COMMENTARY: A device refresh is a good time for channel partners to fix security gaps before new equipment goes live. Every laptop, printer, or kiosk adds another device, login, and access point to manage. By reviewing authentication, permissions, and endpoint controls during deployment, partners can help customers avoid bigger and more costly problems later.
Every new laptop, printer, kiosk, or connected device helps customers work more efficiently. For channel partners that advise customers on technology purchases and deployments, each new endpoint represents both an opportunity and a responsibility to address security risks from the start.Recent guidance from the Cybersecurity and Infrastructure Security Agency (CISA) underscores how weaknesses in the tools used to manage connected devices can create opportunities for attackers. Following a cyberattack against a medical technology firm, the agency urged organizations to strengthen endpoint management system configurations and access controls, emphasizing the importance of securing those management systems.As organizations continue to expand their technology footprints, the consequences of overlooking endpoint security continue to grow. And channel partners are best positioned to help them identify where a single compromised device, weak credential or misconfigured management system can provide attackers with access to sensitive data, critical systems and business operations.Device refresh projects, whether they involve replacing aging hardware or deploying new equipment, create a natural opportunity to address those risks before endpoints go live.Security conversations that happen during a device refresh project can help customers avoid costly incidents long after the rollout is complete.The recent CISA guidance serves as a reminder that management systems deserve just as much attention as the devices they support. Administrative tools often provide broad visibility and control across an environment, making them attractive targets for attackers.As customers add new endpoints, review which users have administrative access, how permissions are assigned and what safeguards exist around high-risk actions. Access controls that seem minor during deployment can create significant risk if privileged accounts are compromised later.Evaluate each endpoint's role in the environmentNot every endpoint carries the same level of risk. A networked printer, a shared kiosk and an executive laptop may all require different security considerations based on how they’re used and the information they can access.Before deployment, help customers understand how each device interacts with networks, applications and critical systems. Identifying high-risk endpoints early can make it easier to prioritize security controls and address potential vulnerabilities before they become larger issues.Make authentication part of the refresh conversationWeak or compromised credentials can undermine even well-secured devices. According to Verizon's 2025 Data Breach Investigations Report, compromised credentials were used as an initial access vector in 22% of breaches.Use the refresh as an opportunity to evaluate how users authenticate to devices and systems across the environment. Strengthening authentication controls through phishing-resistant methods and passwordless approaches can help reduce credential-related risks while creating a more consistent user experience.Build ongoing security reviews into the deployment planSecurity considerations should continue long after devices are installed. New threats, changing user needs and evolving business requirements can all introduce risk over time.Encourage customers to establish a process for reviewing device configurations, user access and security policies on a regular basis. Ongoing reviews can help identify issues before they become larger problems while ensuring endpoints continue to align with organizational security requirements.
ChannelE2E Perspectives columns are written by trusted members of the managed services, value-added reseller, and solution provider channels or ChannelE2E staff. Do you have a unique perspective you want to share? Check out our guidelines here and send a pitch to [email protected].
You can skip this ad in 5 seconds




