Vendor Security for Macs-Toronto Case Study

Confidential Client Story:
Apple IT Security for Vendor Screenings

How TUCU secured an all Mac data and design firm so it could pass a formal IT security audit and keep its largest client.

Client Since 2020

RESULTS AT A GLANCE
IT strategy plan icon
Audit Ready

From self assessed questionnaires to passing a formal, evidence based IT security audit.

business growth icon
Largest Client Retained

The controls the audit asked for are now in place and reviewed every year.

scalable it solutions icon
New Clients Secured

Additional high value clients secured with new data security controls.

About The Client

This spotlight is anonymous.

The client is a leading data and design firm. They build high stakes presentation decks, templates and brand systems that large organizations use to present to their own boards, investors and customers.

The work is confidential by nature. A single project can involve unreleased financials, product roadmaps and campaign plans belonging to some of the biggest brands in the world.

The firm runs on Apple devices. Almost every person on the team works from a MacBook, and design work moves fast between full time staff and contract designers.

IT Challenges

BEFORE:

Freelancers on personal devices. Macs with no central security tooling. No device management. No cloud security controls. No data classification. Nothing an auditor could verify.

AFTER:

Every Mac enrolled and managed. Managed accounts through Apple Business Manager. Conditional access on cloud data. Confidential files labelled, encrypted and restricted. Documented evidence for every control.

Their largest client, a global leader, increased channel and partner security requirements.

For years that client accepted a self assessed IT security questionnaire from smaller organizations it did business with. As cyber threats against supply chains grew, it moved to a formal IT security audit for all channel partners, regardless of size. 

That put the firm’s biggest revenue relationship on the line, and it exposed a gap that is common, which is that Macs feel safe. They are well built and they ship with good security features. But a secure computer and IT security are very different things. An auditor does not ask what features a computer has. An auditor asks how data is protected, what you enforce, how you prove it, and what happens if a device goes missing.

To answer those questions, pass their audit, and keep the client, the firm needed security controls applied across the board, quickly.

With experience in channel partner security screenings, TUCU was able to help them move quickly.

“TUCU has been fantastic to work with over the years.”

The Solutions

We started by reading the client’s actual security requirements list line by line, then mapped each requirement to a control we could implement and evidence. No guessing at what the auditor might want.

Controls were organized against NIST Cybersecurity Framework practices. That framework matters here for a practical reason rather than a technical one. It gives you a structure and a vocabulary the person reviewing your answers already knows. 

Specifically, TUCU enabled:

Additional Technical Details:

NIST Framework Alignment

To help our client create a secure environment and to meet NIST best practices, we used Azure Active Directory as the framework for connecting users, computers and cloud applications. We paired it with Apple Business Manager to control device provisioning, and extensive data loss prevention policies with Microsoft tools.

The result is a secure network and stringent company wide policies that can meet and exceed any compliance audit they may face from existing and new data security conscious clients.

Apple Business Manager connected to Entra ID and Microsoft InTune is used to bind Mac devices, applications, and managed Apple ID’s, allowing us to grant or deny access to company data hosted in the cloud. In addition, advanced compliance controls are necessary for this audit and this combination of tools allows our client to pass annual IT audits.

EntraID is Microsoft’s multi-tenant, cloud-based directory and identity management service. It combines core directory services, advanced identity governance, and application access management.

Enforcement of data labelling policies to classify files that may contain sensitive information and apply security controls to those file (i.e. tag a file as “confidential” or “Client X”, which will encrypt it, water mark it, prevent it from being shared, forwarded, printed etc).

Retention labels to maintain specific time frames for automated deletion of Client X’s files.

What Is Happening At The Firm Now

The Managing Director says: “The audit is no longer a stressful event. It is a review of controls that already run every day. That has had a welcome secondary effect for us. Enterprise security questions now arrive early in new business conversations, and we can answer them straight away, which builds trust early with new prospects. What started as a requirement to keep one client turned into something we use to secure more business.”

What Is Next?

The Managing Director says:

“We’re focused on growing the client roster and continuing to expand our reputation as a leading data and design agency that delivers winning decks.”

See more client spotlights.→

Ready for a great IT partner?

Cybersecurity controls are consistent across many industries, but you have your own challenges and workflows. TUCU is here to help you balance both.

Schedule a call to discuss how we can help you.

Book A Discovery Call

Tell us about your IT challenges. Let’s discuss how TUCU might help.