Emnify achieves unified, risk-based vulnerability management with Mondoo
How an IoT communications provider gets deep visibility into their vulnerabilities from a single platform.
Published December 2025 · Updated August 2026
- Organization
- emnify
- Industry
- IoT Cellular Communications
- Locations
- Germany, US, Philippines, Brazil
- Environment
- AWS — hundreds of EC2 instances across dozens of accounts
- Architecture & compliance
- Infrastructure as Code, Kubernetes, SOC 2
- Mondoo's role
- Unified, risk-based vulnerability management from a single platform
Who is emnify?
Emnify is a leading cellular communications provider in the IoT stack, connecting millions of IoT devices globally — like sensors, trackers, and smart appliances. The emnify platform offers features like real-time monitoring, provisioning, and management tools through a single API, all built on a cloud-native architecture called the 'SuperNetwork'.
With its infrastructure built on AWS, emnify has a large footprint on AWS with several hundreds of EC2 instances and dozens of AWS accounts.
What did emnify need from a vulnerability management solution?
Nader Erian, Staff Security Engineer at emnify, is part of a team led by Benoit Flippen, CISO at emnify, who oversees security operations. The team is responsible for the security of the emnify platform and ensuring that it meets the highest security and compliance standards.
Emnify needed a vulnerability management solution that would allow them to understand the risk level of each vulnerability detected across the different infrastructure layers, and to automate information gathering for AWS infrastructure and associated vulnerabilities — improving the overall vulnerability management process and assisting during audits such as SOC 2.
Why did emnify choose Mondoo?
The emnify team started looking into possible solutions. Several options were evaluated based on requirements and cost considerations. After evaluating different solutions, emnify selected Mondoo.
How does Mondoo deliver risk-based vulnerability management at emnify?
The depth of data in Mondoo is very helpful to emnify. Mondoo shows any potential attack vectors, related advisories, and how the issue needs to be patched. It also shows the risk of the vulnerability based on factors such as exploitability, network exposure, ease of exploitation, and any compensating controls. This intelligence is crucial for emnify to assess overall criticality.
Another important aspect is that Mondoo shows exactly which packages are affected and which package upgrade would solve the problem. This reduces the amount of research needed to remediate the issue and results in a faster MTTR (Mean Time To Resolution).
Mondoo workspaces have also been useful to emnify. The ability for R&D engineers to log into the platform with assigned roles allows them to view their assets, identify vulnerable packages that require updates, and access proposed patches for different operating system versions, significantly improving remediation efforts.
Mondoo's extensive integrations — especially the AWS S3 Exporter — have been essential in automating ticket creation for emnify's R&D teams, accelerating the speed at which emnify can fix vulnerabilities.
What results did emnify achieve?
With Mondoo Platform, emnify achieved prioritization insights, accelerated decision making, and faster remediation. The intelligence provided by Mondoo on discovered vulnerabilities — such as whether an exploit exists in the wild or if a vulnerability is known to be actively exploited — has been crucial in assessing overall criticality. Mondoo has been instrumental in helping emnify identify vulnerabilities across assets and plays a key role in their vulnerability ticket generation process, greatly accelerating the resolution of vulnerabilities and ensuring the most critical ones are fixed first.
With Mondoo's unified view into the vulnerabilities across emnify's entire infrastructure, it's now far easier for emnify to quickly understand the risk level of each issue and focus on fixing the most critical ones first. These insights also provided valuable support during audits such as for SOC 2 compliance.
“Beyond the product itself, the customer support we receive from Mondoo has been outstanding. The team is highly responsive, dedicated, and cooperative, always willing to listen to our feedback and continuously improve the platform. Their willingness to implement the features we have requested has been very much appreciated and is a great plus to the product, reinforcing our trust in Mondoo as a partner in our security strategy.”
Nader Erian, Staff Security Engineer at emnify
“With Mondoo we can see vulnerability data and perform queries from a single platform. This allows us to make better and faster decisions. We also get visibility into the criticality of any missed patches so we know which ones need to be fixed first.”
- remediation, with the most critical vulnerabilities fixed first
- Fasterremediation, with the most critical vulnerabilities fixed first
- for vulnerability data and queries — better, faster decisions
- 1 platformfor vulnerability data and queries — better, faster decisions
- audits supported by automated information gathering across AWS
- SOC 2audits supported by automated information gathering across AWS
Frequently asked questions
Emnify uses Mondoo for unified, risk-based vulnerability management across its AWS infrastructure — several hundreds of EC2 instances and dozens of AWS accounts. Vulnerability data and queries live on a single platform, which allows the team to make better and faster decisions.
Mondoo shows the risk of each vulnerability based on factors such as exploitability, network exposure, ease of exploitation, and any compensating controls — including whether an exploit exists in the wild or a vulnerability is known to be actively exploited. This intelligence is crucial for emnify to assess overall criticality and fix the most critical issues first.
Mondoo shows exactly which packages are affected and which package upgrade would solve the problem, reducing research and delivering a faster MTTR. Workspaces let R&D engineers log in with assigned roles to view their assets and proposed patches, and the AWS S3 Exporter automates ticket creation for R&D teams.
Emnify needed to automate information gathering for AWS infrastructure and associated vulnerabilities to assist during audits such as SOC 2. Mondoo's unified view into vulnerabilities across the entire infrastructure provided valuable support during SOC 2 compliance audits.
Every vulnerability, one platform.The most critical fixed first.
Emnify runs unified, risk-based vulnerability management across hundreds of EC2 instances and dozens of AWS accounts on one platform — with the intelligence to fix the most critical issues first and insights that support SOC 2 audits.

