Skip to content
Case Study

Scaling Security Testing Without Starting Over

How a Fortune 100 technology company extends its offensive security team with UltraViolet Cyber, testing web, mobile, client, and embedded systems entirely within the customer’s environment.

At A Glance

Industry:
Technology and cybersecurity

Company Size:
Fortune 100 Enterprise

Security Offering:
Web, mobile, client, and embedded systems penetration testing; source code review

Region:
North America
 


 

12+ Years of Partnership

Supporting the customer’s security program 

~240 Consultant-Weeks a Year  

Delivering specialized security testing

100% Inside Customer Systems  

Keeping code and data inside customer systems 

A global technology and cybersecurity company develops web and mobile applications, client software, and embedded systems used by enterprises worldwide. Its in-house offensive security team runs adversary emulation and coordinates security assessments across this portfolio. Each in-scope product must undergo an annual security assessment to meet internal policy, regulatory obligations, and customer requirements.

UltraViolet Cyber began supporting a single business group more than a decade ago. As the customer consolidated the security program and testing requirements grew, UltraViolet’s support expanded across the portfolio.

 

 

The Program Context

At this scale, security testing is not a series of periodic projects. It is an ongoing operating rhythm. Planning happens quarterly, multiple assessments are underway at any given time, and testing volume rises and falls with release schedules and seasonality.

The customer forecasts 40 to 80 consultant-weeks of testing each quarter. That range requires a partner that can scale capacity up or down while maintaining the technical expertise, consistent delivery, and program knowledge each assessment requires.

Three constraints shape how the program operates:

Code and Data Cannot Leave Customer-Controlled Systems

Sensitive code and data must remain inside the customer’s environment, so every assessment must run on customer-controlled infrastructure.

Different Products Require Different Testing Plans

Each product type presents a distinct risk profile, and the program also includes source code reviews. A single plan applied across the portfolio could miss important attack paths and edge cases.

Many of the Company's Customers Require CREST-Accredited Testing

Many of the company’s enterprise customers require assessments from a CREST-accredited external provider, and some request UltraViolet Cyber by name. UltraViolet’s accreditation allows the program to meet those requirements through the established delivery team.

 

 

The Approach

UltraViolet Cyber operates as an extension of the customer’s offensive security team. Together, the teams have refined an operating model that adjusts testing as the product portfolio, business priorities, and risk landscape change.

 

Every Assessment Begins With Current Context

Before testing, the team reviews what has changed since the previous assessment and identifies the highest-risk attack paths and edge cases based on the product, architecture, and scope. The customer follows a rigorous testing methodology and expects its partners to challenge the plan, so the delivery team scopes each assessment to current conditions rather than reusing a checklist from the prior review.

Testing Stays Where the Code and Data Live

UltraViolet testers work directly within the customer’s approved tools and infrastructure. When broader access supports deeper analysis, the customer provides the delivery team with the full internal tool suite, including AI tools, without moving code or data to external systems.

Capacity Flexes With Quarterly Demand

Because the customer forecasts testing volume a quarter in advance, UltraViolet aligns staffing with the forecast and each assessment's technical requirements. During heavier quarters, the delivery team increases capacity and adjusts around release schedules and planned freezes. 

Weekly Planning Keeps Priorities Aligned

Each week, both teams review active assessments, schedule changes, and upcoming demand. Between meetings, the customer can reach the delivery lead directly whenever questions arise and receive answers grounded in the current state of the work. When priorities shifted several times during a recent planning cycle, UltraViolet resequenced the work without disrupting the broader testing plan.

 

Customer Impact

Together, these practices create a testing program that can absorb change without losing momentum or rigor. The impact is visible in day-to-day delivery and in how the program performs over time.

The Internal Team Stays Focused on Offense

The customer’s security organization divides assessments between its in-house team and external partners. Each quarter, UltraViolet Cyber handles its planned share of that external work, so the internal offensive security team can focus on adversary emulation and red teaming.

Annual Security Assessment Commitments Stay on Track

Year after year, the customer has completed every required annual assessment across the portfolio, including through release crunches, seasonal freezes, and mid-cycle priority shifts.

Findings Stand Up to Technical Scrutiny

The customer’s experienced in-house offensive security team reviews each assessment report. In some cases, those reports also support assurance requirements from the company's  enterprise customers. Detailed evidence and validated findings give engineering teams clear direction, so they can move from report to remediation with less follow-up.

Specialist Capacity Is Built into the Plan

As demand changes, the customer can draw on specialists in embedded systems, mobile applications, source code review, and other testing disciplines without sourcing qualified testers one assessment at a time. UltraViolet’s broader application security practice includes 355+ professionals delivering 7,000+ assessments each year.

 

Why the Partnership Continues 

The customer works with two assessment partners and assigns work each quarter based on scope, required expertise, and delivery performance. Neither partner is guaranteed a set volume, so each must continue earning the work. The customer consistently uses the testing capacity planned with UltraViolet.

At the most recent annual renewal, the customer cited the fully intact delivery team as a reason to continue the partnership. Several UltraViolet team members have supported the program for more than a decade, and the customer’s current program director has worked with the team for nearly as long.

During recent onsite executive sponsor reviews, two program stakeholders independently highlighted the delivery team’s technical depth and consistent delivery.

Continuity gives the customer more than flexible testing capacity. Institutional knowledge carries from one assessment to the next. The growing baseline helps the delivery team scope work faster, focus testing more precisely, and keep pace as the customer’s products, technologies, and priorities change.

The program lead has also begun introducing UltraViolet to other business units across the company.

 

Build a Security Testing Program That Holds Up Under Real Pressure

Talk to our team about a security testing model built around your portfolio, environment, and release cadence.

Explore Penetration Testing