← Back to list

Guardrails, Not Roadblocks: User‑Centric Apple Compliance at SEEK

Why I went to JNUC in Denver

Martin Piron in SEEK blog · 2025-11-25 21:40 · 0 claps · 4.0 min read
#apple #security-compliance #jamf #conference
Open on Medium ↗
Wiki topics: SAF · Safety & Alignment 🌐 · Web Development

Guardrails, Not Roadblocks: User‑Centric Apple Compliance at SEEK

Why I went to JNUC in Denver.

As a Senior Systems Engineer in SEEK’s Enterprise Technology Services team, my focus is simple: keep our Apple fleet secure, compliant, and enjoyable to use without compromising the user experience.

At the Jamf Nation User Conference (JNUC) in Denver last month, I shared how we’re modernising device governance by utilising the new compliance benchmarks capabilities in jamf pro. I also used the conference as an opportunity to connect with peers and learn how the wider Apple admin community is evolving. This will help shaping our roadmap for the upcoming months and help us adopt the latest and greatest technology available.

What is JNUC?

The Jamf Nation User Conference (JNUC) is Jamf’s annual gathering of Apple IT professionals from around the world, convened over three days to learn, collaborate, and share real-world practices for managing and securing Apple at work. It is purpose-built for practitioners and is explicitly not a sales expo or trade show, emphasising community-driven sessions and practical outcomes. Attendees include Apple admins, IT teams, and InfoSec leaders who come together to discover new and better ways to manage and secure Apple devices.

Presenting on Jamf’s new compliance benchmarks

I had the privilege of presenting on Jamf’s new compliance benchmarks feature. In short, compliance benchmarks provide a structured way to define, measure, and report on security baselines across macOS and iOS/iPadOS devices, grounded in industry standards and internal policy. They turn what used to be a mix of spreadsheets, scripts, and tribal knowledge into a cohesive, auditable experience inside Jamf.

SEEK’s environment is dynamic: product teams iterate quickly, our device fleet evolves, and the Apple landscape moves fast. Compliance benchmarks help us keep pace without trading away security. I shared how we’re approaching baseline design, how we map controls to technical enforcement and reporting, and how we migrated from the Jamf Compliance Editor to compliance benchmarks.

SEEK’s approach to compliance

While we hold a lot of Personally Identifiable Information from our customers, we are not operating in a governed environment. Which means we get to decide which security metrics are relevant to us and create our own compliance. We used the CIS Level 1 as a template and tweaked it, aiming to strike the right balance between security and user experience.

For example, we’re happy to keep airdrop available and we don’t need the Bluetooth icon to be visible in the menu bar permanently.

We’ve had a security benchmark set for a while, this presentation is very much focusing on the migration from one tool to the newer more modern solution.

Here’s how we’re realising value:

  • Reduced time to evidence: We can generate control-level evidence in minutes, not weeks, which shortens audit cycles and reduces context switching for engineers.
  • Fewer regressions: Alerts give us early signals when a configuration slips due to OS changes, app updates, or local overrides. We fix fast and learn faster.
  • Better conversations with Security: Benchmarks create a common language between endpoint management and security risk owners, so we discuss outcomes, not just knobs and scripts.
  • User experience preserved: We can design tiered baselines with documented exceptions while maintaining guardrails elsewhere.
  • Clearer upgrade paths: When a new macOS release lands, we can see which controls need updates and test them in ring deployments with confidence.

[embed]

What’s next for SEEK?

We’re converting JNUC momentum into a roadmap that tightens alignment to industry standards, operationalises continuous compliance, and elevates user experience without adding friction.

  • Standards-aligned baselines: Strengthen our alignment with the CIS standards, so every control is traceable to a recognised requirement and testable end to end.
  • Align benchmarks with our audit calendar so evidence generation is continuous, not event driven.
  • UX-first guardrails: Controls will be designed to be quiet by default, self-healing where possible, with clear user prompts when needed, and Self Service pathways for fast, safe remediation.
  • Share back patterns and tooling with the community, because we benefit from others doing the same.

Why this matters?

SEEK has a long history of industry collaboration and conferences like JNUC create concentrated learning loops and real-world connections that accelerate how we secure and manage Apple at work.

  • Faster learning, fewer blind spots: In three days you can validate assumptions, see approaches in action, and pressure-test ideas with practitioners who have solved similar problems, compressing months of trial and error into a single cycle.
  • Practitioner first, not sales first: JNUC is intentionally built around practitioners, with content designed for Apple admins and security teams rather than a trade show pitch, so the takeaways are actionable on Monday morning.
  • Shape the roadmap together: Calls for sessions and direct access to Jamf experts give us a channel to influence features and focus areas, ensuring vendor investments align with real-world operational needs.
  • Stronger standards alignment: Comparing notes on how others map CIS/NIST/ISO controls to Apple platforms helps us refine our own baselines, reduce interpretation drift, and converge on language auditors understand.
  • Community as a force multiplier: The network we build (admins, security engineers, product teams) becomes a year-round support system for incident learnings, upgrade planning, and novel workflows that we can adopt and contribute back to.
  • Talent development and brand: Presenting and participating grows our team’s craft and elevates SEEK’s profile in the Apple community, which helps with hiring, partnerships, and peer validation.
  • Cross-industry signal: With education, healthcare, and enterprise voices in the mix, we spot emerging risks and best practices earlier and carry them back into our own standards and compliance rhythms.

A huge thank you to the Jamf community, the Denver hosts, and everyone who joined the session and shared candid feedback.

The reason I love JNUC is simple: we leave with fewer unknowns, stronger networks, and sharper tools. For SEEK, that translates directly into a safer fleet and a smoother experience for our people. For the industry, it accelerates a healthy trend towards measurable, user-centric security on Apple platforms.


메타데이터
post_id
e514ea7b3653
slug
guardrails-not-roadblocks-user-centric-apple-compliance-at-seek-e514ea7b3653
url
https://medium.com/seek-blog/guardrails-not-roadblocks-user-centric-apple-compliance-at-seek-e514ea7b3653
canonical_url
https://medium.com/seek-blog/guardrails-not-roadblocks-user-centric-apple-compliance-at-seek-e514ea7b3653
author_url
https://medium.com/@mpiron_60005
status
ok
fetched_at
2026-07-15 11:02:28