Enterprise Technology

Enterprise Technology

10 min

IT security in remote equipment: the risk that starts in the hardware

IT security in remote equipment: the risk that starts in the hardware

Matias Lerner

Primer informe con datos propios de la operación de First Plug. Período: enero–junio 2026.

Tech companies invest time and resources in protecting their systems: cloud permissions, two-factor authentication, access to SaaS tools. All of that matters. But there is a layer of security that always gets left out of that conversation: physical hardware.


The laptop of the person who resigned last month. The equipment that was never recovered. The device that arrived without MDM and is today, basically, a black box with your company's credentials inside. In remote teams scattered across several countries, this problem is more common than it seems.


Do you know who has access to your company's data right now?


Here we explore the problem in depth. And we show you solutions that several of the companies we work with are already applying.


The risk vector that security teams usually ignore


When discussing data security in a tech company, the conversation always revolves around the same things: passwords, cloud permissions, two-factor authentication, access to SaaS tools. All of that matters and needs to be in order. But there is another vector that comes up much less: physical hardware.


Think of three typical cases. The laptop someone took when they resigned. The equipment left at a collaborator's house after a poorly executed offboarding. The device that was never recovered because the process was complicated or no one claimed it in time. Those physical assets are still real access points to the company's systems. And in many cases, no one is monitoring them.


It's not a problem of bad intentions. It's a management problem. And it's more common than it seems.

The three most common scenarios of involuntary data exposure


It doesn't take a sophisticated attack for sensitive information to be exposed. In most cases, the problem isn't a hacker. It's day-to-day operations, executed without proper controls. These are the three scenarios we see most frequently:

  1. The equipment that was never recovered. An employee leaves the company. The equipment remains at their home. No one followed the recovery process. Months later, no one knows where that device is or who is accessing what was inside.


  2. The access that was never revoked. The IT department revoked access to the corporate email, but forgot about three critical SaaS tools. The former employee can still log in. Sometimes for weeks. Sometimes for months.


  3. The device without security configuration. A device was delivered without MDM, without disk encryption, and without access policies. If it is lost or stolen, the data is accessible to whoever finds it.


All three have something in common. They are not the result of a technical breach. They are the result of processes that were not executed, or that simply did not exist.

Profesional de IT trabajando en laptop en un entorno de infraestructura tecnológica.

Offboarding without protocol: the most vulnerable moment in the employee lifecycle


Onboarding gets all the attention. There are checklists, there are processes, there are people assigned to ensure the new employee is operational from day one. Offboarding, on the other hand, is usually improvised. When someone resigns or is dismissed, energy goes toward the transition, covering the role, and finding a replacement. The operational aspects are postponed.


What remains pending? A laptop at a private home, with saved credentials, open sessions, and downloaded files. And that is a problem. Offboarding is the moment when most things can be left poorly closed. Unrevoked access. Unrecovered equipment. An active account that nobody disabled. Every single one of those points is a vulnerability that persists over time.


In remote and distributed teams, the problem multiplies. There is no office where someone picks up the equipment on the last day. Nor is there an IT department that physically sees that the device has returned. Offboarding happens virtually, incomplete, and often without a checklist to back it up.

Colaboradora remota recibiendo y configurando su laptop junto a la caja de envío.

What promises to be the solution to this problem: what is MDM?


MDM stands for Mobile Device Management. It is a solution for remotely managing, monitoring, and controlling a company's devices. With MDM, you can see which applications are installed. You can force security updates. You can restrict certain uses. And, in case of loss or theft, you can remotely wipe the device's content.


Without MDM, your company's devices are basically black boxes. You don't know if they have an updated operating system. You don't know if someone installed unauthorized software. You can't wipe a computer remotely if it gets lost or if someone leaves suddenly. You have no real visibility into what happens on those machines once they leave the controlled environment. If there ever was a controlled environment.


With equipment scattered across several countries, and hardware in dozens of different homes, the absence of MDM is not a minor detail. It is a structural security hole.


