UBank runs a distributed estate: laptops behind the counter in every branch, tablets carried by relationship officers, and handhelds in the hands of field agents. The estate grew with the bank. The means of controlling it did not. We deployed TechSwitch MDM across more than 1,000 of those devices, brought every one of them under enforced policy, and gave the IT team a single console to work from. No branch lost a working day to the rollout.
The challenge
A bank does not get to treat device security as an internal matter. Every device that leaves a branch carries customer data, and every one of them is in scope when an auditor asks what controls are in place and how they are evidenced. UBank could answer the first half of that question. The second half meant calling branches.
- Devices were configured by hand, one at a time, so no two builds matched.
- Security policy existed on paper. Nothing on the device enforced it, and nothing reported when a setting was changed.
- A device reported missing started a round of phone calls rather than a procedure.
- There was no authoritative record of which devices were in service, at which branch, and with whom.
Growth had outpaced control. The bank needed to secure every device without slowing down the branches that depend on them from the moment the doors open.
What we deployed
We rolled out the TechSwitch MDM platform as the single point of control for the fleet: every device enrolled, the bank's security requirements expressed as enforceable policy, and the remote controls a regulated institution needs when something goes wrong.
Enrolment in waves, run by IT
Devices were enrolled by the IT team before they reached the person using them, in scheduled waves organised branch by branch rather than in one cutover. Each wave was rehearsed on a pilot group first, so a configuration problem surfaced on a handful of devices instead of a thousand. Branch staff received a device that was already configured and already reporting to the console.
Policy the device enforces on its own
Encryption, passcode strength, lock timeout, application allow-lists, and network profiles are defined once in the console and applied across the estate. The device holds to them whether or not it is on the bank's network. When a device drifts out of policy, the console flags it and reapplies the setting instead of waiting for someone to notice.
Visibility that stands up to an audit
Every enrolled device reports its state continuously: operating system version, encryption status, policy compliance, and last check-in. That record exports on demand, which turned compliance reporting from an exercise in chasing branches into a query. When internal audit asks which devices are encrypted, the answer takes a minute and arrives with evidence attached.
Remote action when a device goes missing
A device reported lost or stolen is locked or wiped from the console. Each action is logged with a timestamp and the operator who ran it, which matters as much as the action itself: the bank can show exactly what was done and when. Across the first quarter of operation, every incident raised against the fleet was closed remotely. No engineer travelled to a branch to resolve a device issue.
Deploying the TechSwitch MDM solution has simplified device management, improved operational efficiency, and helped us maintain a secure mobile environment at scale.
The results
The rollout completed without a single branch losing a working day. Within the first quarter of operation:
| Outcome | Before | After |
|---|---|---|
| Device build | Manual, one at a time | Standardised at enrolment |
| Policy compliance | Stated on paper | Enforced and evidenced, 100% |
| Lost-device response | Phone calls and best effort | Locked or wiped from the console, logged |
| Support model | Engineer travels to the branch | 100% of issues resolved remotely |
| Fleet record | Fragmented and out of date | One live console |
Where it stands now
Every device the bank issues is enrolled before it reaches the person who will use it, and stays under policy for as long as it is in service. The IT team spends its time on the estate rather than on individual devices, and the evidence an auditor asks for is already there when the question is asked.
Talk to us about your device fleet and we will show you what the same level of control looks like across yours.