Case Studies

Securing the Supply Chain: Endpoint Protection for a Logistics Company with 200 Mobile Workers

Drivers Logging Deliveries on Unsecured Phones

A mid-sized logistics provider based in Tuas managed a fleet of 200 delivery personnel who relied on mobile devices to log consignments, update tracking statuses, and communicate with dispatch. These workers used a mix of company-issued smartphones and personal devices to access internal systems, including a custom-built delivery management platform hosted in a hybrid cloud environment. No mobile device management (MDM) policy existed, and employees routinely connected from public Wi-Fi hotspots at cargo terminals and roadside stops. In mid-2023, an internal audit flagged multiple unauthorised access attempts originating from devices with outdated operating systems and unverified app installations. One device had been reported lost two weeks prior but remained active on the network, nearly allowing external access to shipment manifests and customer contact data. The risk of a full-scale breach under Singapore’s Personal Data Protection Act (PDPA) was immediate, and the company faced potential penalties, reputational damage, and operational disruption if the issue was not resolved within weeks.

Zero Visibility Into Mobile Device Posture

When TYPENT was engaged, we found no centralised control over mobile endpoints. The IT team could not remotely wipe lost devices, enforce encryption, or verify whether software patches were applied. Device ownership was split: approximately 60% of field staff used personal phones under a bring-your-own-device (BYOD) arrangement, while the rest used company smartphones with inconsistent provisioning. None of the devices had mandatory passcodes, and app installations were unmonitored — several had file-sharing tools not approved by IT. The delivery platform required only single-factor authentication, making compromised devices an easy entry point. Network logs showed repeated failed login attempts from geolocations outside Singapore, suggesting targeted probing. The company had no endpoint detection and response (EDR) layer on mobile devices, and no integration between their identity provider and mobile infrastructure. The root cause was not technological deficiency but the absence of a mobile security strategy aligned with operational reality.

Deploying a Tiered MDM Framework with Conditional Access

We implemented a phased mobile security overhaul using Microsoft Intune as the core MDM platform, integrated with Azure Active Directory for identity validation. All company-issued devices were enrolled automatically via zero-touch provisioning through Samsung Knox and Apple Business Manager, depending on device type. For BYOD users, we introduced a voluntary enrolment model with containerisation using Microsoft’s Company Portal app, which isolated corporate data from personal content. Conditional access policies were configured in Azure AD to block access from devices without up-to-date OS versions, active passcodes, or verified encryption. Any device failing compliance checks was automatically quarantined from accessing email, the delivery platform, or internal file shares. We deployed Veeam for mobile-aware backup of critical app data and configured automated alerts for lost or stolen devices. Simultaneously, we upgraded authentication to enforce multi-factor authentication (MFA) using Microsoft Authenticator, eliminating reliance on static passwords. Security awareness training was rolled out via in-app micro-modules tailored to driver workflows, focusing on Wi-Fi risks and phishing.

Full Device Compliance Achieved in 45 Days

Within six weeks, 100% of company-issued devices and 89% of BYOD endpoints were enrolled in Intune and compliant with baseline security policies. The number of unauthorised access attempts dropped by 97%, with blocked logins now triggering real-time alerts to the SOC team. After the lost device incident, remote wipe capability was tested and executed successfully within two minutes. The client reported zero data leakage events in the nine months post-deployment, compared to five incidents in the prior year. IT gained full visibility into device posture, including OS version, patch status, and app inventory, through a central dashboard. Downtime related to device troubleshooting decreased by 60% due to automated configuration and over-the-air updates. Long-term, the company integrated mobile compliance into its vendor onboarding checklist and now requires MDM enrolment for all field staff before system access is granted.

Security Cannot Be an Afterthought When Devices Are the Workforce

For logistics firms where mobile devices are the primary interface to operations, treating mobile endpoints as secondary to network security creates critical blind spots. This engagement showed that policy enforcement must match the physical mobility of the workforce — static firewalls and server-side controls alone cannot protect data that lives on phones moving through unsecured environments. The lesson for other Singapore SMEs is clear: if your employees access systems from devices outside the office, those devices must be treated as secured assets, not personal accessories.

When your delivery team is your IT perimeter, security starts at the device — learn how we design mobile-first protection for distributed workforces.

Uncover your hidden systems risk in 5 minutes.

Stop reading about risk and start measuring yours. Our free interactive assessment generates a custom IT vulnerability score — specific to your setup, your sector, and your staff count.