Scaling Security Testing Without Starting Over
How a Fortune 100 technology company extends its offensive security team with UltraViolet Cyber, testing web, mobile, client, and embedded systems entirely within the customer’s environment.
Benchmarks your AI security practices against peer data.
Find flaws in AI Systems
Find flaws in web, mobile, and IoT applications.
Live-fire exercises to sharpen detection and response.
Time-boxed security assessments across networks, apps, and infrastructure.
Simulated attacks to test detection and incident response.
Named security experts integrated seamlessly into your team.
Real-time detection and automated threat response.
24x7 monitoring and response by expert analysts.
Detection-focused SIEM migration without visibility gaps.
UltraViolet's proprietary AI platform powering all application penetration testing.
Unified security platform powering all UV services.
Automated detection engineering across your security platforms.
Cross-platform toolkit for advanced red team ops.
UltraViolet Cyber provides security services across the AI lifecycle, combining strategy, threat modeling, adversarial testing, monitoring, and training to support secure AI adoption.
How a global financial software company keeps hundreds of marketplace applications moving through a ...
Secure your code, infrastructure, and deployment pipelines before attackers exploit them.
Before you trust a MITRE ATT&CK coverage number, run it through three questions. Here's what to ask, and why each one ...
UltraViolet's AISec Study uses an interview-based methodology to score AI security maturity across 10 organizations. Read ...
UltraViolet Cyber is a practitioner-led MSSP delivering offensive and defensive security to Global 2000 and Federal clients. Built by former intelligence operators, we unify application security, red teaming, detection, and engineering under one roof. Our UV Lens platform replaces silos with integrated, outcome-driven operations.
How a global financial software company keeps hundreds of marketplace applications moving through a repeatable security gate each year.
10+ Years of Partnership
Supporting the customer's third-party security program
~60 Priority Tests Active at Any Time
Continuous testing cadence across hundreds of developers
9+ Dedicated Assessors
Steady team supporting an ongoing assessment queue
For a global financial software company, every third-party application in its marketplace carries a measure of its reputation. Customers see those integrations as part of the company’s ecosystem, even though another developer builds the software. A vulnerability in that code can put both customer data and trust at risk.
The marketplace hosts hundreds of integrations, built by developers ranging from two-person shops to established software firms. Some applications handle basic data processing. Others work with Social Security numbers and sensitive financial information. Each brings different risks, but by promoting them, the company puts its name behind software it does not build.
Before an application can enter the marketplace, it must pass a penetration test. Once listed, it must undergo testing again every year. Premium listings generate revenue for the company, but the testing requirement applies to every tier.
As the marketplace grows, keeping up means managing hundreds of assessments for developers with very different levels of security experience. Many are going through a penetration test for the first time. Each application needs to be scoped, compliance documentation collected, and findings explained so developers can work through remediation. Moving that work forward takes practitioner judgment and regular, direct conversations.
When the company first turned to UltraViolet Cyber, its internal security team was already working beyond capacity. The red team focused on black-box testing of live production systems. The pre-production testing needed to approve marketplace listings required separate support.
Today, that work runs through an ongoing assessment program, with UltraViolet supporting both the testing and the developer coordination needed to keep it moving.
The company needs additional testing capacity that meets specific staffing and reporting requirements. Anyone who could access U.S. tax data must be based in the United States, which rules out offshore delivery for those engagements.
Every assessor must also hold recognized security certifications. For money-movement products that process billions of dollars, the company has historically reviewed assessors’ resumes and interviewed them before approving their participation.
The reporting requirements are equally specific. The company needs formal, well-documented external testing reports that meet its expectations for rigor and support internal reviews.
UltraViolet continues to meet these requirements year after year. As the company pursues ISO/IEC 27001 certification, independent third-party testing also gives the team evidence it can use in its compliance and certification work.
