A UK media and telecommunications firm has significantly enhanced its security posture by partnering with RiverSafe, a cybersecurity solutions provider. Faced with decentralized security data and inefficient operational processes, the company aimed to boost operational efficiency and visibility across its IT environment.
Before collaboration with RiverSafe, the firm dealt with disparate security tools, which siloed data and required extensive time and effort from developers, security teams, and executives to track down important vulnerability information.
Challenges of Disparate Security Data
The company struggled with a lack of centralized Continuous Integration/Continuous Deployment (CI/CD) pipelines, resulting in separate processes for individual developers or teams.
This situation not only increased inefficiency but also elevated the risk of vulnerabilities going unnoticed, proving frustrating for the development team. Developers often lacked comprehensive insight into the organization's security status, which hampered their ability to address security concerns swiftly.
RiverSafe's Tailored Solution
RiverSafe developed an integration script that allowed developers to efficiently execute their pipelines
To tackle these challenges, RiverSafe developed an integration script that allowed developers to efficiently execute their pipelines.
Once activated, the script notified a customized server designed by RiverSafe to aggregate identified vulnerabilities and relay them back to developers' pull requests. This ensured that the necessary information reached developers quickly, allowing for timely resolution of security issues.
Advancing Data Insights
RiverSafe then collaborated with the client's team to channel all security data into a centralized pane-of-glass tool. Developers can now access all their repositories and projects in one unified interface, while management benefits from a holistic view of vulnerabilities and their impact.
The tool features a scoring model to visually assess repository security levels, providing alerts for any deficiencies. Additionally, RiverSafe supplies strategic guidance for addressing vulnerabilities.
Embracing Multiple Security Operations
The tool supports various security operations, including SAST, SCA, and Secret Scanning
The tool supports various security operations, including Static Application Security Testing (SAST), Source Code Analysis (SCA), and Secret Scanning.
Built serverless on AWS, the solution minimizes infrastructure maintenance time. Continuous improvements, quality enhancements, and integration expansions have been made to this tool since its launch.
Positive Outcomes and Future Plans
This centralized tool now consolidates data from over 22,000 code repositories. It empowers the company to analyze security data, common library usage, and vulnerability trends, significantly cutting down time previously spent searching for data across multiple locations.
As a result, response times to zero-day vulnerabilities have drastically improved, enabling the immediate location and remediation of affected repositories. Enhanced operational efficiency allows developers to focus more on code quality. Moving forward, RiverSafe, along with the client, plans to expand coverage, enhance analytics and alert systems, and centralize CI/CD pipelines.
The client, a British media and telecommunications company, was looking to increase operational efficiency, save time spent on identifying and addressing vulnerabilities and reduce risk by increasing visibility across their environment.
With multiple security tools in different places, security data was siloed and needed to be accessed separately. This led to long periods of time spent jumping between tools to find data, and a lot of context switching when it came to looking at the results. Developers, security teams and senior directors were forced to search in multiple places for critical, often time-sensitive information about vulnerabilities.
Risk of vulnerabilities
Not only did this eat into their valuable time, but it also meant they had no overall visibility into the organization’s security posture. This lack of visibility significantly hampered the development process, as developers struggled to locate and address security issues.
In addition, the organization did not have centralized CI/CDs, instead running different pipelines for individual developers or teams. Combined with poor visibility, this lack of efficiency was causing major frustration for the development team, slowing down development and increasing the risk of vulnerabilities in the code going undetected.
The solution
RiverSafe was initially brought on board to address the issue of decentralized security data, and help improve operational efficiency. The team’s goal was to allow for the results to be sent directly to the developers without them needing to access and search multiple security platforms to find the information they needed.
The RiverSafe team created an integration script for the developers to execute when they were running their pipelines. Once triggered, the script would send a notification to a server that RiverSafe had specifically designed, which collated the identified vulnerabilities and relayed them back to the developers’ pull request. This ensured the development team got the information they needed to improve the security of their code.
The next phase: Developing the data insights
RiverSafe consultants worked alongside the client’s team to take all the security data that was being collected and, rather than sending it to individual developers’ pull requests, instead created and directed it to a pane-of-glass tool.
This tool allows the developers to log in and see their repositories and projects in one place. For management, it allows them to have a complete picture of all the vulnerabilities and what they are impacting, on both individual repositories or a given product.
The tool also allows them to build reports and includes a scoring model to give a visual rating so everyone can easily see if their repositories are secure or not. The scoring system, ranging from insecure to excellent sends alerts to let the developers know if their repositories fall below a certain level so they don’t need to continually monitor themselves. The RiverSafe team also provides advice on the steps that should be taken to remediate any identified vulnerabilities.
Multiple security operations
A key requirement of this tool was that it supported multiple security operations, including SAST (Static Application Security Testing), which would look at code smells and general quality of life, Source Code Analysis (SCA), which would look at which libraries are being used and also Secret Scanning to look for secrets in the code.
RiverSafe also wanted to ensure that all of this is serverless on AWS to minimize the time spent on infrastructure maintenance. After launching, RiverSafe continued to work on improving this tool, making quality improvements, performing maintenance, and enhancing the integration via the shell scripts.
The outcome
The tool now brings together data from over 22,000 code repositories into one centralized place, allowing the client to see all of their security information, what libraries were most common, where the vulnerabilities were, and to start looking for trends.
Developers and other stakeholders no longer need to scour multiple locations for vulnerability data, saving the company huge amounts of time and making its development process more efficient. With the bespoke script in place, the data comes to them. This increase in visibility has also led to improvements in response times to zero-day vulnerabilities. Previously, it could take weeks or even months to find all the affected repositories.
However, since implementing RiverSafe’s custom tool, the team has been able to locate repositories featuring the vulnerable package immediately and remediate any issues quickly, massively improving their overall security posture. Thanks to this uplift in operational efficiency, the development team is now able to spend more time improving their code. RiverSafe and the client’s team are now working on expanding coverage throughout the organization, improving analytics and alerting, and centralizing CI/CD pipelines.