Christchurch · Dunedin · Nationwide
Endpoint Security Services for NZ Businesses
Protect the laptops, desktops, servers and phones your business relies on, with endpoint protection that is deployed, configured and checked. Exodesk agrees which devices are covered, how protection is applied and what happens when a device drops out.
Supporting New Zealand businesses since 1989
The short answer
What is endpoint security?
Endpoint security is the protection on each device that holds business data or reaches business systems: laptops, desktops, servers, phones and tablets.
Modern endpoint protection watches behaviour as well as known threats, and can block, quarantine or isolate on its own. A licence is only part of the job. Endpoint security services cover the work around it: enrolling every device, applying the right settings and checking that protection stays in place as staff, software and equipment change.
When to look closer
When your devices need attention
Endpoint protection can be installed on every device and still leave gaps nobody can see.
These are signs your device protection is worth a closer look, not a diagnosis.
No current device list
Nobody can say how many laptops, phones and servers reach business data, or which of them are protected.
Settings differ from device to device
Protection was installed by different people at different times, so each device is configured a little differently.
Protection that quietly stopped
An agent was removed, expired or stopped updating, and nothing flagged it.
Phones outside the plan
Staff read work email and files on phones that have no protection or management at all.
Servers treated like laptops
Servers run the same product as staff computers without the server licence or settings they need.
Two products on one device
A new tool was added without removing the old one, and the two now interfere with each other.
What we protect
Which devices can our endpoint security services protect?
Each type of device is protected in the way that suits it, so the scope lists them separately.
Computers
Windows and Mac laptops and desktops
The devices staff use every day, with protection, settings and reporting applied the same way across the fleet.
Supported operating system versions are confirmed before onboarding. A device past vendor support may need replacing before it can be protected properly.
Servers
Physical and virtual servers
Protection configured and tested around the role each server plays and the applications it runs.
We scope and license server protection separately from staff computers.
Company mobiles
Company phones and tablets
Business-owned phones and tablets brought into protection and reporting. Your scope states whether that means app protection, device management or mobile threat protection, which provide different controls from those on a laptop or server.
Supported platforms, apps and licences are confirmed before quoting. Full phone and tablet management is covered by our mobile device management service.
Staff-owned
Staff-owned phones
Where supported and included in your scope, app protection secures work data in approved apps without managing the personal side of the phone.
Staff agree to the arrangement before protection is set up, so everyone knows what the business can and cannot see.
The service
What our endpoint security service includes
Six areas of work, scoped around your devices, your people and the tools you already have.
Enrolment and deployment
Every device in scope enrolled and protected, with a record of what is covered and what is not.
Protection policies
Consistent settings inside the endpoint protection tool, applied across the fleet and adjusted for servers, phones and anything with special requirements.
Coverage checks
Enrolled devices checked to confirm protection is running and reporting. A device that stops reporting is identified and followed up.
Detections and exceptions
What the tools block or quarantine is followed up, and software staff need that has been blocked is reviewed through an agreed process.
Moving from existing protection
Supported tools kept where they are suitable. Where they are not, a planned move to a supported tool with the old agents removed.
Changes as the business changes
New starters, leavers, new devices and retired ones added or removed, so the coverage stays accurate.
Some related work has its own service. Patching and fixing known weaknesses is covered in vulnerability management, Microsoft device policies in Microsoft Intune, and wider protection against malicious software in malware protection. Your quote lists the protection policies included and identifies any separate work needed for disk encryption, recovery keys, application control, patching or wider device management.
Endpoint security can be bought on its own or alongside our managed IT services, and it works with your current IT provider or internal team on a co-managed basis.
Getting started
How do we put endpoint protection in place?
Endpoint security is set up in stages, and each device in scope is confirmed to have the required protection, settings and reporting before the rollout is signed off.
Find every device
List the computers, servers, phones and tablets that reach business data, including the ones that are away from the office for weeks at a time.
Check compatibility and licensing
Confirm which devices and operating systems are supported, whether your current protection can stay, and which licences are needed.
Plan the rollout
Agree the settings and roll out to a small group first, so any conflict with the software your business uses is found before it reaches everyone.
Deploy and confirm
Protect each device, remove superseded agents and confirm each one has the required protection, settings and reporting.
Keep it current
Check coverage, follow up devices that stop reporting and update the scope as devices and staff change.
When something goes wrong
Detections and lost devices
Endpoint protection handles a lot on its own. The service makes sure the rest has an owner.
- A threat is detected. The tool may block or quarantine it automatically, or isolate the device where that action is supported and configured. The detection is recorded and followed up under the agreed process. Analyst investigation at any hour is part of our optional managed detection and response service.
- A device is lost or stolen. Staff report it through the agreed support route. We take the access steps we are authorised to perform, or coordinate them with your IT team, and request a remote lock or wipe where the device is managed and the action is supported.
- The result is checked. A remote action depends on the device receiving and carrying out the command, so we record what is confirmed and what remains unknown. Sending a wipe request does not on its own show that data has been removed.
- The record is ready. If the device held personal information, a clear record of its protection helps with the privacy assessment. Our NZ Privacy Act compliance guide covers the obligations.
Endpoint security and MDR
Do you need managed detection and response as well?
