Network-based scanning assumes devices sit on a network you control. For a workforce that connects from home, from clients’ offices and occasionally from an airport, that assumption fails quietly: the scanner reports on the machines it can reach, the numbers look reasonable, and the laptops that have not been seen for months are simply absent. The NCSC’s device security guidance starts from the same premise, that the device rather than the network is now the control point.
Agents become the only reliable method
An agent reports whenever the machine has an internet connection, which removes the dependency on a corporate network entirely. That makes coverage the metric that matters: the proportion of known devices reporting within the last seven days. Investigate the gap rather than the average, because a device that has not checked in for a month is either decommissioned, broken or being used by somebody who has found a way around your management. All three deserve a phone call, and the third is the one you most want to know about.
See also: What to Put a Sauna On: Pads, Decks, and Gravel for Small Spaces

Patching without a reboot you can enforce
Updates install and then wait, sometimes for weeks, because the user keeps deferring the restart. Measure pending reboots as a separate figure from missing patches, since a device that has downloaded everything and rebooted nothing is still vulnerable. Set a deferral limit that eventually forces the restart with warning, and pick a time of day based on how people actually work rather than assuming an overnight window that never arrives for a laptop that closes at six. Report the average age of pending reboots alongside the count, because one machine waiting ninety days matters more than thirty waiting a day.
“Third-party software is where remote estates fall behind. The operating system updates itself because the platform pushes it, and then the browser plugin, the PDF reader and the video conferencing client sit two years out of date. Those are the ones being exploited, so measure them separately or they will hide behind a healthy operating system figure.”
William Fieldhouse, Director, Aardwolf Security Ltd
Making non-compliance visible to the user
Conditional access turns patching into something the user notices. A device that fails a compliance check loses access to email and files until it updates, which converts a report nobody reads into a five minute task the user completes themselves. Introduce it with a grace period and clear messaging, since the alternative is a service desk overwhelmed on the first morning. The same mechanism handles devices that fall out of management entirely, because access depends on the device proving its state rather than on your ability to reach it.
What still needs checking directly
Agents report what they are configured to look for, so they can miss configuration weaknesses and locally installed software outside the inventory. Endpoint vulnerability scanning gives you the patch position, and a periodic build review checks the things an agent will not, including local administrator rights, disk encryption status and whether the standard image has drifted. Internal and remote security testing then answers the question that matters most, which is what an attacker who compromises one remote laptop can reach in your environment.
Frequently asked questions about remote device patching
These questions come up whenever a hybrid workforce is reviewed.
Do you still need network scanning?
For servers, printers, network hardware and anything that cannot run an agent, yes. For laptops, agents are the practical answer, with network scanning reserved for verifying that the agent data matches reality.
What coverage figure is acceptable?
Aim for ninety-five per cent of known devices reporting within seven days, and treat the remainder as an investigation list rather than an acceptable margin. The devices that never report are rarely the unimportant ones.



