Skip to main content
Security & Endpoint Protection

Endpoint protection and IT security for Gauteng businesses

A business laptop leaves the office, an employee changes phones and a new user needs access to company files. CJN IT Solutions helps small and medium businesses in Pretoria, Centurion, Midrand and Johannesburg put practical protection around their Windows devices and Microsoft 365 accounts, using Trend Micro Worry-Free Business Security Services, BitLocker drive encryption, two-factor authentication, Conditional Access and supporting IT policy documentation where required.

Since 2003
Pretoria & Gauteng support
Fixed-cost support
Microsoft 365 support

A practical baseline

Protection that works around routine events: a replaced laptop, a new phone, a user whose access was never reviewed.

  • Endpoint protection on covered devices
  • Drive encryption where supported
  • Authentication that staff can actually use

Devices accounted for

A protection plan needs to reflect the computers people actually use, including replacements and equipment no longer in service.

  • Which computers belong to the business
  • Whether agreed protection is installed
  • What happens when a device is retired

Rules that match reality

A sign-in rule can block legitimate work if it does not reflect how and where staff actually work.

  • Conditional Access reviewed first
  • Licensing implications identified
  • Policy documentation that matches the setup

This is a practical IT baseline service

These are the everyday controls that keep device and account management consistent. It is not a specialist penetration testing, forensics or security operations service, and specialist work of that kind sits outside this scope.

Start with an accurate device list

A protection plan needs to reflect the computers people actually use. An SME may have office desktops, travelling laptops, replacement devices waiting to be configured and older equipment that is no longer in regular use.

Start by identifying which computers belong to the business, who uses them and whether the agreed protection is installed and working. That makes it easier to spot gaps when a device is replaced, reassigned or retired.

CJN supplies and supports business hardware as well as endpoint protection. We can discuss the device and its configuration together, including whether it supports the controls the business wants to apply.

Trend Micro protection for business devices

CJN supplies, configures and supports Trend Micro Worry-Free Business Security Services.

Endpoint protection helps detect and respond to malicious software on the computers selected for coverage. It needs to remain installed, current and working as equipment changes.

A new laptop needs the agreed protection before it is handed to the user. A retired computer needs to be accounted for. If the product reports a problem or a device needs attention, the support responsibility should be clear.

The Trend Micro subscription and agreed service scope determine the exact coverage and management responsibilities. Those details should be stated in the proposal.

BitLocker drive encryption and recovery keys

BitLocker encrypts the drive on compatible Windows devices, helping protect stored information against unauthorised access when the device is appropriately secured.

CJN helps implement BitLocker on supported business computers. The setup needs to include recovery planning as well as encryption. An authorised user may need assistance if a computer requests its recovery key, so the business needs an approved way to store and retrieve that information.

Compatibility depends on the device and Windows edition. BitLocker also does not replace backups or control everything a signed-in user can do. We check the intended setup and recovery-key handling before implementation.

Two-factor authentication and user enrolment

Two-factor authentication, also called 2FA or MFA, adds another verification step to a sign-in. It is a practical baseline for protecting business accounts.

CJN helps with the technical setup and user support around enrolment. Staff need to know which method they will use and what to do when a phone is replaced or lost. The business needs an authorised recovery process rather than an improvised exception at the moment someone cannot sign in.

Planning the communication and support around enrolment helps the control become part of normal work.

Conditional Access based on working patterns

Conditional Access can apply Microsoft sign-in requirements according to configured conditions, subject to the licences and features available in the environment.

CJN helps implement Conditional Access where it is appropriate. We first consider which accounts and applications staff use, whether they work remotely and what devices they use. Those details matter because a rule can block legitimate work if it does not reflect the real environment.

We discuss suitable rules, licensing requirements and rollout considerations before implementation. We do not assume every Microsoft 365 subscription includes the same capabilities.

For mailbox configuration, user administration and collaboration support, see Microsoft 365 support.

Policy documentation that reflects the technical setup

Where required, CJN helps create IT policy documentation that supports the controls being implemented. Useful subjects may include:

  • Acceptable use of company equipment and work information.
  • Approval of account access and changes to permissions.
  • What staff should do when a device or authentication phone is lost.
  • How managers notify IT when an employee joins, changes roles or leaves.
  • Who can approve an exception to the normal arrangement.

Keep protection aligned with everyday IT changes

Management remains responsible for approving the business rules and communicating them to staff. A short policy that matches the actual setup is more useful than a document staff cannot apply.

Adding a user, replacing a laptop or changing remote-working arrangements can affect the protection baseline. Device setup and account administration should include the agreed controls rather than relying on someone to remember them later.

This work can form part of managed IT support. If the concern is recovering information after a device failure or loss, see backup and disaster recovery, or review all business IT services.

What these controls do and do not do

They help reduce common exposure and make device and account management more consistent. They do not guarantee that an incident will never happen. Backups, staff behaviour, maintenance and clear support processes still matter.

Next step

Put the practical baseline in order

If you cannot confirm which laptops are encrypted, how users recover access after changing phones or whether every business computer has the agreed endpoint protection, start with those questions.