Laptop and device build reviews

Your build image is the one control that scales. Get it right and four hundred laptops are hardened at once. Get it wrong and you have shipped the same weakness four hundred times.

What a build review is

A build review assesses the standard device configuration your organisation deploys: the Windows or macOS image, the mobile baseline, and the policy applied on top. We take a device built exactly the way your users receive it and work out what an attacker holding it, or one who has phished the person holding it, could do next.

It is deliberately not a test of one machine. The point is the template, because a weakness in the template is a weakness everywhere.

What we look at

Privilege and access

Whether users hold local administrator rights, how privileged accounts are handled, whether local administrator passwords are unique per device, and what an attacker gains from one compromised machine. Shared local administrator passwords remain one of the fastest routes from a single laptop to the whole estate.

Encryption and recovery

Disk encryption status and enforcement, where recovery keys are held and who can read them, and whether encryption genuinely protects data at rest given the configured boot and sleep behaviour.

Execution control

What is allowed to run. Application allowlisting, macro policy, script host and PowerShell configuration and logging, installer restrictions, and whether a user can bring their own executable. This is the control that decides whether a phishing click becomes an incident.

Patching and update state

Operating system and third party patch levels, how updates reach the device, and how long a device can go without checking in. Third party applications, browsers and PDF readers above all, are the common gap.

Credential exposure

Cached credentials, browser password stores, saved sessions, credential protection configuration, and what can be recovered from memory or disk once an attacker has user level access.

Defence and visibility

Endpoint protection configuration rather than its presence, firewall rules, tamper protection, removable media policy, and whether the device reports anything useful to whatever is watching.

Microsoft estates

Most builds we review are Windows devices managed through Intune and Entra ID, so we assess the policy set alongside the device: configuration profiles, compliance policies, conditional access, Defender settings, and how far the deployed baseline has drifted from what the documentation says it is. Drift is normal and it is usually the finding, because baselines are set once and then quietly amended.

How this relates to Cyber Essentials Plus

Cyber Essentials Plus tests a sample of devices against five specific controls, and it is a pass or fail assessment against a defined standard. A build review is broader and has no pass mark: it tells you what an attacker would do with the build, including the many things the scheme does not examine. Organisations preparing for Cyber Essentials Plus often run one first, because fixing the image is considerably cheaper than failing an assessment and rebuilding under time pressure.

What you get

A prioritised list of configuration changes, each with the setting to change, where to change it in your management tooling, and what the change breaks if anything. We work from your actual estate rather than handing over a generic benchmark printout, because the useful judgement is which of those controls you can realistically apply without stopping people working.

Common questions

How is this different from Cyber Essentials Plus?

Cyber Essentials Plus is a certification assessment against five controls with a defined pass mark. A build review has no pass mark and no fixed scope: it looks at the whole configuration from an attacker’s point of view. The two work well together, and running the review first usually removes the surprises from the assessment.

Do you need a physical device?

A physical device or a virtual machine built from the same image both work. For Intune managed estates we can also enrol a test device against your policies, which shows what actually applies rather than what the policy claims.

How many builds do you review?

However many you deploy. Most organisations have more than they think: a standard user build, a developer build, something for one particular department, and something inherited from an acquisition. The inherited one is usually the interesting one.

Do you review macOS and mobile builds?

Yes. macOS reviews cover FileVault, Gatekeeper, System Integrity Protection, privilege configuration and MDM policy. Mobile reviews cover the iOS and Android baseline applied through your MDM, including what a user is permitted to change.

What about personal devices?

Where BYOD is in scope we assess the controls that apply to it, which is normally application protection policy rather than device configuration. The honest answer on personal devices is usually that your control is over the data, not the machine.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.