Securing 100+ laptops for a national health charity
A charity needed its whole laptop fleet brought up to a security-audit standard — encrypted, patched and provably compliant. Our team delivered it, with the evidence to prove it.
The challenge
A national health charity with staff spread across offices and home-working had a laptop estate that had grown without a consistent security baseline. Devices ran a mix of Windows versions, encryption wasn’t enforced everywhere, and patching was inconsistent — exactly the gaps a security audit is designed to find.
With a Cyber Essentials–style assessment ahead, they needed every machine brought up to standard, and they needed to be able to prove it to auditors — not just assert it.
What we did
Our team worked through the estate methodically:
- Encryption everywhere — built and deployed BitLocker and Secure Boot policies to enforce full-disk encryption across 100+ managed laptops, so a lost or stolen device is a non-event, not a breach.
- Patch compliance — tightened operating-system and third-party patching through NinjaOne, and increased its aggressiveness so machines stayed current instead of drifting out of date.
- One source of truth — aligned the device inventory across Intune, Entra ID and NinjaOne, and removed stale, duplicate and inactive records so reporting reflected reality.
- New devices, ready to work — built, encrypted and configured 20 new laptops to the charity’s standard and dispatched them to users.
- Version remediation — identified machines on older Windows builds and worked through the upgrades to bring them to a supported, compliant version.
- Evidence for the auditors — produced clear documentation showing the encryption and patch state across the fleet, on a tight deadline.
The result
The charity went into its assessment with an encrypted, patched and consistently-managed laptop fleet — and, crucially, the evidence to demonstrate it. A sprawling, inconsistent set of devices became audit-ready, fully-managed endpoints, with monitoring in place so compliance is maintained rather than rebuilt from scratch every audit cycle.
Honest about who did the work
This work was delivered by our team. We’ve anonymised the client out of respect for their privacy — but the work, the numbers and the outcome are real. If you’re facing a security audit, or you simply know your device estate has drifted, it’s the kind of thing we handle as part of managed IT support and cyber security.
Services we used
Got a project like this?
Tell us what you're trying to fix and we'll come back with a clear, no-obligation plan and price.
