A check can tell you that a configuration needs attention. It cannot, on its own, change that configuration. Hardening and protection do the other parts of the job: reduce the room for an attack, then watch for threats that remain.
First, know what is actually set.
A device assessment compares observed settings with a defined set of recommendations. The CIS Benchmarks are configuration recommendations developed through a consensus process. They provide a reference for discussing a setting, rather than a vague claim that a machine is “secure”. Read about the CIS Benchmarks.
cybee assesses configuration against the CIS Benchmark through 118 checks. The free posture score makes gaps visible. Read that score with the underlying findings and the number of devices assessed. A high score on one Mac says nothing about another Mac that has not reported.
The finding names the control and the device.
Consider who uses the device and what work depends on it.
Hardening changes configuration; assessment alone does not.
A new observation supports a new record.
Choose settings that fit the work.
Different people use devices differently. A founder, a designer and a developer may need different software and access. A useful hardening workflow makes the intended configuration clear before changing it.
cybee’s paid hardening offers three profiles with reversible changes. It applies the chosen settings and restores them if they drift. The free check shows what needs attention; applying changes is a separate, approved step.
Ask what will change.
Before applying a change, review the affected devices, the setting, the expected impact and the reversal path. An unexplained improvement in a score is not enough context for a decision.
Hardening also has limits. Configuration cannot remove every vulnerability or stop every permitted action from being misused. It reduces particular opportunities. It is not a promise that an attack cannot execute.
A harder target still needs protection.
Protection watches activity and looks for threats. cybee’s endpoint protection combines behaviour, signatures and content inspection on the device. That is a different task from checking a configuration against a baseline.
macOS already includes security mechanisms. Apple describes Gatekeeper, notarisation and XProtect as parts of its malware defences. cybee works alongside these built-in mechanisms. Read Apple’s malware protection overview.
Hardening asks
“Is this setting appropriate for the work this device does?”
Protection asks
“Is this activity a threat that needs a response?”
cybee shows AI tools, mapped external connections and recorded tool actions alongside device security findings. This context helps you investigate what was observed. It does not restrict agent permissions or replace protection and hardening. Explore AI visibility.
Keep the change and its evidence together.
The third job is the record. Which control was observed? On which device? When? What changed? A dated record connects security work to those questions without claiming that one result describes everything the business does.
The paid Trust Passport seals a technical record for a chosen period. Its integrity can be checked against cybee’s sealed copy. It is not an independent audit or a certification. It covers the assessed Macs, and its coverage statement belongs beside the result.
What the device record covers.
Encryption, endpoint protection, application patch status, screen lock, and installed browser extensions and AI tools.
Google Workspace accounts and multi-factor authentication (MFA) have their own record. Backups, training completion, incident plans, policies, code, suppliers and people need separate evidence.
Read the coverage details
On a typical questionnaire the passport answers, with dates, the questions about your Macs: disk encryption on every listed Mac; endpoint protection that watches behaviour, and since when; the patch status of your applications; screen lock and password on wake; the browser extensions and AI tools installed. This device record does not cover accounts and MFA. Connected Google Workspace has its own account record, within the connected organisation. Backups, training completion and the incident plan also need separate evidence. Policies, code, suppliers and people need their own evidence.
Make the next action clear.
A practical routine is to look at the findings, review the proposed hardening, confirm the intended action, and then read the new assessment. Keep unresolved findings visible. Continue protection while configuration is being improved. Treat response to a threat as a separate decision from applying a hardening profile.
That is how security and evidence support each other. A report can explain what happened. It cannot substitute for the work that changes the device.
Explore the hardening workflow