About The Client

The client is a global leader in semiconductor and infrastructure software solutions, operating across domains such as networking, data centers, telecommunications, and cybersecurity.

With 10+ Business Units (BUs), each having its own suite of products and subproducts, the client struggled to overcome siloed processes, manual inefficiencies, and integration challenges while maintaining security across this vast ecosystem.

Business Challenge

The client's business units (BUs) was tasked with overseeing the security compliance across the BUs, each using different static analysis tools (Blackduck, SonarQube, Coverity, etc.) and managing vulnerabilities in siloed environments. The cybersecurity team used ArmorCode for centralized vulnerability visibility. 

However, Manual processes were leading to inefficiencies, miscommunication, and increased turnaround time in fixing vulnerabilities. 

  • Decentralized Scanning , Manual Processes, Lack of Real-time Coordination

    • Triaged vulnerabilities were manually exported from ArmorCode and shared via email or Excel spreadsheets
    • Product owners and security champions received updates in fragmented formats
    • Manual follow-ups created long email chains and alignment delays
  • Scalability Issues in Triaging

    • Triaging involved security analysts manually verifying and enriching vulnerability data from external sources
    • Average triaging time per vulnerability: 30–45 minutes
    • Analysts could triage ~100 vulnerabilities/day, while the need was 10,000+/day

Tools & Technologies

Saksoft Solution

  • Connector Development using ConnectAll

    • Connectors were built between ArmorCode and project management tools like Jira/ Rally using the ConnectAll universal adapter
    • Enabled bi-directional sync:
    • New vulnerabilities created in Armorcode to the respective product respective Jira/ Rally boards automatically
    • Any updates made on either side reflected across platforms in real-time
  • Custom Plugin for Siloed BU Boards

    • Several BUs had standalone Jira/Rally instances not integrated with ArmorCode
    • Developed a custom Python-based plugin to extract data from these instances and feed into ArmorCode
    • Allowed previously unconnected BUs to be onboarded into the centralized platform
  • Automated Triaging System

    • Defined and automated the triaging process using Python
    • Built a system to:
      1. Query public vulnerability databases (e.g., CVE, NVD)
      2. Parse security data (severity, exploitability, remediation)
      3. Provide enriched metadata for faster fixes
      4. Dynamically assess and assign severity based on multiple risk scores
      5. Reduced analyst workload and eliminated bottlenecks in vulnerability prioritization

Business Outcome

Full transparency, real-time communication, and significant reduction in manual coordination 

  • Improved Collaboration: Unified platform enabling seamless interaction across BUs

  • Enhanced Scalability: Automated triaging improved throughput from 100 to thousands per day, with digital security initiatives directly tied to business objectives
  • Increased Agility, Traceability: Rapid vulnerability management, reduced turnaround time, End-to-end visibility of assets, test plans, and remediations