The challenge
Intruder is an AI pentesting, vulnerability and exposure management platform, helping lean security teams find and fix weaknesses across their attack surface before someone else finds them first. As part of its own product, the company tracks a cyber hygiene score an A-through-F score covering patch status and endpoint health. Intruder’s business runs on trust in the score: customers hand Intruder visibility into their own exposure, and Intruder's whole value proposition rests on doing something useful with it. Internally, Intruder grades itself in a similar fashion.
For years, keeping a high cyber hygiene score was manageable. Co-founders Patrick Craston (CTO) and Chris Wallis (CEO), had built the company from a handful of people around a shared table, working on personal laptops they'd bought themselves, and everyone just made do. But as headcount pushed past 30, the manual process of patching every laptop started to break down. Joe Haigh, who at the time was responsible for tagging outdated software and following up individually with each person, earned himself the nickname "the Enforcer". Patrick describes the same challenge from the other side.
We spent a lot of time reminding people on Slack. We had a lot of visibility into what wasn't patched, but we just couldn't get on top of it. As soon as you've told everyone to patch it, a few of those people patch it, new patches come out, and it's just an endless rock and roll to some extent.
Patrick CrastonCTO at Intruder
The result showed up in the metric that mattered most: Intruder's own cyber hygiene grade started drifting from an A toward a failing score, at the exact moment the company needed to show it held itself to the same standard it sells.
The solution
Choosing something intuitive over deep, manual customization
Patrick and Joe evaluated several device management platforms before landing on Iru (then Kandji). Some competitors offered more granular configuration on paper, but that flexibility came with a setup burden that Intruder, without a dedicated IT team, didn't have the bandwidth to take on. Iru's opinionated defaults won out instead.
What was really nice about Iru is that it's opinionated. It says, these are our defaults, this is the best way of doing things. If you want to do it differently, you can dig into the options and change it. More often than not, going with the default sets you off on a really good path.
Patrick CrastonCTO at Intruder
From manual patching to a sustained A score
Once Iru was in place, automated patching and vulnerability response closed the gap almost immediately.
Because we were monitoring it using our own solution, we could see how suddenly everything got patched, how our cyber hygiene score improved, and the problem basically fixed itself.
Patrick CrastonCTO at Intruder
Also, enforced updates meant devices now restarted and installed patches on a countdown rather than waiting on a person to act, which employees noticed right away. The countdown gave people real notice, usually a day or two, and the ability to apply an update on their own schedule within that window. Employees mentioned that enforcement felt less like an ambush and more like a deadline. Since that rollout, Intruder's internal cyber hygiene score has stayed at an A.
Zero-touch enrollment as the team scaled
Enrollment started out manual: an internal documentation page, a link, an enrollment code, and a short message asking people to click through. That worked fine for a technical team, but when it came to non-technical new hires, it meant someone had to chase down the tasks. Connecting Iru directly to Intruder's Apple Business account removed that step entirely.
Whenever we buy a new laptop for an employee, they just open it up, turn it on, and it automatically provisions everything.
Patrick CrastonCTO at Intruder
Turning routine software rollout into something invisible
Intruder’s own vulnerability-scanning product, which depends on an internal detection agent running on laptops, required a manual installation process. Before Iru, employees would run terminal commands, pasting one line at a time, being especially difficult for non-technical hires. Automating that deployment through Iru removed the back-and-forth entirely.
It was really nice for Iru to be able to automate that whole process without having to even think about the commands needed to be sent across. It's provisioned automatically, and we can see the output and the success of it, or fix it remotely if there's a failure.
Joe HaighTechnical Solutions Specialist at Intruder
Compliance evidence that flows on its own
Intruder holds itself to SOC 2, and Iru feeds that compliance picture directly: disk encryption, password manager status, and other required controls sync into their compliance software automatically for every laptop, and flag immediately if something falls out of line.
With the right tools, you can do those jobs as part of your main job. If I didn't have those tools, there's no way I could also manage our compliance platform on the side. It makes it possible for me to perform all these different tasks.
Patrick CrastonCTO at Intruder
Results
Intruder's cyber hygiene score has held at an A since the rollout, through headcount growth that has more than doubled, without adding a dedicated IT role to maintain it. Patrick still gets asked whether it's time to hire an IT manager or bring in outside help.
Our head of finance has said to me, do we need to hire an IT manager, or get an external IT team or service to help us? I've always said, maybe when we're bigger. As we've grown, we still haven't hit that need yet.
Patrick CrastonCTO at Intruder
Andy Hornegold, Chief Security Technologist, feels that low overhead in his own place. With an intuitive platform, he is able to navigate the system quickly without the need to rely on Iru's support team.
I really had no problems finding the custom script section, deploying a script across our estate, and getting results. I've not had any situation where I've needed to engage with the support team. I'm sure they're fantastic, but the product at the moment kind of speaks for itself.
Andy HornegoldChief Security Technologist at Intruder
Looking ahead
The same self-service model that solved patching is already being pointed at newer challenges. When employees started building their own Claude Code skills to speed up internal work, Joe built a security approval pipeline on top of Iru's API: a skill gets submitted, Intruder's security team reviews it, and once it clears, it's packaged and pushed to Iru's self-service portal. From there, anyone can install it in one click and Iru's API keeps it current as new versions ship.
It gives us the control that we need, and it also gives users the simplicity that they value, being able to grab the things they need to do their job even more effectively.
Joe HaighTechnical Solutions Specialist at Intruder
Andy has a similar wishlist for the next category of risk: supply chain compromises in package managers like npm, Homebrew, and PyPI. Currently, he reactively checks for potential compromises with custom scripts, but would rather block outright before a bad package ever reaches a laptop.
About Intruder
Intruder is a cybersecurity company that unifies AI pentesting, attack surface management, cloud security, and continuous vulnerability scanning in one platform, helping lean security teams find and prioritize the weaknesses that matter most before they can be exploited. Founded in 2015 and headquartered in London, Intruder works with more than 3,000 customers worldwide.