Your Clients’ Macs Are Only Half-Compliant Out of the Box. Here’s the Other Half.
A new MacBook feels finished the moment it powers on. It’s encrypted-capable, it has a firewall, it has Gatekeeper, and it carries the reputation Apple has spent two decades earning: Macs are secure. So when you tell a client their fleet needs hardening, you get the same reaction every time: “Our Macs are already secure. Why are we paying for this?”
Here’s the uncomfortable part. They’re half right. Apple even agrees the risk is real: during the 2021 Epic trial, Apple’s own software chief Craig Federighi testified that the Mac had “a level of malware that we don’t find acceptable” — Apple had removed roughly 130 malware families targeting Macs the prior year, versus a handful on iOS. A Mac is genuinely secure for a consumer. It is not the same thing as compliant for a business — and the gap between those two is bigger than most people think.
That gap is exactly what we dug into with Brent Porter of Master Switch IT, a Minneapolis MSP that’s been managing Apple fleets for the better part of a decade, in our recent webinar Compliant by Default: How Smart MSPs Are Automating Apple Security. This is the short version of what we covered, and why the gap is one of the best service opportunities on your menu right now.
Apple builds for the person. MSPs have to secure it for business.
Every default on a new Mac is tuned for one user’s convenience, not a company’s risk posture. Out of the box, a device isn’t enrolled in MDM. The passcode minimum is short and weak, so people reach for “123456.” iCloud Drive, AirDrop, and personal Apple Accounts are all on, quietly moving company data through channels nobody’s watching. None of that is a flaw: it’s a deliberate design choice for a consumer product. It’s just not what a business needs.
Now put a framework on top of it. Run even the most basic default benchmark (CIS Level 1) against a brand-new Mac and about half the controls fail on day one. Reach for something stricter like STIG or CMMC and the failure count climbs from there.
Apple’s defaults get a device roughly halfway to business-ready. The other half is on you.
“Compliant by default” means it stops being a manual project
Closing that gap by hand is where most teams quietly give up. A framework isn’t a switch, it’s a stack of macOS configurations. CIS Level 1 alone is 97 rules on macOS 26 and 87 on macOS 14, because Apple changes controls with every release. CMMC Level 1 runs 82 rules; Level 2 runs 208. Each one might be enforced through a profile, a script, or a manual step a human has to physically perform, and every rule has to be tested so it doesn’t wreck the user experience, reported on continuously, and rebuilt when the benchmark changes next year.
Doing that across a dozen clients, by hand, and now we’re talking a full-time job with no finish line. Both Brent and our own team have tried it the manual way. It takes weeks to months to stand up a single benchmark for a single client.
Compliant by default flips the order of operations. In Addigy, you start with monitor-only mode: apply a benchmark that reads the status of every device and changes nothing. In minutes you have a real scorecard: of these 40 Macs, 11 are compliant.
Getting that kind of baseline is the single most persuasive thing you can put in front of a stakeholder before you’ve sold them anything. Then you turn on remediation, and the fleet flips toward 100% — typically within about 30 minutes, not months.
The stuff you only learn by breaking it in production
The reason automation matters isn’t speed. It’s that the raw benchmarks have landmines, and Addigy has already stepped on them so you don’t have to.
The clearest example: a CIS rule that disables logging into other users’ locked sessions. Pull it straight from the public repo and apply it, and it silently breaks Touch ID. Nobody tells you that — you find out when the help desk lights up. Addigy ships a curated remediation that enforces the control without killing Touch ID, and bakes that fix into the benchmark automatically.
It goes further. Every rule in Addigy carries its actual test script (which you can run on-device to see exactly what a device returns), a plain-language description of what it does and why, and a downloadable PDF that maps the rule to NIST 800-53, CIS Controls v8, and CCE. That PDF is audit evidence and a client leave-behind in one file. And because rules like Gatekeeper live in nearly every framework, Addigy tracks them across a 300+ rule database and keeps your cloned benchmarks synced as NIST and CIS publish revisions — tested and announced before they reach you.
The gap is your next revenue stream
Here’s the reframe that matters for your business: the work Apple leaves undone is a repeatable, billable service. Base security in every plan; deeper compliance in a paid tier. As Brent put it, the premium tier is real work — you shouldn’t be doing it for free.
The trick is having the conversation before the fire. The worst version is the client who calls the week before a SOC 2 or ISO audit asking you to make everything compliant “by next week” — and a SOC 2 Type II covers a period of time, not a point in time, so a last-minute scramble can’t retroactively prove months of good hygiene. The best version is proactive: monitor-only baseline, a before-and-after report, a clear tier. Master Switch has watched this play out — they’ve actually seen ticket volume drop as they added security and automation, passed an audit clean, and turned that result into an expanded engagement with the client.
Compliance done right also makes clients sticky. When someone can open self-service and see every check green, that’s reassurance they can feel — and reassured clients don’t leave.
What’s next: AI is the conversation starting now
The newest front is AI. Nearly every MSP we talk to says some version of “I have no idea which AI tools my users are running, and no way to gate or monitor it.”
So we shipped an AI Compliance Basics benchmark (in public beta) that lets you allow and block specific tools with point-and-click control — permit Claude and Gemini, say, while blocking others you haven’t vetted. It’s a natural next tier to offer a client who’s already asking the question, and it pairs neatly with removing local admin rights, which curbs the AI-tool sprawl at the source.
See it, then let’s talk
The webinar goes deeper than any recap can: a live benchmark deployment, the full table of rules that trip up users, and how to wire compliance into Microsoft Intune for conditional access and a real zero-trust posture.
Watch Compliant by Default on demand, then get a demo with our team to help you run a monitor-only baseline on a client fleet. You’ll have a compliance scorecard to show a stakeholder before the end of the day — and the beginning of a service you can sell to every client after.