Endpoint protection can prevent threats, record suspicious activity and take automatic action without anyone watching.
What it does not provide is round-the-clock analyst investigation that connects an alert with activity in email, cloud accounts or the network and decides what to do at two in the morning. That is the job of our managed detection and response service, which uses the same devices as one of its sources. It is optional, quoted separately, and your quote shows whether it is included.
NZ guidance
What New Zealand guidance says about endpoint protection
The National Cyber Security Centre includes application control among its critical controls.
Its guidance on application control describes allowing only approved software to run, and notes that for a lower effort option an organisation could use endpoint detection and response tools, which can detect and block malicious activity. We apply that guidance to your devices and the software your business depends on, rather than treating one control as the right answer for every business.
Cost
What affects the cost of endpoint security?
The service is priced on the devices it protects.
We scope the service before quoting. These are the things that move the figure:
- Devices. The number of computers, phones and tablets in scope.
- Servers. Server protection is scoped and licensed separately from staff devices.
- Licences. Whether suitable licences are already in place or supplied with the service.
- Moving from current protection. Any work to replace or take over the tools you have now.
- Managed detection and response. Whether analyst monitoring is added.
Your quote sets out what the recurring fee covers and how adding devices changes it.
Why Exodesk
Why work with Exodesk?
Supporting businesses since 1989
We support New Zealand organisations from our teams in Christchurch and Dunedin, with devices considered alongside your systems and support.
Coverage you can see
You know which devices are protected, which are not and what is being done about the gaps, rather than assuming every device is covered.
Part of your wider security
Endpoint security sits alongside our cyber security services and network security, so devices and connections are protected together.
Questions
Endpoint security questions
What is endpoint security?
Endpoint security is the protection on each device that holds business data or reaches business systems, including laptops, desktops, servers, phones and tablets. Modern endpoint protection watches behaviour as well as known threats and can block or quarantine automatically. The service around it enrols every device, applies consistent settings and checks the protection stays in place.
Which devices can you protect?
Windows and Mac computers, servers, company phones and tablets, and staff-owned phones. Server protection is scoped and licensed separately, and on staff-owned phones app protection covers work data in approved apps. Supported operating system versions are confirmed before onboarding.
Can you manage the endpoint protection we already have?
We work with supported endpoint security tools and check compatibility and licensing before onboarding. If your current product is supported and suitable, it can stay. If not, we plan the move to a supported tool and remove the old agents so two products are not fighting on the same device.
How do you check every device stays protected?
Enrolled devices are checked to confirm the protection is running and reporting. A device that stops reporting is identified and followed up, and your agreement sets out how that works. Telling us about new, replaced and retired devices keeps the coverage accurate.
Does endpoint security include monitoring outside business hours?
Endpoint protection keeps working at any hour and can block or quarantine threats automatically. Analyst investigation and response outside business hours is part of our managed detection and response service, which is optional and quoted separately. Your quote shows whether it is included.
Can staff-owned phones be protected?
Yes, where supported and included in your scope. App protection secures work data in approved apps without managing the personal side of the phone. Our mobile device management page explains how that separation works.
What happens if a laptop is lost?
Report it as soon as possible through the agreed support route. We take the access steps we are authorised to perform and request a remote lock or wipe where the device is managed and the action is supported. We then record what is confirmed and what remains unknown, which helps with any privacy assessment you need to make.
Is losing an encrypted laptop a privacy breach?
If the laptop holds personal information, losing it can be a privacy breach even when the drive is encrypted. Whether it must be notified depends on whether serious harm has occurred or is likely, taking into account the information involved and whether the protection was effective. Our NZ Privacy Act compliance guide covers the obligations.
Is antivirus the same as endpoint security?
Antivirus is one layer of endpoint security, and modern antivirus can use behaviour and cloud intelligence as well as known signatures. Endpoint security adds deployment, consistent policies, coverage checks and an agreed process for detections and exceptions.
Can we buy endpoint security without managed IT?
Yes. Endpoint security can be bought on its own, without moving the rest of your IT to Exodesk. We can work alongside your current IT provider or internal team, with the agreement setting out who handles each task.
How much does endpoint security cost?
The cost depends on the number and type of devices, the licences needed and any work to move from your current protection. Server protection is scoped and licensed separately from computers and phones. Your quote sets out what the recurring fee covers and whether managed detection and response is included.
Do you provide endpoint security outside Christchurch and Dunedin?
Yes. Deployment, policy management and coverage checks work remotely, so the service is available to businesses across New Zealand. We support organisations throughout the country from our teams in Christchurch and Dunedin.
Next step
Know which devices are protected
Talk to Exodesk about endpoint security for the laptops, servers and phones your business relies on. We will discuss what you have, what is covered and what a sensible first step looks like.
It helps to know roughly how many devices you have and which protection is installed. If you would rather establish where you stand first, request an IT assessment.
Get in touch
Discuss endpoint protection
Tell us a little about your devices and we will be in touch to arrange a time that suits.
Prefer to talk?
Christchurch
Level 1, 85 Riccarton Road
Christchurch 8011
03 343 3124
Dunedin
Level 3, Bartons Building
2 Stafford Street, Dunedin 9016
03 479 2941