We also provide laptops to our teams as it is a part of the requirements. One good step to take is to move out of the Windows environment (all our laptops are now running Linux). It makes things very secure. Also, if you are not giving admin rights to the users, they cannot install anything on it other than what is already given by the IT team. No viruses or trojans, so no security risks. The current GUI (graphical interface) makes it almost like Windows except that the commands are in a different place (top, not bottom).
Protocol Controls for Data Security
If moving to Windows is not an option, then you need to put in a series of "Protocol Controls" either directly through the Zero Admin option or by putting in third-party software. VPNs are one of the common ones. Of course, you need antivirus. Blocking user rights to install software is one option, but then they also can't install any printers.
I do not know the IT Admin department you have. If you have one, they can do the necessary things (if they are capable). Else, you can take the help of an external managed services team. Some of them also have the ability to remotely work on the laptops.
If you need any help with this, send me a Personal Message, and we can talk on the phone. (We have done this in our office and for some of the clients)
Regards.