Fortune 500 healthcare provider shifts application security left
Security scans were delaying deployments and findings reached developers months late. Winmill moved testing into the developers’ own workflow, and the metrics followed.
Industry: HealthcareService: Application Security
Remediation time cut in half
Scan volume grew 200 percent
Security and development now work as one team
The project
One of the largest healthcare providers in the US needed help with application security. Governed by HIPAA, PCI, and a long list of other regulations, the company struggled to ensure its applications were being sufficiently and efficiently tested for vulnerabilities. The security team was overburdened and overscheduled, so scans were delaying production deployments. And the handoff from security testers to developers was clumsy: it was unclear which vulnerabilities were real, how they should be fixed, and whether they were fixed at all.
The challenges
Testing arrived too late. The security team held full control of application security testing, and it happened very late in the development lifecycle. Scan results reached development teams weeks or even months after the code changes were committed.
A massive application. The development team supports a home-grown, client-facing application of more than one million lines of code, deployed across several hundred affiliated websites, with hundreds of third-party dependencies and REST API integrations for hundreds of partner companies.
MFA blocked automation. Production and staging environments require SMS multi-factor authentication to log in, which made automating security scans significantly harder.
No pipeline to build on. The company had no continuous integration or deployment architecture that automated scanning could plug into.
The solution
Winmill helped the company evaluate scanning solutions and recommended a leading dynamic application security testing tool, Acunetix, now part of Invicti Security. After a proof of concept confirmed the fit, Winmill handled installation, application onboarding, and configuration. Scanning shifted left into the QA environment, which eliminated the multi-factor authentication obstacle for the majority of scans.
Winmill trained the developers on the tool, taught best practices to designated security champions on the development team, and integrated the platform into the company’s development lifecycle, including a direct connection to Jira. Remediation strategies and best practices were established and folded into the SDLC as well.
The results
Security and development on the same team. The two groups now work in an integrated DevOps architecture. Developers run scans before posting code, managers schedule recurring or immediate scans, and new applications are incorporated into the architecture automatically.
Automatic routing. When a scan completes, the application owner is notified and tickets are created and assigned in Jira. Developers can retest a specific vulnerability to confirm remediation instead of re-running a full scan.
No more bottleneck. Applications are scanned and remediated before production, and deployment cycle times have been dramatically reduced.
The numbers. Application security scans increased by more than 200 percent, and mean time to remediation decreased by more than 50 percent. With daily scanning in the developers’ hands, the security team focuses on strategic security planning.
Is security testing keeping up with your releases?
Tell us what you’re building and we’ll connect you with the engineers who integrate security into development pipelines every day.