

An estate you can read is the precondition for everything else

This Article is the least dramatic thing we sell and the one most often skipped, usually on the reasoning that monitoring is not security. Monitoring is not security. It is the thing that tells you where security is absent.

An unpatched machine nobody knew about, running unfiltered, is how most of the incidents in the rest of this catalog actually begin. The lines here are the cheapest on the schedule for a reason: they are the ones that make the expensive ones effective.

Where this Article stops

  • Monitoring and management report and remediate. They are not threat detection. Behavioral detection and response is Article I, and the two lines are deliberately separate.
  • Web Protection governs web traffic from the device. It does not filter mail, which is Article III, and it does not govern what executes locally, which is Article II.
  • Monitoring includes basic mobile device management. Where Apple devices are a serious part of the estate, Fortify-Control is the line that does the job properly, and where the concern is mobile threats rather than mobile configuration, Fortify-Mobile is the one you want. They are separate lines because they solve separate problems.
  • Nothing in this Article copies data anywhere. Backup is Article VI.