Halved the vulnerabilities reaching production | Case Study | The Software Geek
All case studiesEnterprise software

Halved the vulnerabilities reaching production

Client A US enterprise software providerServiceSecurity & ComplianceDuration 15 months

Security review sat at the end of the delivery pipeline, which made it both a bottleneck and easy to route around. The brief was to design an estate where the secure path is also the easy one.

50%Fewer vulnerabilities reaching production
days → minsInfrastructure provisioning time
4Compliance regimes kept audit-ready

The challenge

  • Security checks ran late in delivery, so problems surfaced when they were expensive to fix.
  • Infrastructure provisioning took days, pushing teams toward unreviewed workarounds.
  • Four compliance regimes applied at once: SOC 2, ISO 27001, PCI DSS and GDPR.
  • No consistent provenance for what was actually running in production.

What we did

  • Designed the security architecture for CI/CD and infrastructure, integrating SAST, DAST, SCA, secret scanning and container image scanning.
  • Built least-privilege self-service on Backstage and Crossplane so the fast path was also the governed one.
  • Designed the SBOM generation, artifact signing and provenance validation model for the software supply chain.
  • Codified security defaults into Terraform and Crossplane so compliance held by construction rather than by audit.

Technology

AWSEKSTerraformCrossplaneBackstageKyvernoSBOMSAST/DAST/SCA

Facing something similar?

Tell us what you are working on and we will come back with a straight answer on whether we can help, and what it would take.

Schedule Free Consultation

More work