| Fortify-RMM | N-able N-sight: health, inventory and patch status across Windows, macOS and Linux, plus mobile device management |
|---|---|
| Fortify-RMM-DNS | N-able N-sight Web Protection: web security, content filtering and bandwidth monitoring on managed devices |
| Fortify-Control | Addigy: Apple device management with configuration enforcement and automated compliance for macOS and iOS |
| Fortify-Mobile | Zimperium: on-device AI threat protection for Android and iOS handsets and tablets |
| Inventory | Hardware, installed software, operating system build, and patch level per device |
| Web visibility | Sites visited, category and reputation, and bandwidth consumed, including private browsing sessions |
| Apple controls | Software deployment, security baselines, remote remediation, and continuous compliance reporting |
| Mobile detections | Zero-day mobile malware, phishing, jailbroken and rooted devices, rogue wireless and interception attempts |
| Mobile architecture | Detection runs on the device and does not depend on cloud connectivity to make a decision |
| Billing unit | Per device, per Apple device, or per handset, per month |
The asset register is fiction and everybody knows it
When we start an engagement, one of the first exercises is comparing the client's device list against what actually authenticates. The gap is never zero. There are laptops issued to people who left, a server nobody has logged into since a migration, a machine in a branch office running an operating system that stopped receiving updates two years ago, and a tablet that a director bought personally and put company mail on.
Every one of those is a control gap that no amount of spending elsewhere covers. Allowlisting cannot protect a device without the agent. Detection cannot alert on a machine it has never seen. Enumeration is unglamorous and it is load-bearing.
Patch level is a security control with an invoice attached
Fortify-RMM runs on N-able N-sight and reports health, inventory, and patch status across Windows, macOS and Linux, carrying mobile device management for phones and tablets. The value is not the dashboard. It is that somebody can answer, in a meeting, how many machines are more than thirty days behind and which ones they are.
That answer is also what your insurer and any serious client questionnaire will ask for. Businesses that cannot produce it tend to discover the cost of that at renewal rather than at audit.
Including the sessions people believe are private
Fortify-RMM-DNS adds N-able N-sight Web Protection, doing web security, content filtering and bandwidth monitoring on the managed device rather than at the network edge, which means it follows the laptop home and into the coffee shop. Visibility covers programmatic and browser-based activity including incognito sessions, with site categories, reputation scores, and consumption per device.
Two uses, and both are worth stating plainly. The security use is blocking the destination at the moment a user clicks something that got past mail filtering. The operational use is seeing where bandwidth and working hours actually go, which is a management question rather than a security one, and we would rather you buy this knowing that.
Two lines that exist because the other tools do not cover them
Fortify-Control is Addigy, an Apple-only fleet platform: configuration enforcement, software deployment, security baselines, inventory, and automated compliance across macOS and iOS, with remote remediation when a device drifts. Apple estates behave differently enough from Windows that treating them as an afterthought is how the drift happens in the first place.
Fortify-Mobile is Zimperium, protecting the handsets and tablets that read your mail and hold your authenticator app. Behavioural models run on the device, so a decision does not wait on cloud connectivity. It covers zero-day mobile malware and phishing, jailbroken and rooted devices, interception and rogue wireless attacks, and risky applications installed from the public stores.
Phones are routinely the least protected device holding the most sensitive session in a small business. They are also the cheapest line on this page.
Management is the prerequisite that makes the rest of the board true
The controls in step one are only as complete as the inventory they were deployed against. A default-deny policy on ninety percent of your endpoints leaves a tenth of the estate running anything it is handed, and the intruder only needs to find one of them.
Buy management to make the other lines honest. It is the cheapest set of rates on the board and the one that most changes whether the expensive ones actually cover what you think they cover.
Where this stops
This is management and prevention, not forensics. Remote monitoring shows you the state of a device now and going forward. It does not reconstruct what happened on a machine before the agent was installed, and it is not an evidence-preservation tool.
Web protection filters and reports on managed devices carrying the agent. It has no visibility into a personal device that was never enrolled, and monitoring staff activity carries employment and privacy obligations in your jurisdiction that are yours to meet.