Case Study: StoneX reaches unified risk visibility across 8,000 repositories in 48 hours with Cycode
Key results
The challenge
StoneX runs a large engineering organization with over 1,000 developers across more than 50 product teams and approximately 8,000 code repositories. Its existing security tooling was fragmented, forcing the application security team to manually consolidate data from four different source-control management platforms and five different scanning tools just to answer basic questions, with no automated correlation between SAST, SCA, and DAST results.
The solution
StoneX adopted Cycode's unified ASPM platform with native scanning and graph-based context intelligence, connecting its source-control systems, integrating a third-party DAST scanner, and linking Active Directory. The team also stood up a gamified, belt-based Security Champions maturity program with Cycode enforcing scanning coverage and policy in developer workflows.
“In 48 hours, we had a more complete view of our risk posture than we had managed to build in the previous years.”
CPCássio Batista PereiraApplication Security Evangelist, StoneX
The results, in context
Connecting the SCMs, integrating the DAST scanner, and linking Active Directory took roughly a day, and within two days the security team had unified visibility across all 8,000 repositories. StoneX reported gaining a more complete view of its risk posture in 48 hours than it had managed to build in the previous years, replacing manual consolidation across four SCM platforms and five scanning tools with a single platform.