An $800 million litigation services corporation connects thousands of attorneys to depositions worldwide through its patented platform, which handles millions of confidential legal and medical records. For a business built on trust, security is not a feature. It is the product.
The challenge
The CTO wanted an honest read of the platform's cyber weaknesses and strengths, and a roadmap to resolve them in priority order: how would the business fare in a cyberattack, and what would it take to be ready?
How we helped
In four weeks we completed static code analysis and software composition analysis across the application, categorizing vulnerabilities with the OWASP Top 10 and rating severity with CVSS v3.0. The assessment scored the platform's availability, confidentiality, integrity, and overall health, giving the technology division a defensible baseline. Leadership then asked us to stay and fix what we found.
The result
We fixed 18 critical vulnerabilities within the first two weeks, including multiple code-injection risks, removed all 26 high-severity issues, and resolved 33 cross-site AJAX risks in the collections component. The platform's overall health score rose 70 percent. We left a best-practices template for future delivery, and the firm engaged us to evaluate eight more applications.
