X World 2026
25-26 AUGUST • NAARM | MELBOURNE
Victor Lyuboslavsky
Does Your Mac Fleet Need an EDR? A Field Guide for Mac Admins
Sooner or later, your security team or your CISO will ask if your Macs need an EDR. You get a vendor demo, a price quote, and a slide deck full of acronyms. What you might not get is a clear answer to whether you actually need one, what an EDR does that your MDM, Santa, and osquery do not, and how to tell a strong EDR from a noisy one. This session fills that gap. On macOS, an EDR is one or two system extensions watching process, file, and network events, with behavioral rules on top. We walk through what that gives you beyond an MDM compliance check or osquery scheduled query, where it overlaps with Santa, and how to read a feature list, whether commercial or open source. We then map the decision against real factors: organization size, regulatory environment (Essential 8 ML2 versus ML3), incident history, and what your existing tools already cover. Attendees will leave able to answer three questions. Do we need an EDR? If yes, what should we ask the vendor? If no, what should we tighten first inside the tools we already run?
About the presenter
Victor Lyuboslavsky is a software engineering leader, author, and speaker with over 25 years of experience building products and leading teams. He has co-founded startups, held technical leadership roles at AMD, and now architects secure, scalable systems for enterprise IT at Fleet Device Management, covering fleets of macOS, iOS, and other major platforms. Victor's work bridges hands-on technical execution and strategic leadership. His talks draw on lessons from startups, open source communities, and creating an open source macOS EDR, with a focus on Apple platform security, hardware-backed identity, and endpoint telemetry.
Interview
We asked Victor a few questions about where Apple's heading and what he's working on.
What are you most excited about in Apple's upcoming OS releases?
AllowedBinaries and DeniedBinaries, in the new com.apple.configuration.app.settings declaration. Real application control on the Mac.
Is there new hardware you're hoping Apple ships?
Less new silicon and more access to the silicon that is already in there. Every Mac has a Secure Enclave that can prove a key was generated in hardware on that specific machine. That is the strongest device identity primitive on the platform, but admins get limited access to it.
The rise of AI: excited, scared, intrigued, or something else?
Intrigued. AI makes it very cheap to produce things nobody understands, and understanding was always the actual security control.
What's the best thing you've built that nobody's heard of?
An open source macOS EDR, built from scratch over the last year. Not an official Fleet product, not my day job, and not ready for real end-user devices yet. I'm dogfooding it on my own machines, so it is real enough to install and poke at: github.com/getvictor/fleet-edr
What do you wish you'd known when you started building admin tools for Apple platforms?
How much easier MDM makes everything. On a Mac, an app that needs permissions is either a bunch of prompts your users will hate you for, or an MDM configuration profile that handles everything. MDM is the whole difference.
Finish this sentence: "You should come to my talk if…”
... someone has asked whether your Macs need an EDR, and you would like to answer with something better than a vendor's slide. Come if you want to see what that EDR agent is actually doing to your Macs underneath.




