What an endpoint security baseline should accomplish
A business laptop is both a productivity tool and a potential path into company accounts, cloud services and shared data. A practical endpoint security baseline defines the minimum controls every managed Windows PC and Mac must meet before it is trusted with business information.
The baseline should be specific enough to verify, but simple enough for a small IT team or managed service provider to operate consistently. At minimum, every business endpoint should have:
- A supported operating system and applications that receive security updates.
- Centralized patch and device-management oversight.
- Full-disk encryption with a recoverable, protected recovery key.
- Built-in or third-party malware prevention, with alerts reviewed by a responsible person.
- Endpoint detection and response where the business needs investigation and response capabilities beyond traditional antivirus.
- A local firewall, screen lock and least-privilege user configuration.
- Defined controls for removable media and other peripherals.
- A documented process for isolating, reimaging or retiring a lost, compromised or unsupported device.
NIST identifies patching, encryption, access limitation and security procedures as foundational small-business security practices. Its small-business cybersecurity guidance is a useful starting point, while the NIST patch-management practices provide a more detailed reference for organizations formalizing their process.
Define the baseline before choosing tools
Do not begin with a product name. Begin with the result you need to prove. A tool is useful only if it can deploy the control, report its status and help someone respond when the control fails.
Create an inventory containing each device owner, operating system, hardware model, business role, encryption status, management status, security-agent status and last check-in time. Include laptops, desktops, shared workstations and administrator devices. Treat unsupported or unmanaged devices as exceptions that require an owner and a deadline.
A reasonable small-business policy can use the following minimum standards:
- Supported software: Devices must run an operating-system version that still receives security updates from its vendor. Applications that handle business data, browsers, remote-access tools and document software must also be maintained.
- Patch timing: Enable automatic updates where practical. Establish a risk-based deadline, such as applying ordinary security updates within 14 days and prioritizing actively exploited or business-critical vulnerabilities much sooner. Test updates on a small pilot group when operational risk warrants it.
- Encryption: Require full-volume encryption on business laptops and any desktop that stores sensitive data. Escrow recovery keys in an administrator-controlled system; do not rely solely on a key stored with the user.
- Malware protection: Real-time protection, cloud-delivered detections where available, automatic security intelligence updates and tamper protection should be enabled.
- EDR coverage: Devices that access sensitive systems, administer infrastructure or represent a high business-impact role should have EDR or an equivalent managed detection capability.
- Local protection: Require a host firewall, automatic screen lock, strong sign-in protection and removal of routine local administrator rights.
- Peripheral policy: Define whether USB storage is allowed, audited, restricted to approved devices or limited to encrypted media.
- Verification: Review compliance reports regularly and investigate devices that have not checked in, missed patch deadlines or disabled protection.
Patching and software maintenance
Patch management is not simply turning on automatic updates. It is the complete cycle of identifying software, evaluating updates, deploying them, checking results and handling exceptions.
Recommended patch-management workflow
- Maintain an inventory. Know which operating systems, browsers, productivity applications, VPN clients, remote-management agents and line-of-business applications are installed.
- Use supported versions. A security product cannot compensate indefinitely for an operating system that no longer receives vendor security updates. Replace or upgrade unsupported devices.
- Enable automatic updates. Use a management platform to configure update behavior rather than relying on every employee to make the correct choice.
- Use pilot deployment where necessary. Test updates on representative devices before broad deployment if a business application or specialized hardware could be affected.
- Set deadlines and exceptions. Document how quickly critical updates must be installed, who can approve a delay and when an exception expires.
- Verify installation. A policy is not complete until you can report patch status, failed installations, pending restarts and devices that have stopped checking in.
CISA has repeatedly recommended a formal software and patch-management program, and its ransomware guidance includes timely updates, endpoint protection and application allowlisting or EDR among useful defensive measures. See the CISA guidance on routinely exploited security controls and the StopRansomware Guide.
Verification questions
- Can you list every endpoint that missed the patch deadline?
