by 2025 If measured as a country, cybercrime would be the world’s 3rd largest economy (after the US and China) A ransomware attack hits a business every 11 seconds 60% of small businesses close within 6 months of a cyberattack Supply chain attacks have doubled since April 2025 Likelihood of detection and prosecution of cybercriminals is as low as 0.05% in the US | Cybercrime ref: https://cybersecurityventures.com/cybercrime-damage-costs-10-trillion-by-2025/ https://cyble.com/blog/supply-chain-attacks-double-in-2025/ https://www3.weforum.org/docs/WEF_Global_Risk_Report_2020.pdf 20.05.2026 WhizUs GmbH 4
to scale and improve attacks – both in quantity and quality More code is being published faster (AI-generated) and is harder to control Questions we previously couldn’t answer well: How do we handle vulnerabilities on our devices? How do we detect if a device has a vulnerability? How is patch and update management established? | Growing Technical Threats 20.05.2026 WhizUs GmbH 7
stricter cybersecurity obligations ISO 27001 is increasingly required in tenders and business relationships Proof of methodical security & data protection is becoming mandatory for working with large enterprises We are actively audited by customers – detailed reports on business continuity, data protection, and security processes are expected | Regulatory & Market Pressure 20.05.2026 WhizUs GmbH 13
now a hard requirement in many RFPs Customer in financial sector: a supplier was removed entirely because they couldn’t demonstrate adequate security measures; Customer in energy sector: before we could even start the project, we had to provide detailed documentation of our technical and organizational security measures No security = no customers. There is no alternative for our business. | Real-World Examples 20.05.2026 WhizUs GmbH 14
"good luck" (e.g. alerts, real-time) overview where we are (e.g. dashboards) vulnerability detection on devices patch and update management software inventory and cleanup of unused/outdated apps industry proven solution(s) work with: linux, windows, mac, ios, android automation (best with IaC) pricing/costs we can manage Device Management is not just a corporate requirement – it is a personal security hygiene tool. | What do we need? 20.05.2026 WhizUs GmbH 16
UEM; deeply integrated with Microsoft 365 and Entra ID; supports all our platforms (Windows, macOS, Linux, iOS, Android); Terraform/OpenTofu provider available; GDPR compliant; dominant in Austrian enterprise environments Jamf: Apple-focused MDM, industry leader for macOS/iOS fleets Hexnode: Multi-platform UEM aimed at SMBs, competitive pricing FleetDM: Open-source, osquery-based; popular in engineering-heavy teams We chose Intune – covers all our requirements BUT we’re free to switch to a better alternative | Solutions ref: https://www.gartner.com/reviews/market/unified-endpoint-management 20.05.2026 WhizUs GmbH 20
do MDM together (IaC) and limit the effort to only relevant parts with MDM one "could" do "almost everything" on the device we limit this (explained in the transparency section) only settings for improving security are configured information disclosure is limited as much as possible | Issues and Solutions 20.05.2026 WhizUs GmbH 30
Developer Merge Release PR Release published (trigger) tofu plan Upload plan artifact to release Create approval issue (with plan details) Notify "Release ready, waiting for approval" Review plan in issue | Workflows 20.05.2026 WhizUs GmbH 35
Wie hoch sind die finanziellen Schäden durch Cyberkriminalität? Supply Chain Attack on Axios Pulls Malicious Dependency from npm iPhone-Hackcode Intune Defender Microsoft Graph API 20.05.2026 WhizUs GmbH 44