How SEEN found a light and privacy-friendly alternative to MDM

By Anthony Harrison
April 29, 2024

Anthony Harrison is Operations Director and Co-founder at SEEN, an innovative Norway-based video production company. Recently, SEEN went searching for a device security solution to gather evidence for their ISO 27001 certification, in line with its company values. Discover Anthony's journey went, and how he found the perfect solution in XFA to keep devices secure without limiting their users' freedom.

For those who are not yet familiar with your company, what is SEEN all about, in short?
Anthony (SEEN): SEEN is an international company based in Oslo, Norway, specializing in personalized videos at any scale. We provide data-driven video content, helping companies to engage with their customers. We were founded 7 years ago and now count 40 people.

How are you organized in terms of cybersecurity strategy?
Anthony: Together with the CTO and the rest of management, we shape our cybersecurity strategy. I’m currently pursuing our ISO 27001 certification, where one of the initiatives was to improve how we verify device compliance, together with rolling out a password manager.

How are you organized in terms of team and devices?
Anthony: The majority of our devices are company-owned, although some people use their own devices for various reasons. Before finding XFA on the Vanta platform, which we use to guide us through the ISO certification, we didn't use a specific device security solution or MDM. We relied on trust that people would keep their devices safe, which works in a small company. With the certification and just the scale that we are now, we had to start verifying that all devices were compliant.

You mentioned searching through Vanta for a solution to cover device security, what were your main goals and requirements?
Anthony: In specific, our main goal for device security was to make sure all devices were verified to be compliant in Vanta, with a light solution that truly covers all devices, and one that doesn’t allow a single user to run commands on all systems, which would invade on the privacy of our employees and contractors.

… like a single point of failure?
Anthony: Yes indeed, we needed Device Compliance, not Device Management. We don’t have dedicated IT support at SEEN, so we needed a solution that is simple, while making sure that all the needed security measures are in place.

How do you measure the success of your device security solution?
Anthony: We will monitor whether essential device security measures are complied with, such as having a password manager installed, antivirus turned on, screen lock enabled, and hard disk encryption on all devices. As we have XFA configured on our main applications, we are sure we get this information and enforce the right policies on all devices used within SEEN.

What device security solutions did you consider, and why were they less optimal for you?
Anthony: We looked at Google’s built-in endpoint solution, but it lacked support for macOS. Jumpcloud was considered but raised concerns as the management approach wouldn’t fit our company culture, and it would introduce that potential centralized point of failure.
We also explored Kolide, which we really liked and works similar to XFA, but it still required an MDM setup and only offered integrations via Okta, which isn't compatible since we use Google Workplace. We went for XFA because it ticked all the boxes of being a lightweight, privacy-respecting solution with broad compatibility.

What are the top three best things about XFA from your perspective?
Anthony: Firstly, XFA's privacy-first approach resonates with us. Secondly, your location in Europe makes communication and compliance easier. Lastly, but not least, you guys really give a sh*t (haha), we felt really supported and understood as to what’s needed to support a small company like ours.

Finally, what improvements would you like to see from XFA in the future?
Anthony: We look forward to seeing more device security checks and the option to search through devices using filters on your dashboard, set up some automated reports etc. That would really be nice.