Technology Category
- Cybersecurity & Privacy - Application Security
- Cybersecurity & Privacy - Network Security
Applicable Industries
- Equipment & Machinery
- National Security & Defense
Applicable Functions
- Logistics & Transportation
- Product Research & Development
Use Cases
- Supply Chain Visibility
- Tamper Detection
Services
- Cybersecurity Services
- Training
About The Customer
The customer is a global financial services firm that advises clients on a variety of matters, including regulatory issues, compliance, risk management, liquidity, restructuring, acquisitions, and more. The firm places a high priority on software application security, understanding that a data breach could expose customer data, result in potential financial losses for the company and its clients, and cause significant damage to the company’s reputation. The firm's development team had been using Contrast for over two years and had nearly eliminated vulnerabilities introduced in later stages of the software development lifecycle (SDLC).
The Challenge
The financial services firm in question was facing significant challenges in achieving comprehensive application security test coverage for its entire software portfolio. The existing application security tools were proving to be inaccurate and ineffective, leading to developer disengagement, product delays, and negative business impacts. The IT Security team was primarily focused on network security, relying on perimeter security solutions to protect their applications and data. The application development team had minimal involvement in application security, and the training they received did not keep pace with advances in application development and hacking. The security team lacked the visibility needed to work efficiently and effectively, with their scanner tool reporting many false positives and lacking the necessary information for developers to find and fix errors. The existing tools and processes were preventing a complete security analysis of their applications, delaying the delivery of new business-critical software functionality.
The Solution
The firm discovered Contrast Assess, a product that offered a unique approach to finding and presenting vulnerability data in a way that was understandable by both developers and the security team. Contrast Assess works from within the application, without requiring any configuration changes. Its quick and easy installation, detailed dashboard, and real-time, continuous approach solved many of the application security challenges the firm was facing. The firm decided to onboard the SaaS version of Contrast Assess to accelerate deployment and simplify ongoing operations. Using Contrast’s continuous security testing, the application development team improved the security of their applications and could provide predictable delivery without adding headcount or expertise to the team. Real-time results allowed developers to fix problems as they came up throughout the development process. The insight Contrast Assess provided into custom and third-party code helped the development team identify which libraries had vulnerabilities, and whether their firm’s applications were using vulnerable code within those libraries.
Operational Impact
Quantitative Benefit
Case Study missing?
Start adding your own!
Register with your work email and create a new case study profile for your business.
Related Case Studies.
Case Study
Smart Water Filtration Systems
Before working with Ayla Networks, Ozner was already using cloud connectivity to identify and solve water-filtration system malfunctions as well as to monitor filter cartridges for replacements.But, in June 2015, Ozner executives talked with Ayla about how the company might further improve its water systems with IoT technology. They liked what they heard from Ayla, but the executives needed to be sure that Ayla’s Agile IoT Platform provided the security and reliability Ozner required.
Case Study
IoT enabled Fleet Management with MindSphere
In view of growing competition, Gämmerler had a strong need to remain competitive via process optimization, reliability and gentle handling of printed products, even at highest press speeds. In addition, a digitalization initiative also included developing a key differentiation via data-driven services offers.
Case Study
Predictive Maintenance for Industrial Chillers
For global leaders in the industrial chiller manufacturing, reliability of the entire production process is of the utmost importance. Chillers are refrigeration systems that produce ice water to provide cooling for a process or industrial application. One of those leaders sought a way to respond to asset performance issues, even before they occur. The intelligence to guarantee maximum reliability of cooling devices is embedded (pre-alarming). A pre-alarming phase means that the cooling device still works, but symptoms may appear, telling manufacturers that a failure is likely to occur in the near future. Chillers who are not internet connected at that moment, provide little insight in this pre-alarming phase.
Case Study
Premium Appliance Producer Innovates with Internet of Everything
Sub-Zero faced the largest product launch in the company’s history:It wanted to launch 60 new products as scheduled while simultaneously opening a new “greenfield” production facility, yet still adhering to stringent quality requirements and manage issues from new supply-chain partners. A the same time, it wanted to increase staff productivity time and collaboration while reducing travel and costs.
Case Study
Integration of PLC with IoT for Bosch Rexroth
The application arises from the need to monitor and anticipate the problems of one or more machines managed by a PLC. These problems, often resulting from the accumulation over time of small discrepancies, require, when they occur, ex post technical operations maintenance.
Case Study
Data Gathering Solution for Joy Global
Joy Global's existing business processes required customers to work through an unstable legacy system to collect mass volumes of data. With inadequate processes and tools, field level analytics were not sufficient to properly inform business decisions.