Kingside logo

From Blind Spots to Full Coverage: How Kingside Secured Their Developer Fleet with Workbrew

How Kingside, an Australian Web3 venture studio, moved from manual, semi-automated vulnerability triage to zero-touch CVE remediation across its developer fleet with Workbrew.

of incoming vulnerabilities automatically triaged
100%
to build a complete monthly security report
15 min
packages installed or updated
3,000+
  • New CVEs auto-remediated every week with zero manual triage.
  • Weeks from first deploy to visibility, not months.
The vulnerabilities aspect was definitely a bit of a blind spot, basically a glorified grep across the CVE list, and then a manual ping to the engineer to say, hey, can you update this?
Sajeeb LohaniCISO, KingsideKingside

Before Workbrew

Kingside's approach to Homebrew management before Workbrew was almost entirely manual. The team used Osquery to discover installed packages (formulae) across devices, but there was no automatic way to turn that large amount of raw data into actionable vulnerability intelligence. The team had to spend significant human effort enriching this data to get anything meaningful out of it.

"The vulnerabilities aspect was definitely a bit of a blind spot," Sajeeb explains. "Vulnerability management became a semi-automated process — basically a glorified grep across the CVE list, and then a manual ping to the engineer to say, hey, can you update this?"

While this semi-automated process worked for a while, it's not something that can scale. It only works as well as the person running it, and it leaves significant blind spots. There was no systematic way to know what was installed, no clear view of what was vulnerable, and no detail of what patches were applied.

"Funny enough, I was looking through Reddit to identify some really good ways of managing Homebrew better and potentially using Homebrew as a patch management system. That's where Workbrew came in."

Sajeeb didn't go searching for an enterprise vendor or a complete solution. He was just looking for a better way to manage Homebrew. What he found was a platform that is purpose-built for exactly this problem: Homebrew governance at scale, complete with enterprise-level visibility layered on top.

Using Workbrew

Kingside didn't just deploy Workbrew and call it a day: they built automation around Workbrew. Within weeks, the team had connected Workbrew into their existing vulnerability workflow. Patches not only happen automatically now, but there's full visibility along the way. And as a bonus, it's no longer just something added to someone's tasks.

"We have an automation that uses the API and automatically kicks off a brew command for every single vulnerability coming in," Sajeeb says. "It's almost zero touch for us at this point. We just sit back, let the systems take care of themselves, and keep an eye on threat intel."

For Sajeeb, Workbrew fills a specific and important role in their security stack. Workbrew is distinct from and works alongside your existing Endpoint Detection & Response (EDR) and Mobile Device Management (MDM) tools. Beyond those tools, it's also not your ordinary vulnerability scanner or patch management system. Workbrew is a comprehensive solution covering the entire lifecycle of software on your devices.

"Workbrew is first an analytics tool, and then a management tool. The analytics provides the observability layer for us. Looking at the exact bits of data, matched up with vulnerability management data. On top of that is the management layer, which is an appropriate way of actually remediating those issues. It's an action-oriented system."

Kingside's experience proves that having a quick view of the current state of software in your fleet is essential. Combined with the ability to remediate with a single click, Workbrew's action-oriented system provides complete coverage.

Deploying Workbrew

One of the biggest concerns for any team is that adding yet another management layer creates inevitable friction. This can be especially concerning when layering on top of developer tooling because developers notice when something changes in their workflows, and will often push back when they experience friction. But at Kingside, that conversation never happened at all. That's part of the magic of Workbrew.

"Except for two or three devs, I don't think people even realized it. They just kind of went with their day-to-day."

That small number of developers who did notice a change had hit a minor permissions bug in the agent. This bug was quickly resolved by Workbrew's Support and Engineering teams. For everyone else, the brew CLI felt exactly the same as they were used to.

"Our devs are pretty switched on, so giving them the ability to install a lot of what they want is fine," Sajeeb explains. "We're still monitoring everything going in and out of the systems. Providing that flexibility meant they didn't have to sit down and wait for approvals, it made the process a lot more seamless."

Workbrew is a rare security layer that is invisible to your users, so there's nothing to compromise on. This aligns perfectly with Kingside's security philosophy, which centers on giving developers flexibility while maintaining complete monitoring coverage.

After Workbrew

Today, the Workbrew Console is a daily touchpoint for Kingside's security team. CJ, Senior Security Engineer, checks it first thing each morning, alongside other environment dashboards. CJ isn't checking because anything is usually wrong. Instead, the Workbrew Console gives him immediate confidence that nothing is wrong.

"At the moment the fleet's protected, so I know that," CJ says. "It's so intuitive, I've never had to read any documentation to figure out how to do stuff. It just works."

Workbrew sits alongside their existing tools in CrowdStrike and Jamf, as one of three cross-reference points Kingside uses to validate device activity and security. When check-in patterns look unusual, all three signals get compared before any action is taken. This gives the team high confidence in their findings, and Workbrew plays a critical role in this process.

"Part of my management style as a CISO is a monthly security report to the CEO and head of product," Sajeeb notes. "In 15 minutes, they know exactly what's going on: all the highlights, the lowlights, incidents, everything. Being able to show the number of vulnerabilities identified and fixed, and that Workbrew did that, shows the ROI of the tool to the people who pay for it."

For day-to-day CVE remediation, automation handles a couple of vulnerability events per week. This automation connected to Workbrew ensures patches are applied in a timely manner for all users.

"Your typical packages - like OpenSSL - will pop up," Sajeeb says. "We have an automation that kicks off once a day, creates the commands automatically for each of the different machines, and then it goes in and starts doing the patches as needed."

The result is an automated vulnerability management process that runs largely without manual intervention, but provides visibility and oversight. It also provides a security posture the team can report on with confidence.

What to know

When asked what they'd say to another security leader evaluating Workbrew, both Sajeeb and CJ answered without hesitation.

CJ: "There may be other ways to run scripts to get the information, but Workbrew is just so much easier, and the dashboard and console is so intuitive. It just works." Sajeeb: "My favorite part is that they actually appreciate feedback — and you can see your feedback inside the product. It's nice to know it's actually actioned."

About Kingside

Kingside is an Australian technology company that incubates and accelerates some of the world's fastest-growing Web3 brands, including Shuffle, Origami, and Dumm Capital. As you may expect, moving fast is core to their identity and so is staying secure. For Sajeeb Lohani, Kingside's CISO, those two priorities no longer have to be in conflict with the right tools in place.

Industry
Web3 Technology & Venture Studio
Location
Australia
Team
Security (CISO + Security Engineer)
Stack
Jamf, CrowdStrike, Automox, Workbrew

Ready to see Workbrew in action?

Get full visibility over the software on your fleet and keep every package patched automatically.

We use cookies to analyze traffic and improve your experience. You can accept all cookies or decline non-essential ones. Read our Privacy Policy for details.