---
title: "The Email that Launched a Global AppSec Team"
date: "2026-10-07T19:56:09+00:00"
url: "https://checkmarx.com/resources/the-email-that-launched-a-global-appsec-team/"
---

# The Email that Launched a Global AppSec Team

- [Home](https://checkmarx.com/)
- [Customer Stories](https://checkmarx.com/resources/resource-type/customer-testimonials/)
- [The Email that Launched a Global AppSec Team](https://checkmarx.com/resources/the-email-that-launched-a-global-appsec-team/)

Case Study

How one fintech’s security program scaled from small pen testing to real-time risk visibility with Checkmarx One.

![The Email that Launched a Global AppSec Team2x](https://checkmarx.com/wp-content/uploads/2026/10/The-Email-that-Launched-a-Global-AppSec-Team2x.webp)

![](https://checkmarx.com/wp-content/uploads/2026/06/Correlate-Signals-1.svg)

One consolidated signal

![](https://checkmarx.com/wp-content/uploads/2026/06/Visibility-V2.svg)

Real-time risk visibility

![](https://checkmarx.com/wp-content/uploads/2026/06/Risk-Reduction-1.svg)

MTTR cut by 3x

The Need

## Background

Sometimes an email asking a few questions can change a career.

It was around 13 years ago that a then-IT professional had some ideas on how to help protect the sales team from social engineering by bad actors. So he emailed the CIO a list of questions.

The CIO replied, “Those are fantastic questions… go figure it out. Now you’re on the security side.”

Fast-forward to today. The IT professional became the company’s Business Information Security Officer (BISO), a financial services and education technology company serving schools and institutions from kindergarten to universities. Today, he leads a team across business lines and dozens of applications supporting thousands of clients in dozens of countries.

Getting to this point meant evolving Application Security from point-in-time events into something continuous. In his team’s early days, security relied on annual pen testing. As the company grew, those tests became more frequent. But the code was changing so fast that reports went stale, he says, “as soon as they came off the printer.” Developers burned hours closing findings instead of building applications.

Security needed a holistic solution that integrated earlier into the development lifecycle without slowing developer productivity or losing the trust they had spent six years building with product and engineering. As they looked at options, one requirement was always non-negotiable: speed. If a tool slowed developers down, that was the end of the conversation.

The Solution

## One Platform, Global Reach

After a competitive evaluation and proof of concept, the team chose Checkmarx One to unify their application security testing onto one platform, Checkmarx One first rolled out to a curated group of early adopters. Within two months, the team onboarded every repository, then shifted focus to measurement, exception workflow, and pipeline integration.

One of the most appealing benefits was how the unified platform and Risk Orchestration capabilities created a centralized experience for a team used to being inundated with signals from many tools. Checkmarx One was viewed as one central signal to support operational needs, not six additional signals stitched together.

That single view now spans the entire application estate, allowing the team to look at enterprise posture down to individual applications and the team that built them. Recurring findings become legible patterns, so they can indicate whether an issue is a training or tooling problem.

For this fintech’s developers, the change was that security stopped arriving after the fact. Findings now surface in the developer’s IDE the moment code is written — including AI-generated code — with a suggested fix attached. No separate console, no waiting on a build, no context to reconstruct later. Security is part of writing the code rather than an interruption to it.

## The Double-Take: “can you run those numbers again?”

The first quarter of full deployment produced what the customer called a “happy surprise.” When the analyst sent initial metrics, the BISO’s response wasn’t congratulations. It was, “can you run those again?” She did. They held.

In three months, several hundred critical and high vulnerabilities were closed and Mean Time to Remediation (MTTR) went down by a factor of three. Both were achieved before any pipeline enforcement. Results came from putting findings in front of developers as they wrote.

The BISO built an ROI model simple enough to survive an executive review: fully loaded developer cost, multiplied by the time saved per finding (roughly 2.5 hours, comparing in-IDE remediation against post-pen-test remediation), multiplied across every finding remediated. That produced a hard dollar figure and set up the question they are working on next: what developers build with the hours they get back.

The Results

## Identifying Champions, Gamifying the Process

A reliable and meaningful Application Security strategy is about enabling the business to be as secure as possible while still empowering people to innovate, experiment, and move fast without creating unnecessary friction. That’s why the rollout of Checkmarx One started with people rather than policy.

Any new technology rollout for an organization is first and foremost a change management exercise. So leadership rolled out Checkmarx One to early adopters embedded in product teams. These “champions” explained the tooling to their teammates in their own language, which traveled further and faster than the same message from security. “When it’s one of their own teammates who says ‘you should really use this tool,’ that makes a big difference,” noted the BISO.

Then it got competitive. Developer teams started comparing results and showing up to meetings having already cleared their findings. No incentive scheme, no leaderboard, nobody in security set it up. Security, the thing that interrupts work that developers weren’t always excited about — had become something to win.

## What’s Next for this Team?

DAST is planned to roll out alongside SAST, giving the team visibility into both how code is written and how applications behave at runtime. This customer is also an early adopter of Checkmarx Triage & Remediation Assist, which will allow developers to triage the backlog and submit merge-ready fixes for easy approval by developers.

It’s been 13 years since this BISO sent off that fateful email that changed his career path. But the expectations of his team remain the same: secure the estate, keep the backlog from becoming the work, and empower developers with solutions that help them build technologies that make a difference for customers around the world.

Looking ahead, the team is embracing a future where security becomes increasingly seamless, automated, and embedded into the development process. The goal is to make secure software delivery the path of least resistance, allowing developers to focus on what they do best: building, innovating, and delivering value to the business.

- **Enterprise risk visibility:**Real-time posture across all dozens of applications, drillable to team level
- **Developer time per finding:**10–15 minutes in the IDE; seconds when the suggested fix is accepted
- **Mean time to remediation:**Reduced by a factor of three in three months
- **Critical and high backlog:**700+ findings closed in three months
- **Signal management:**One consolidated signal into security operations

“We just see Checkmarx One as truly one signal that gives us our operational needs, not six more signals stitched together.”

— Business Information Security Officer & AppSec Leader

- Industry Financial Services, Education Technology
- Location Lincoln, Nebraska

[Checkmarx One](https://checkmarx.com/product/application-security-platform/) [SAST](https://checkmarx.com/cxsast-source-code-scanning/) [Triage and Remediation](https://checkmarx.com/product/triage-and-remediation/)

 [Download the Case Study](https://checkmarx.com/wp-content/uploads/2026/10/100726-Nelnet-Case-Study.pdf)

### See Checkmarx One in Action

Agentic AppSec that finds, triages, and fixes vulnerabilities autonomously.

 [Request a Demo](https://checkmarx.com/request-a-demo/)
