Skip to content
Winmill

Winmill

  • Services
    • AI Solutions
      • Data & Intelligence
      • Microsoft Fabric & Foundry
      • AI on Your Data
      • Machine Learning Operations
    • Cloud Engineering
      • AKS to Azure Container Apps
    • Custom Software Development
      • Cloud, Desktop & Mobile Apps
      • Rapid Prototyping & MVP
      • DevOps & CI/CD Engineering
      • Technologies & Tools
    • Cybersecurity
      • Penetration Testing
      • Application Security
      • Cloud & Infrastructure Security
    • Data Center & IT Support
      • Managed IT Services
      • Disaster Recovery & Business Continuity
      • IT Advisory & Procurement
  • About
    • Company
    • Leadership
    • Careers
    • Partners
  • Resources
    • Blog
    • Success Stories
  • Get in Touch
Success Story

Fortune 500 healthcare provider shifts application security left

Security scans were delaying deployments and findings reached developers months late. Winmill moved testing into the developers’ own workflow, and the metrics followed.

Industry: HealthcareService: Application Security
  • Remediation time cut in half
  • Scan volume grew 200 percent
  • Security and development now work as one team

At a glance

Client
A Fortune 500 healthcare services company
Situation
Application security testing lagged far behind development
Scope
DAST implementation with shift-left scanning inside the DevOps workflow

The project

One of the largest healthcare providers in the US needed help with application security. Governed by HIPAA, PCI, and a long list of other regulations, the company struggled to ensure its applications were being sufficiently and efficiently tested for vulnerabilities. The security team was overburdened and overscheduled, so scans were delaying production deployments. And the handoff from security testers to developers was clumsy: it was unclear which vulnerabilities were real, how they should be fixed, and whether they were fixed at all.

The challenges

  • Testing arrived too late. The security team held full control of application security testing, and it happened very late in the development lifecycle. Scan results reached development teams weeks or even months after the code changes were committed.
  • A massive application. The development team supports a home-grown, client-facing application of more than one million lines of code, deployed across several hundred affiliated websites, with hundreds of third-party dependencies and REST API integrations for hundreds of partner companies.
  • MFA blocked automation. Production and staging environments require SMS multi-factor authentication to log in, which made automating security scans significantly harder.
  • No pipeline to build on. The company had no continuous integration or deployment architecture that automated scanning could plug into.

The solution

Winmill helped the company evaluate scanning solutions and recommended a leading dynamic application security testing tool, Acunetix, now part of Invicti Security. After a proof of concept confirmed the fit, Winmill handled installation, application onboarding, and configuration. Scanning shifted left into the QA environment, which eliminated the multi-factor authentication obstacle for the majority of scans.

Winmill trained the developers on the tool, taught best practices to designated security champions on the development team, and integrated the platform into the company’s development lifecycle, including a direct connection to Jira. Remediation strategies and best practices were established and folded into the SDLC as well.

The results

  • Security and development on the same team. The two groups now work in an integrated DevOps architecture. Developers run scans before posting code, managers schedule recurring or immediate scans, and new applications are incorporated into the architecture automatically.
  • Automatic routing. When a scan completes, the application owner is notified and tickets are created and assigned in Jira. Developers can retest a specific vulnerability to confirm remediation instead of re-running a full scan.
  • No more bottleneck. Applications are scanned and remediated before production, and deployment cycle times have been dramatically reduced.
  • The numbers. Application security scans increased by more than 200 percent, and mean time to remediation decreased by more than 50 percent. With daily scanning in the developers’ hands, the security team focuses on strategic security planning.

Is security testing keeping up with your releases?

Tell us what you’re building and we’ll connect you with the engineers who integrate security into development pipelines every day.

Get in touch See more success stories
Winmill

Enterprise software, built and defended since 1994.

Services

  • AI Solutions
  • Cloud Engineering
  • Custom Software Development
  • Cybersecurity
  • Data Center & IT Support

Company

  • About
  • Success Stories
  • Blog
  • Careers

Connect

1501 Broadway STE 12060
New York, NY 10036-5601

Ready to discuss your project?

Start a Conversation

© 2026 Winmill Software. All Rights Reserved. Privacy Policy  |  Accessibility