Visby Medical Replaces Meraki with NinjaOne

Industry

Location

Products

Results

  • 50% lower cost than Meraki
  • 4 hrs saved weekly on patching
  • Zero-touch Android enrollment

Industry

Location

Products

Overview

Visby Medical is a medical device company based in San Jose, California, that develops PCR-based diagnostic devices used to test for a range of health conditions, with a growing footprint in the direct-to-consumer market. IT Manager Devin and a lean three-person team are responsible for securing and managing a mixed environment of Windows and Mac endpoints, Linux servers, and mobile devices, all while meeting the data-sensitivity standards that come with handling patient health information.

For years, that meant piecing together multiple IT solutions. The stack included Kaseya’s VSA for endpoint management, Qualys for vulnerability scanning and patch correlation, and Cisco Meraki Systems Manager for mobile device management. Today, Visby Medical runs its entire endpoint security and patching operation through NinjaOne, including vulnerability management, autonomous patch management, and native Android MDM.

Meraki is not an MDM solution — they only tacked it on as a convenience to their customers. Switching to NinjaOne was a no-brainer.”

Devin, IT Manager, Visby Medical

Challenge

An aging endpoint stack that couldn’t keep pace

Visby Medical’s IT function had outgrown its original tools. The company had been managed by an outside MSP running Kaseya’s VSA platform, but as Devin’s team took on more responsibility internally, the antiquated, hard-to-manage system became a constant source of friction.

“We were having some challenges with managing our endpoints,” Devin explained. “We needed to find a more modern-day solution that would allow us to keep up with the latest threats, keep up with monitoring, and easily deploy applications.”

Meraki wasn’t built to be an MDM

On the mobile side, the problem was worse. Visby relied on Cisco Meraki Systems Manager to manage Android and Apple devices, but Meraki is a network-first platform that added mobile device management almost as an afterthought.

“Meraki is not an MDM solution. They only tacked it on as a convenience to their customers,” Devin said. “They don’t use the native Android SDK. You have to deploy a separate app, and if that app isn’t running in the background, it won’t get policy updates or app updates.”

That gap created constant support headaches. Employees would report that a new app or policy never arrived, and more often than not, the fix was simply to reopen the Meraki SM app that had quietly stopped running in the background. Enrollment wasn’t much easier as Visby’s team ran into repeated device-enrollment failures tied to how its Google environment was configured. “It was a nightmare, honestly,” Devin said. “It was really challenging.”

Patching and vulnerability management that couldn’t scale with a lean team

On the patching side, Visby had spent three years on Qualys specifically because it could correlate a vulnerability to the patch that fixed it, a capability that mattered for a health company handling patient data. Between manually building patch jobs and troubleshooting failure, Devin was regularly losing hours every week to a process that should have been automatic.

Solution: Why Visby Medical chose NinjaOne

A single, mobile-first platform

When Devin’s team evaluated replacements for their aging MSP tooling, including Microsoft Intune and Atera, NinjaOne stood out for one reason above all. It worked the same way regardless of device type, with a dedicated mobile app rather than a browser-based workaround.

“NinjaOne had a mobile app; the others had management through a mobile browser,” Devin said. “We wanted something we could integrate with our single sign-on, rather than a private browser window. NinjaOne had that.” Intune, he added, “is more meant for Microsoft shops. We’re a Google shop, so that didn’t make sense.” And when Visby’s team reached out to Atera, “Nothing happened. We reached out to NinjaOne, and immediately we got in contact with a sales agent, and the rest is history.”

Replacing Meraki with native Android MDM

When Meraki began sunsetting its device management capabilities, Visby didn’t have to shop around. NinjaOne was already the company’s endpoint management platform, and rolling mobile devices into the same platform was, in Devin’s words, a no-brainer.

The difference came down to how NinjaOne manages Android, through the native Android Device Policy app rather than a bolted-on third-party client. “That’s probably the biggest differentiator,” Devin said. “Not having to have a native third-party app but using the Android Device Policy app makes things so much easier. If you’re already a NinjaOne customer, it’s just a smooth transition to add one more module.”

Onboarding took some ramp-up while Devin’s team, self-described Apple specialists still building out their Android expertise, learned Google’s Android Enterprise policies. NinjaOne connected Devin with a senior Android specialist who walked through every misconfiguration one by one. “She pinpointed and picked apart everything and really helped us figure out what we were doing wrong,” Devin said.

From there, Visby connected its Android Enterprise instance directly to NinjaOne, so new institutional devices auto-enroll the moment they connect to Wi-Fi. “They connect straight into NinjaOne, download the policies, people sign in, and they’re home free,” he said.

Vulnerability management and patch, correlated and automated

NinjaOne’s patching won Devin over on its own merits, so much so that he eventually retired the Qualys workload entirely, once NinjaOne’s vulnerability tool matched that same correlation capability without the extra platform or cost.

“Frankly, I’m kicking myself for not doing it much sooner,” Devin said. “NinjaOne patching is fantastic. It’s simple, and it’s granular, but not overly granular.” His team now layers NinjaOne’s Patch Intelligence AI into a weekly rhythm. Patches are evaluated and flagged by risk, Devin reviews the AI’s findings for a second opinion, and lower-risk patches go out within three to four days while others wait a full 30-day vetting window. Lab-adjacent devices get patched most frequently, given how central they are to Visby’s operations, while servers are assessed weekly and patched every weekend.

Results & Outcomes

Hours back every week

Automating patch review and vulnerability-to-patch correlation gave Devin’s team back three to four hours a week that used to go into manually building Qualys jobs and chasing down failures. “I honestly don’t have to think about it that much anymore,” he said. “I’ll log in, check what’s failed, check what’s pending, approve the manual ones, and move on.”

Fewer agents, fewer tools, lower cost

Moving vulnerability and patching fully into NinjaOne let Visby drop a dedicated Qualys agent from every device. “It dropped an agent from our devices, which increased performance, one less agent, one less platform to deal with,” Devin said, avoiding the cost of continuing to scale a Qualys deployment. On the mobile side, replacing Meraki cut MDM licensing costs roughly in half. The consolidation was deliberate. “We’re a small team,” Devin said. “We didn’t want to keep having different platforms for different things. Let’s just try to consolidate under one branch.”

Continuous, correlated vulnerability visibility

Beyond patch automation, NinjaOne gave Visby something it never had at this price point with Qualys: a single, always-on view of vulnerability risk tied directly to remediation. “Using AI intelligence, it’s able to determine a vulnerability, able to patch it, and then we get the reporting,” Devin said. For a company handling patient health data, that continuous correlation between vulnerability and patch has become the backbone of Visby’s security posture. “It allows us to know that our environment is as secure as it can be.”

Quieter support, fewer fire drills

Replacing Meraki’s third-party app with NinjaOne’s native Android MDM eliminated the single biggest source of mobile support tickets. “If someone puts in a ticket for something, we just push it and it works,” Devin said. “It’s instantaneous, because the Android device policy is native to the platform, not a third-party app. That’s it. Straightforward.”