Endpoint security gets discussed as if it starts with an advanced detection platform. In practice, most incidents exploit gaps in the unglamorous basics: unpatched software, local admin rights nobody removed, and devices with no encryption that quietly leave the building in a laptop bag.

Patch management is the first layer, and the timing matters more than most businesses assume. Exploitation of a disclosed vulnerability often begins within days, while many organisations still average months to fully remediate critical patches across their fleet — a gap that exists on the wrong side of the risk equation for as long as it's left unmanaged.

Local administrator rights are the second common gap. A user with standing admin access on their own device is one convincing phishing email away from a full compromise, because malware inherits whatever privilege the logged-in account holds. Removing standing admin rights and using just-in-time elevation for the rare occasions it's genuinely needed closes a disproportionate amount of risk for the effort involved.

Full-disk encryption and remote wipe capability matter more than they get credit for, specifically because the failure mode they protect against — a lost or stolen device — is common, mundane, and entirely preventable with a setting that costs nothing extra on most business-grade endpoint management platforms.

None of this replaces endpoint detection and response, but EDR without the basics underneath it is a more expensive way to catch problems that better hygiene would have prevented in the first place. The order matters: fix what's cheap and structural before adding what's sophisticated and reactive.

All technical perspectives