Case Study
Scaling Security Testing Without Starting Over
How a Fortune 100 technology company extends its offensive security team with UltraViolet Cyber, testing web, mobile, client, and embedded systems entirely within the customer’s environment.
12+ Years of Partnership
Supporting the customer’s security program
~240 Consultant-Weeks a Year
Delivering specialized security testing
100% Inside Customer Systems
Keeping code and data inside customer systems
A global technology and cybersecurity company develops web and mobile applications, client software, and embedded systems used by enterprises worldwide. Its in-house offensive security team runs adversary emulation and coordinates security assessments across this portfolio. Each in-scope product must undergo an annual security assessment to meet internal policy, regulatory obligations, and customer requirements.
UltraViolet Cyber began supporting a single business group more than a decade ago. As the customer consolidated the security program and testing requirements grew, UltraViolet’s support expanded across the portfolio.
The Program Context
At this scale, security testing is not a series of periodic projects. It is an ongoing operating rhythm. Planning happens quarterly, multiple assessments are underway at any given time, and testing volume rises and falls with release schedules and seasonality.
The customer forecasts 40 to 80 consultant-weeks of testing each quarter. That range requires a partner that can scale capacity up or down while maintaining the technical expertise, consistent delivery, and program knowledge each assessment requires.
Three constraints shape how the program operates:
Code and Data Cannot Leave Customer-Controlled Systems
Sensitive code and data must remain inside the customer’s environment, so every assessment must run on customer-controlled infrastructure.
Different Products Require Different Testing Plans
Each product type presents a distinct risk profile, and the program also includes source code reviews. A single plan applied across the portfolio could miss important attack paths and edge cases.
Many of the Company's Customers Require CREST-Accredited Testing
Many of the company’s enterprise customers require assessments from a CREST-accredited external provider, and some request UltraViolet Cyber by name. UltraViolet’s accreditation allows the program to meet those requirements through the established delivery team.
The Approach
UltraViolet Cyber operates as an extension of the customer’s offensive security team. Together, the teams have refined an operating model that adjusts testing as the product portfolio, business priorities, and risk landscape change.
Every Assessment Begins With Current Context
Before testing, the team reviews what has changed since the previous assessment and identifies the highest-risk attack paths and edge cases based on the product, architecture, and scope. The customer follows a rigorous testing methodology and expects its partners to challenge the plan, so the delivery team scopes each assessment to current conditions rather than reusing a checklist from the prior review.
Testing Stays Where the Code and Data Live
UltraViolet testers work directly within the customer’s approved tools and infrastructure. When broader access supports deeper analysis, the customer provides the delivery team with the full internal tool suite, including AI tools, without moving code or data to external systems.
Capacity Flexes With Quarterly Demand
Because the customer forecasts testing volume a quarter in advance, UltraViolet aligns staffing with the forecast and each assessment's technical requirements. During heavier quarters, the delivery team increases capacity and adjusts around release schedules and planned freezes.
Weekly Planning Keeps Priorities Aligned
Each week, both teams review active assessments, schedule changes, and upcoming demand. Between meetings, the customer can reach the delivery lead directly whenever questions arise and receive answers grounded in the current state of the work. When priorities shifted several times during a recent planning cycle, UltraViolet resequenced the work without disrupting the broader testing plan.
Customer Impact
Together, these practices create a testing program that can absorb change without losing momentum or rigor. The impact is visible in day-to-day delivery and in how the program performs over time.
The Internal Team Stays Focused on Offense
The customer’s security organization divides assessments between its in-house team and external partners. Each quarter, UltraViolet Cyber handles its planned share of that external work, so the internal offensive security team can focus on adversary emulation and red teaming.
Annual Security Assessment Commitments Stay on Track
Year after year, the customer has completed every required annual assessment across the portfolio, including through release crunches, seasonal freezes, and mid-cycle priority shifts.
Findings Stand Up to Technical Scrutiny
The customer’s experienced in-house offensive security team reviews each assessment report. In some cases, those reports also support assurance requirements from the company's enterprise customers. Detailed evidence and validated findings give engineering teams clear direction, so they can move from report to remediation with less follow-up.
Specialist Capacity Is Built into the Plan
As demand changes, the customer can draw on specialists in embedded systems, mobile applications, source code review, and other testing disciplines without sourcing qualified testers one assessment at a time. UltraViolet’s broader application security practice includes 355+ professionals delivering 7,000+ assessments each year.
Why the Partnership Continues
The customer works with two assessment partners and assigns work each quarter based on scope, required expertise, and delivery performance. Neither partner is guaranteed a set volume, so each must continue earning the work. The customer consistently uses the testing capacity planned with UltraViolet.
At the most recent annual renewal, the customer cited the fully intact delivery team as a reason to continue the partnership. Several UltraViolet team members have supported the program for more than a decade, and the customer’s current program director has worked with the team for nearly as long.
During recent onsite executive sponsor reviews, two program stakeholders independently highlighted the delivery team’s technical depth and consistent delivery.
Continuity gives the customer more than flexible testing capacity. Institutional knowledge carries from one assessment to the next. The growing baseline helps the delivery team scope work faster, focus testing more precisely, and keep pace as the customer’s products, technologies, and priorities change.
The program lead has also begun introducing UltraViolet to other business units across the company.
Build a Security Testing Program That Holds Up Under Real Pressure
Talk to our team about a security testing model built around your portfolio, environment, and release cadence.
ADDITIONAL INSIGHTS
READY TO GET STARTED?
We’re here to help. Get in touch for an initial conversation with one of our security experts and learn more about how UltraViolet Cyber can help you take cyber readiness and resilience to new levels.
UltraViolet Cyber Acquires Black Duck’s Application Security Testing Services Business
UltraViolet Cyber Launches Solstice