Case Study Deskcasestudydesk.com
Financial ServicesSourced

Case Study: StoneX reaches unified risk visibility across 8,000 repositories in 48 hours with Cycode

StoneX Case StudySourced & dated by Case Study Desk
Key facts · TL;DR
Company
StoneX
Industry
Financial Services
Challenge
Security tooling was fragmented across four SCM platforms and five scanning tools operating in silos.
Headline result
StoneX consolidated fragmented tooling onto Cycode and reported a more complete view of its risk posture in 48 hours than it had built in prior years, across roughly 8,000 repositories.

Key results

48 hours
To unified visibility across all repositories
~8,000 repositories, 1,000+ developers, 50+ product teams
~1 day
To connect SCMs, DAST scanner, and Active Directory
9 tools
Fragmented tools consolidated onto one platform
4 SCM platforms and 5 scanning tools

The challenge

StoneX runs a large engineering organization with over 1,000 developers across more than 50 product teams and approximately 8,000 code repositories. Its existing security tooling was fragmented, forcing the application security team to manually consolidate data from four different source-control management platforms and five different scanning tools just to answer basic questions, with no automated correlation between SAST, SCA, and DAST results.

The solution

StoneX adopted Cycode's unified ASPM platform with native scanning and graph-based context intelligence, connecting its source-control systems, integrating a third-party DAST scanner, and linking Active Directory. The team also stood up a gamified, belt-based Security Champions maturity program with Cycode enforcing scanning coverage and policy in developer workflows.

In 48 hours, we had a more complete view of our risk posture than we had managed to build in the previous years.

CP
Cássio Batista Pereira
Application Security Evangelist, StoneX

The results, in context

Connecting the SCMs, integrating the DAST scanner, and linking Active Directory took roughly a day, and within two days the security team had unified visibility across all 8,000 repositories. StoneX reported gaining a more complete view of its risk posture in 48 hours than it had managed to build in the previous years, replacing manual consolidation across four SCM platforms and five scanning tools with a single platform.

Products used

Cycode Cycode ASPM Platform