Managed or Merely Owned: The Endpoint Question in Operational Due Diligence
Updated: 1 day ago
Allocators have grown more specific about endpoints. The question used to be whether the firm had a mobile device policy. Now it is what percentage of devices are enrolled and managed, and the answer is either a figure or an evasion. At your firm it is a figure, because every device we deploy is enrolled before it reaches the person using it. Today's post covers why that question has climbed the diligence agenda, and a change we now offer to how those devices get onto your network.
THE BOUNDARY IS THE DEVICE NOW
The office network stopped describing the edge of an investment firm years ago. Order management, research, reporting, and the fund's books sit in platforms reached from wherever a principal happens to be, which in this business is often an airport or a house in Connecticut on a Sunday. The device in hand is the boundary, so the estate divides cleanly: a device is either enrolled under firm management, or it is not.
THE DEVICE BECOMES THE CREDENTIAL
Start with the least examined control in most firms. Access to the office Wi-Fi network is granted by a shared password every employee knows, along with the consultant who visited in 2019 and the analyst who left in March. It’s almost never changed, because changing it means retyping it on every device in the building. The jack in the conference room wall asks for even less than that: nothing. In a diligence review, both are findings waiting to be written.
Roark now offers a different arrangement. Instead of a password, each managed device carries a digital certificate: a credential built into the device that identifies both the device and the person it belongs to. On Wi-Fi, the device presents that certificate and joins. Nobody types anything, so there is no password to forget, none to share with a colleague, and none to type into a fake login page by mistake. A device without a certificate cannot join at all, which is the real change: the office Wi-Fi is no longer something anyone can be let onto with a phrase written on a card. Guests get a separate guest network, which is where they belong.
The same test applies to the network jacks in the wall. When a laptop is plugged into a port in a conference room or an empty office, that port carries nothing but the authentication exchange until the device proves who it is. A managed device passes and the port opens. Anything without a certificate stays exactly where it is, connected to a wall and nothing else. Certificates are installed automatically when we set up a device, and they are tied to your firm's authentication system, whether that is Microsoft, Okta, or Google, so a person's access to the network is governed by the same account as their access to email and files. We adopted this as our standard and are moving client environments onto it.
Three points matter for your business. Nobody can be tricked into giving away a password that doesn’t exist. When someone leaves the firm, the certificate is switched off with their account, so their access to the network ends at the same moment as their access to positions and email. And the control is one that a reviewer can verify, which is more than can be said for a shared password and a good intention.
THE ARTIFICIAL INTELLIGENCE MOVED ONTO THE DEVICE
There is a second reason this matters more than it did a year ago. Artificial intelligence moved into the phone and the laptop themselves. New versions of Apple's software arrive this month, and Windows is heading the same way. These features are built to be helpful, and to be helpful they read the files on the device, summarize email, and keep track of what appears on the screen. Some of them send that material to a service outside the firm to do the work. For a firm holding non-public information about companies, counterparties, and their own positions, that is a governance question rather than a matter of personal taste. Almost all of it can be turned on or off, so the only real question is who makes that choice. On a managed device, your firm makes it. On a device nobody manages, the manufacturer makes the choice, and manufacturers set their defaults for the public rather than for a firm that keeps client confidence.
A survey published this year asked firms a useful question: when you have a rule about how company information may be handled, does anything enforce it? On company-managed computers and phones, the rule was enforced 29 percent of the time. On personal devices nobody manages, 6 percent. And only one firm in ten could reliably tell approved use of artificial intelligence from unapproved use. A rule written in a policy document and nowhere else is not really a rule. Managing the device is what turns it into one.
EQUIPMENT IS STAYING IN SERVICE LONGER ON PURPOSE
We wrote about the cause last week. The price of memory climbed far enough that keeping computers longer is now the correct capital decision rather than a postponement of one, with one condition attached: somebody must keep track. Research published this spring found about one enterprise computer in ten is still running Windows 10, which stopped receiving security updates last October. We keep an inventory of software versions, patch age, the encryption status, and the remaining supported life of every device in your environment, so a longer service life at your firm is a documented choice. That distinction is what a reviewer tests when the endpoint questions start.
THE PERSONAL DEVICE IS A RECORDS QUESTION FIRST
The part of this specific to your business has less to do with malware than with recordkeeping. A principal's own phone carrying firm business is an off-channel communications exposure, and the Advisers Act books and records obligations under Rule 204-2 do not soften because the message was convenient. Regulators have shown considerable appetite on the point, and allocators ask about it.
We handle this in the setup of the devices themselves, rather than with an email asking people to be careful. Any phone or laptop used for firm business is enrolled. Firm messages travel through the firm's own email and messaging systems, where they are automatically saved and kept for as long as the rules require. When someone leaves the firm, or stops using a personal phone for work, we remove the firm's email, files, and network access from that device the same day. Everything personal on it stays exactly where it was. New phones arrive at the firm all the time. Each one is a device to enroll, not a policy to rewrite.
The sticking point on a personal phone is always the same question: once the firm manages the device, what can the IT people see? The plain answer is very little. Enrollment puts the firm's apps and data in their own locked compartment. Your messages, photographs, browsing, and personal apps sit outside it, and the phone keeps them there. We cannot read your messages, see your photographs, or look at your browsing history, and we can’t track anyone’s location.
There is one exception, and we would rather tell you about it than have you find out on your own. We can erase a phone completely, wiping everything on it. We do that when a phone is lost or stolen and its owner asks us to, and that is the only time.
The firm keeps the records the regulators require, and nobody, at the firm or at Roark, ever sees what is on the personal side of the phone.
WHAT IT PRODUCES BEYOND THE DILIGENCE ANSWER
Most of the benefits of managed devices show up on days when nothing goes wrong. A new analyst starting on Monday finds a laptop already set up, already protected, and already able to get on the network, with no first-day scramble. When someone leaves, their access is gone by that afternoon rather than a week or two later, which matters when the person who left knew the fund's positions. And when an investor's due diligence questionnaire asks how the firm's computers and devices are managed, we already have the answer written down. We print the list. Nobody reconstructs it from memory.
It is worth describing what the other way looks like, because it’s common. Firms with unmanaged devices seldom find out through a break-in. They find out when a questionnaire asks a question nobody can answer. Or when someone leaves and, weeks later, nobody is sure what that person can still get into. Or the week a software update switches on a new feature that nobody chose and nobody noticed. None of those is an emergency. All of them are avoidable, and the avoiding gets done in advance, on ordinary mornings, which is where it has already been done for you.
Since 1998, Roark Tech Services has been the IT partner of choice for alternative investment firms that expect expertise, accountability, and an owner who still answers the phone. We support clients in 21 cities across four continents. We do not do standardized. We do not do anonymous. We do bespoke, and we have since before most of our competitors existed.