UltraViolet Cyber serves as the company’s Virtual Security Team (VST), providing ongoing support as an extension of its product security team. A dedicated program manager coordinates assessments from intake through completion, keeping work moving across nine dedicated assessors. As one assessment concludes, the next begins, sustaining a steady testing cadence throughout the year.
The work begins with understanding the application: how critical it is, what data it handles, what has changed since its last review, and how technically complex it is. UltraViolet and the customer use those factors to scope each review. Applications that handle sensitive data, such as Social Security numbers, receive a full, in-depth assessment, while simpler, lower-risk applications receive a narrower, focused assessment.
As one assessment concludes, the next begins. With roughly 60 priority tests active at any time, that steady cadence supports testing throughout the year.
Much of the work happens in direct conversations with developers. UltraViolet handles most of that communication, from onboarding and collecting SOC 2 documentation and other artifacts to following up with the hundreds of development teams moving through the security gate.
The company previously brought this coordination in-house, but found that it took time the security team needed for other work. Today, UltraViolet helps developers understand what to expect, work through findings, and complete the steps needed to move forward. That guidance is a substantial part of the engagement, particularly for teams unfamiliar with security testing.
Most applications in the marketplace are mobile, making hands-on testing especially important. UltraViolet provides manual mobile testing in a program where much of the other assessment coverage is automated. That work has been particularly useful in identifying mobile application vulnerabilities, with reports that help developers understand what the assessors found.
One of the program’s most consequential improvements is how the company verifies that vulnerabilities have been addressed.
With UltraViolet’s input, the company updated its program to require remediation and retesting of critical and high-severity findings. A developer’s confirmation alone is no longer enough. Applications with critical findings cannot enter the marketplace until those findings are resolved or a formal exception is granted.
Over 10+ years, the relationship has grown from individual assessments to quarterly engagements and then to an annual program. Today, it gives the company a repeatable way to manage third-party application risk as its marketplace grows.
The same findings support weekly risk reporting to leadership. The company tracks remediation SLAs by severity, from seven days for critical third-party findings to 90 days for low-severity findings. Adherence is reported weekly to a CISO who reports directly to the CEO. UltraViolet’s structured reports support that tracking and provide evidence for audit reviews.
Assessment data also feeds the company’s operational dashboards. Its data analysts use UltraViolet’s APIs to bring findings into dashboards that track risk across the marketplace and help inform leadership decisions.
The testing process helps the company keep its developer requirements current, too. When developers challenged findings by pointing to the company’s published security requirements, UltraViolet identified places where those requirements had fallen behind current industry standards. That input helped the company update its developer-facing policies, bringing what developers are asked to follow into closer alignment with how their applications are assessed.
Through reorganizations, changes in program ownership, and acquisition transitions on the partner side, the program has maintained its capacity. Established relationships and trust help the teams preserve continuity through those changes.
That continuity is part of the day-to-day working relationship. Weekly meetings give the company regular access to information and time to discuss questions, priorities, and improvements. The security operations manager values the team’s approachability and communication enough to maintain a weekly meeting cadence they do not have with any other vendor.
For the company’s security operations manager, a former NSA red teamer, finding a vulnerability begins a much longer process. A testing partner’s value depends on how well it supports the work that follows.
That perspective continues to shape the program. Findings guide remediation and retesting, strengthen developer requirements, and give leadership evidence to guide risk decisions.
Third-party developers are starting to ask that AI components be included in their reviews as they build more AI-driven features into their applications. The company already sets clear requirements for assessor location, security certifications, and formal reporting. It brings that same emphasis on rigor to AI testing tools, which undergo internal review before being adopted into the program.
As testing needs expand, the partnership builds on the team’s understanding of those requirements and its working relationships with developers, providing continuity in the people and processes that keep the program moving.
Support your team with dedicated practitioners who manage ongoing testing and developer coordination, helping you keep pace as your application portfolio grows.
We’re here to help. Get in touch for an initial conversation with one of our security experts and learn more about how UltraViolet Cyber can help you take cyber readiness and resilience to new levels.