- Can you identify devices running an unsupported operating system?
- Do updates continue when a laptop is away from the office?
- Are users reminded to restart when a security update requires it?
- Can an administrator prove that a high-risk update was installed?
Encryption standards for Windows and macOS
Encryption protects data when a device is lost, stolen or accessed outside the normal operating environment. It does not replace account security, malware prevention or backups. A user who is already signed in, or an attacker with access to an active session, may still be able to access files.
Windows
Use BitLocker on supported Windows devices and store recovery information under administrative control. Microsoft Intune compliance policies can require BitLocker and can also evaluate operating-system requirements and Microsoft Defender risk signals. The relevant Windows compliance settings documentation describes these controls.
For managed Windows fleets, review Microsoft security baselines rather than inventing every setting from scratch. Microsoft describes its Defender and Windows security baselines as groups of recommended settings that can be assigned, monitored and customized through Intune. See the Microsoft Defender security baseline guidance.
Verify at least the following:
- BitLocker is enabled on the operating-system volume.
- The recovery key is escrowed and access to it is restricted.
- The device has checked in recently with the management platform.
- The user does not routinely operate as a local administrator.
- Windows Firewall is enabled for domain, private and public network profiles as appropriate.
- Security intelligence and the endpoint agent are current.
macOS
Use FileVault for Mac computers that store business data. Apple documents FileVault as the built-in capability for protecting data at rest and supports organizational management of recovery keys through device management. For current deployment details, see Apple’s Managing FileVault in macOS documentation and the Apple Business FileVault configuration guide.
For managed Macs, use an MDM service to enforce FileVault, escrow a personal recovery key, configure password and lock-screen requirements, and manage software updates. Avoid treating the recovery key as a document that the employee keeps in a desk or personal cloud account.
macOS also includes Gatekeeper, notarization controls and XProtect. Apple describes XProtect as built-in malware protection that receives automatic security updates. These protections are valuable, but a business may still choose a third-party EDR platform when it needs centralized telemetry, investigation, isolation or cross-platform response. Apple’s macOS malware-protection documentation explains the platform’s built-in layers.
EDR versus antivirus for a small business
Traditional antivirus focuses primarily on preventing or detecting malicious files and activity on an endpoint. EDR adds centralized telemetry, behavioral detections, investigation tools, alerting and response actions such as isolating a device, depending on the product and license.
The distinction is practical rather than absolute. Modern endpoint-protection products often combine antivirus, behavioral protection, attack-surface reduction and EDR features. The important question is whether your organization can see and respond to suspicious activity, not whether a product label contains the word “EDR.”
Antivirus may be sufficient when:
- The business has a small, low-complexity fleet.
- Devices primarily use cloud applications with limited administrative access.
- A trusted IT provider monitors alerts and performs response work.
- The business has strong identity controls, tested backups and a clear incident process.
EDR is more appropriate when:
- The business handles sensitive personal, financial, health or customer information.
- Endpoints administer servers, cloud infrastructure or security systems.
- The company needs centralized investigation and device-isolation capabilities.
- There is no internal security team but a provider can monitor and respond to alerts.
- The organization must investigate suspicious scripts, credential theft, persistence or lateral movement.
Do not buy EDR without assigning responsibility for alerts. An unattended dashboard can create a false sense of security. Evaluate whether the provider offers monitoring, triage, escalation, containment and reporting, and clarify what happens outside business hours.
Device control and removable media
USB storage can introduce malware, enable unauthorized copying or create an untracked path for sensitive data. A blanket block may be appropriate for some roles, but many businesses need a more nuanced policy.
Start with an inventory of legitimate use cases: encrypted backup media, shipping or manufacturing equipment, printers, mobile devices, cameras or vendor troubleshooting. Then choose one of these operating models:
- Block by default: Deny removable storage unless a documented exception is approved.
- Read-only: Allow users to read from approved media but prevent writing.
