Device hardening

How a device is hardened end to end

Hardening a device is not a matter of installing an application. It is a sequence of controls that begins in the hardware, is governed from the EMM and is maintained throughout the life of the device. This page brings the three pillars together: management, communications and encryption.

Equipped soldier beside an armoured vehicle
Layered model

Six layers, from the bottom up

Each layer depends on the one below it. A failure in a lower layer invalidates the upper ones, which is why the order matters.

  1. 01

    Hardware and verified boot

    Galaxy devices with Knox: hardware root of trust, verified boot, Knox Warranty Bit and tamper detection. This is the foundation on which the other layers rest.

  2. 02

    Mandatory enrolment

    Knox Mobile Enrollment binds the device to the organisation's EMM from first boot and after any reset. NFC provisioning for mass onboarding.

  3. 03

    Policy and restrictions (EMM)

    Password and biometrics, mandatory encryption, camera, USB, Bluetooth, tethering, app store, screenshots, debugging. Hundreds of Knox Platform for Enterprise controls applied per profile.

  4. 04

    Applications and container

    Approved applications only, distributed from an internal repository. Separate work container with Knox Workspace and, where required, additional encryption with DualDAR.

  5. 05

    Communications

    Always-on VPN with traffic blocked outside the tunnel, per-app VPN for segmentation, device certificates from the PKI, mutual TLS and, on classified networks, a dual tunnel.

  6. 06

    Operation and response

    Continuous compliance, alerts, remote support, selective or full wipe, certificate revocation and secure retirement with evidence. Everything logged for audit.

06Operation 05VPN 04Apps and container 03EMM policies 02Enrolment 01Hardware
fig.Hardening layers on a managed device
Procedure

How a fleet is hardened in practice

  1. Classify

    What information the device will handle, on which network and with what level of exposure. The profile follows from this.

  2. Design the profile

    Policies, applications, certificates, VPN and encryption per group. Documented as a baseline and checked against CCN-STIC and STIG.

  3. Provision

    KME, NFC or QR. The device leaves the store already enrolled, encrypted and with the profile applied.

  4. Operate

    Continuous compliance, updates approved with E-FOTA, remote support and periodic review of the baseline.

  5. Retire

    Verified secure wipe, removal from Knox and from the inventory, retirement certificate.

Control matrix

Which layer covers each threat

ThreatMain controlLayerPillar
Loss or theft of the deviceEncryption at rest, DualDAR, remote lock and wipe01, 04, 06EMM + Encryption
Data extraction via USB or debuggingRestriction of USB, ADB and file transfer03EMM
Malicious or unauthorised applicationAllow list, internal repository, container04EMM
Interception on an untrusted networkAlways-on VPN, mutual TLS, device certificates05VPN
Lateral access to internal resourcesPer-app VPN and segmentation05VPN
Tampered or outdated firmwareVerified boot, E-FOTA with approved versions01, 06EMM
Device unenrolled or resetKME: forced re-enrolment after reset02EMM
Retirement without guaranteesVerified secure wipe and retirement certificate06EMM + Encryption

The hardening is defined in writing as a baseline and versioned. Every change to the profile goes through the same approval process as a change to a classified system.

Next step

Free MDM/EMM continuity assessment (45 minutes)

A technical session with a specialist to review your situation and return an actionable recommendation. No obligation.

  • Current architecture and number of devices
  • Data criticality and network or cloud constraints
  • Integration with Samsung Knox and mixed fleets
  • Transition options and deployment model (on-prem, hybrid or cloud)