Skip to content
Winmill

Winmill

  • Services
    • AI Solutions
      • Data & Intelligence
      • Microsoft Fabric & Foundry
      • AI on Your Data
      • Machine Learning Operations
    • Cloud Engineering
      • AKS to Azure Container Apps
    • Custom Software Development
      • Cloud, Desktop & Mobile Apps
      • Rapid Prototyping & MVP
      • DevOps & CI/CD Engineering
      • Technologies & Tools
    • Cybersecurity
      • Penetration Testing
      • Application Security
      • Cloud & Infrastructure Security
    • Data Center & IT Support
      • Managed IT Services
      • Disaster Recovery & Business Continuity
      • Microsoft License Review
      • IT Advisory & Procurement
  • About
    • Company
    • Leadership
    • Careers
    • Partners
  • Resources
    • Blog
    • Success Stories
  • Get in Touch
Success Story

TV broadcaster integrates Fortify into 300 application pipelines

One of the largest direct-broadcast and IPTV providers wanted static application security testing built into its development lifecycle, not bolted on after. Winmill delivered it in two phases.

Industry: Media and BroadcastingService: DevSecOps Integration
  • Scanning runs inside CI across more than 300 application pipelines
  • A self-service scan portal for developers
  • Vulnerabilities caught early, where they’re cheapest to fix

At a glance

Client
A national TV broadcaster
Situation
Hundreds of application pipelines with no security scanning built in
Scope
Fortify integrated into the CI architecture, with self-service scanning
Technology
Fortify

The project

When one of the largest providers of direct-broadcast and IPTV services needed to integrate application scanning into the development lifecycle of an increasingly complex application portfolio, it called Winmill. The organization had been using several different products to identify, prevent, and remediate risks like injection vulnerabilities, sensitive data exposure, insecure deserialization, and cross-site scripting. The IT security group wanted to standardize on Fortify SCA, from Micro Focus and now OpenText, and use it to its full potential: static application security testing fully integrated into the SDLC.

The challenges

  • Scanning inside CI. Fortify SCA had to integrate with the continuous integration tools, with results viewable from within the CI pipeline.
  • Faster cycles. Scan times had to come down and feedback loops had to shorten.
  • Security in the merge process. Vulnerability assessments had to feed the merge-approval process, determining when a code change needs a security review before it lands.
  • Developer independence. Developers needed to run scans without engaging the security team, and results had to flow into issue trackers like Jira, GitLab, and Rally.

The solution

Winmill first integrated Fortify SCA with Jenkins, implementing a job that executes a scan, feeds results into an enterprise-wide reporting dashboard, submits a Jira ticket, and emails an auto-generated PDF report to the application security team.

In the second phase, Winmill built a custom portal that lets developers upload code for an ad hoc Fortify scan whenever they choose, without setting up integrations on each workstation or forcing a full application build. The developer signs in through single sign-on, submits a source package with a configuration file, and gets notified that the job is queued. When the scan completes, an email link delivers the full report for review and remediation. The portal processes everything asynchronously and logs all activity for usage monitoring.

The results

  • Shift left, spend less. Integrating scanning into the DevOps architecture catches vulnerabilities early in the lifecycle, where they’re cheapest to fix.
  • Scale across the portfolio. Simultaneous scans run efficiently across more than 300 separate application pipelines, and integration with the build process frees developer time while keeping the process consistent.
  • Sharper triage. The architecture helps the organization triage and prioritize vulnerabilities across the whole portfolio.
  • Security champions, found by data. Usage data identifies the individuals and teams using the system most effectively, so they can be recognized and considered for security leadership roles.

Could your pipelines scan themselves?

Tell us what you’re building and we’ll connect you with the engineers who integrate security into development pipelines every day.

Get in touch See more success stories
Winmill

Enterprise software, built and defended since 1994.

Services

  • AI Solutions
  • Cloud Engineering
  • Custom Software Development
  • Cybersecurity
  • Data Center & IT Support

Company

  • About
  • Success Stories
  • Blog
  • Careers

Connect

1501 Broadway STE 12060
New York, NY 10036-5601

Ready to discuss your project?

Start a Conversation

© 2026 Winmill Software. All Rights Reserved. Privacy Policy  |  Accessibility