- Encrypted media only: Permit only company-approved or encrypted removable storage.
- Audit first: Log usage for a trial period, review the business need and enforce restrictions after users understand the change.
Microsoft Defender for Endpoint supports device-control policies for removable storage and other peripherals on supported Windows and Mac configurations. Its policy model can allow, deny or audit access and can match devices, users and access types. See Microsoft’s device-control overview and device-control policy reference.
Test device-control policies with real printers, phones, encrypted drives and business applications before enforcing them. A poorly scoped rule can block legitimate work or create pressure for employees to bypass the control.
Tool-selection matrix
| Capability | Minimum acceptable approach | Preferred for a growing business | Questions to ask |
|---|---|---|---|
| Device management | Central inventory and configuration | MDM with compliance reporting and remote actions | Can it identify stale or unmanaged devices? |
| Patching | Automatic operating-system updates | Deadlines, pilot rings, third-party application coverage and reports | Can it show failed updates and overdue restarts? |
| Malware protection | Real-time protection and automatic updates | Central policy, tamper protection and alert integration | Who reviews detections? |
| EDR | Not always required for every low-risk endpoint | Managed detection, investigation and isolation | What response actions are included in the license? |
| Encryption | BitLocker or FileVault enabled | Central enforcement and recovery-key escrow | Can administrators recover a device without the user? |
| Device control | Documented USB policy | Allow, deny and audit rules with exceptions | Can policies be tested before enforcement? |
| Reporting | Periodic manual review | Automated compliance and alert dashboards | Can reports be exported for audits or insurance? |
Business laptop security checklist
Use this checklist during deployment and review it at least monthly:
- Record the device owner, serial number, operating system and business role.
- Enroll the device in the organization’s management platform.
- Install all current operating-system and application security updates.
- Enable BitLocker or FileVault and verify recovery-key escrow.
- Enable the host firewall.
- Enable real-time malware protection and automatic security intelligence updates.
- Enable tamper protection where supported.
- Install and verify the EDR agent if required by the device’s risk classification.
- Remove unnecessary local administrator privileges.
- Configure automatic screen lock and require a strong sign-in method.
- Set browser, scripting and application policies appropriate to the business.
- Apply a USB and removable-media policy.
- Confirm the device can be remotely locked, isolated or wiped when the platform supports those actions.
- Test a recovery-key retrieval procedure without exposing the key unnecessarily.
- Document the process for lost, stolen, compromised or unsupported devices.
How to verify the baseline
Verification should produce evidence, not just a green-looking dashboard. Sample a set of devices each month and confirm their actual state. Check the last management check-in, operating-system version, patch age, encryption status, recovery-key escrow, security-agent health, firewall status and local administrator membership.
Run a controlled test for key workflows: trigger a harmless security-alert test supplied by your endpoint vendor, confirm that an approved USB exception works, verify that an unapproved device is blocked or audited as intended, and retrieve a recovery key through the authorized process. Do not use live malware for testing.
Track exceptions with four fields: the affected device, the failed control, the business reason and the expiration date. An exception without an owner or end date becomes the permanent baseline.
Recommended starting point
For many small businesses, the most effective sequence is:
- Inventory every endpoint and remove or isolate unknown devices.
- Enroll Windows PCs in a management platform and Macs in an MDM service.
- Enable automatic patching and create a documented deadline for security updates.
- Enforce BitLocker or FileVault with recovery-key escrow.
- Enable built-in malware protection, firewalls, screen locks and tamper protection.
- Adopt EDR for high-value or high-risk devices, ideally with managed monitoring.
- Start with audited USB controls, then enforce a least-permissive policy based on real business needs.
- Review compliance monthly and test one recovery or containment procedure each quarter.
The goal is not to make every endpoint identical. The goal is to make the minimum security state clear, centrally visible and difficult to bypass. A small business with consistent patching, encryption, malware protection, responsible monitoring and tested response capability will be in a stronger position than one with many disconnected security products and no verification process.
