The endpoint blind spot: what your fleet is actually doing
Ask a CISO what keeps them up at night and the answer is rarely the perimeter. It's the three hundred laptops between the perimeter and the data — unmanaged, unmonitored, and one missed patch away from being the story. This piece is about what we found when we started counting.
“The breach didn't come through the firewall. It came through a laptop that had been three patches behind since March, and nobody had looked at it since the day it was issued.”
A postmortem that started with a shrug
A 220-person logistics firm we work with had a data-exposure scare last year — a departing sales rep's laptop turned up with two years of client pricing sheets synced to a personal cloud folder. Nothing malicious, no ransomware, no headline. Just a laptop nobody had looked at since onboarding, doing exactly what an unmanaged endpoint does when nobody is watching: whatever the user's default settings allow.
The postmortem was the uncomfortable part. IT could not say, for any given machine in the fleet, whether disk encryption was on, whether the OS was patched, or whether antivirus was actually running rather than just installed. The answer to 'how many machines are in this state' was a shrug, not a number.
That gap — not a sophisticated attack, just an absence of a number — is the one we hear about most often when a mid-size company finally looks.
Why traditional endpoint security skips this tier
Enterprise EDR platforms are built for security teams with a SOC to staff them: a dedicated analyst triaging alerts, a budget for the licence, and the headcount to investigate every flagged event. A 50-to-500-person company usually has none of the three. So endpoint security becomes a line item that got bought once, configured never, and reviewed at renewal time if at all.
The result is a strange inversion: the companies most exposed to an unmanaged fleet are the ones least equipped to run the tools built to manage it. What they actually need is smaller — a plain answer to 'which machines are non-compliant right now' — and most of the market doesn't sell that on its own.
This is the gap Momentum's endpoint security module is built for: posture checks and fleet risk, not a SOC replacement.
Three signals, not thirty
We deliberately kept the posture check list short: disk encryption, patch level, and antivirus status, evaluated per machine and rolled into one compliance percentage for the fleet. Every finding is a plain version comparison against a release catalogue — never a claimed CVE match or an inferred severity score. A fact, not a risk rating dressed up as one.
In the accounts we've watched roll this out, the fleet compliance number typically opens in the 60-80% range and climbs past 90% within a month, purely from IT finally having a punch list instead of a hunch. Nobody needed new hardware. They needed to know which fifteen machines to chase first.
Ranking matters as much as the checks themselves. A flat list of 300 machines is useless. A list sorted by risk, worst first, is a Tuesday afternoon's work.
The DLP question nobody wants to own
Data-loss visibility is the feature every IT lead wants and almost none will admit to wanting out loud, because the word surveillance is right there waiting. Our answer is to keep it observational: files copied, flagged transfers, and where they went — never the contents of what moved. The agent records and queues quietly; it cannot block, close, or interrupt anything on the device.
That distinction is not a compliance nicety, it's what makes the feature usable. A tool that blocks transfers turns into a stream of support tickets and workarounds within a week. A tool that shows a pattern — six months of clean history, then a burst of large transfers to an unrecognised destination the week before a resignation — gives a human something to act on, calmly, without an alarm going off on someone's screen.
What doesn't work
We've watched the alternatives fail in fairly consistent ways. Annual manual audits catch the state of the fleet on one day a year and miss the other 364. Enterprise EDR bought and left on default settings generates more alerts than anyone reads, which is functionally the same as having none. And a spreadsheet of asset tags updated by whoever remembers to update it decays within a quarter.
The common failure mode isn't a bad tool — most of these products work. It's that they demand ongoing attention from a team that doesn't have it to give. Anything that requires a dedicated analyst to be useful will, in a 200-person company, simply not be used.
Where to start Monday
Pull the fleet compliance number for whatever agent-managed devices you already have. If you don't have one, that's the first gap to close — you cannot fix what you can't see. Sort by risk and clear the top ten highest-risk machines this week; it's usually a patch, an encryption toggle, or a reinstalled antivirus client, not a hardware problem.
Then leave the data-movement view running quietly in the background for a month before you look at it again. Most of what it shows will be nothing. The value is in the one week it isn't.
If you only remember four things
- The median knowledge worker switches application context every one minute and 52 seconds, far more often than managers estimate.
- Chat drives only about a third of switches; self-directed habits and multi-system workflows account for the rest.
- Protected 90-minute blocks with rotating interrupt coverage cut complex-ticket handle time 18 per cent in a 40-person support org without hurting customer satisfaction.
- Fix the largest structural source of switching before running any behavioural campaign, then re-measure after three weeks.
Writes for The Signal about security and the future of measurable, humane work — drawing on anonymised patterns from the teams and focus hours analysed on Momentum.
Want this picture for your teams?
See timelines, productivity scores, and department comparisons on your own data.
Book a demo