With MDM vs. without MDM: the difference in practice

Capability

With MDM

Without MDM

Device visibility

Status, installed apps, and operating system in real time

No information

Security updates

Forced remotely

Depend on the user

Remote wipe

Available in case of loss, theft, or offboarding

Not possible

Application control

Configurable whitelists and blacklists

No control

Disk encryption

Verifiable and enforceable by policy

Not verifiable

IT Offboarding

Wiping and documented device recovery

Manual process without guarantees

Incident response

Immediate and remote

Requires physical access to the device

Signs that your company needs MDM


In many LATAM companies, device management doesn't start with a "we want an MDM." It starts with small signs that accumulate: more remote work, more access points, more apps, and less and less control. If you recognize two or more of these scenarios, MDM is no longer just a nice-to-have:

  • You don't know how many corporate devices are active. If you had to take an inventory today, it would take you days, and even then, doubts would remain.


  • There were offboardings in the last six months and you cannot confirm that all devices were recovered. Not because no one wanted to, but because the process did not exist or was not completed.


  • Employees use personal devices to access corporate tools. Without separating the personal and professional environments, company data gets mixed up with private accounts.


  • You cannot remotely wipe a lost or stolen device. If tomorrow you are notified that a laptop was stolen at an airport, you have no way to protect what is inside.


  • Security updates depend on each person doing them on their own. This means there are surely devices with months of unapplied patches.


  • You have never had visibility into what apps are installed on the devices. Someone could have third-party software with access to the network without anyone knowing.

Why MDM matters especially in LATAM


In Europe or North America, MDM has already been a standard practice in companies of a certain size for years. In LATAM, adoption is still maturing. And that has concrete consequences for startups in the region.

  • The regulatory framework is tightening. Brazil has its General Data Protection Law and Mexico has its Federal Law on Protection of Personal Data. Both laid the foundations for a new regulatory wave. Chile, Argentina, and Colombia are on the same path, with reforms to regulate data use in new technologies. A company that cannot demonstrate control over its devices has a hard time complying with any of these frameworks.


  • Geographical expansion multiplies risk without multiplying controls. A startup that starts in Argentina and expands to Colombia, Mexico, or Chile suddenly has hardware in several countries with different legal contexts. Without MDM, that distributed fleet is impossible to manage consistently.


  • Devices travel and change hands more often. In LATAM, remote teams, variable connectivity, and high turnover in the tech sector combine. Therefore, devices change hands, locations, and contexts more than in stable markets. This increases exposure.


  • The trust of international clients is also at stake. Multinationals operating in LATAM expect safety standards from their suppliers aligned with their own. A data incident due to an unmanaged device can cost more than just that client. It can cost market reputation.

What an IT offboarding process should include so as not to leave any loose ends


A well-executed IT offboarding is not bureaucracy. It is basic operational hygiene. And in distributed remote teams it is even more critical, because the risks are less visible. These are the elements that cannot be missed:

  • Same-day access revocation. Email, SaaS tools, internal systems, repositories. Everything, on the day of departure.


  • Documented hardware recovery. With a clear return protocol, recovery date, and condition confirmation. If the equipment cannot be recovered immediately, there must be a concrete plan to do so.


  • Remote wipe if applicable. If the device has MDM, the wipe is executed once the device has returned and the data has been backed up. If it does not have MDM, that wipe is not possible. And that is exactly the problem.


  • Active session audit. Check if there are open tokens or sessions in critical apps that do not close on their own when access is revoked.


  • Asset inventory update. The device must be removed from the employee's name. And, depending on the case, return to stock, go to maintenance, or be decommissioned in a documented manner.


Hardware is part of security, not a separate issue


For a long time, hardware management was thought of as a logistics problem. How does the equipment reach the employee? Who coordinates the shipping? Who pays for the insurance?


Those questions remain relevant. But there is a deeper layer that many companies are still not seeing: hardware is also a security vector. The way you buy, configure, distribute, monitor, and recover devices has a direct impact on your data exposure.


At First Plug, we work right at that intersection. We don't just make sure the equipment arrives well and on time. We also ensure it is configured, that it is recovered with a protocol when someone leaves, and that there is visibility over every asset throughout its entire lifecycle.

Primer informe con datos propios de la operación de First Plug. Período: enero–junio 2026.

Does your company have real visibility over its devices?


Security doesn't end with access and passwords. It starts with knowing where your devices are, who is using them, and what happens to them throughout their entire lifecycle.

Does your company have real visibility over its devices?


Security doesn't end with access and passwords. It starts with knowing where your devices are, who is using them, and what happens to them throughout their entire lifecycle.

Written by

Matias Lerner

Matias Lerner

You might also be interested in…

WhatsApp logo

Ready to take the next step?

G2 logo.
""

Ready to take the next step?

G2 logo.
""

Ready to take the next step?

G2 logo.
""