-
Products
- Alphabetical List
- Business & Industry Applications
- Cybersecurity
- Data and Analytics
- AI and Intelligent Operations
- Total Experience
- Sovereign Collaboration
- Specialized Software
- HCL Actian
- HCL Actian Data Platform
- HCL Actian Ingres
- HCL Aftermarket Cloud
- HCL AppScan
- HCL Automation Orchestrator
- HCL Automation Orchestrator Suite
- HCL BigFix
- HCL CAMWorks
- HCL Clara
- HCL Commerce Cloud
- HCL Connections
- HCL Customer Data Platform
- HCL DataConnect
- HCL DFMPro
- HCL Discover
- HCL Domino
- HCL DX
- HCL DevOps Code ClearCase
- HCL DevOps Code RealTime
- HCL DevOps Deploy
- HCL DevOps Plan
- HCL DevOps Model RealTime
- HCL DevOps Test
- HCL DevOps Test Embedded
- HCL DevOps Velocity
- HCL Glovius
- HCL Hero
- HCL iAutomate
- HCL iControl
- HCL Informix
- HCL IntelliOps
- HCL IntelliOps Event Management
- HCL iObserve
- HCL Leap
- HCL Link
- HCL Mainframe Solutions
- HCL Marketing Cloud
- HCL MyCloud
- HCL MyXalytics
- HCL Nippon
- HCL Notes
- HCL Now
- HCL SafeLinx
- HCL Sametime
- HCL Secure DevOps
- HCL SoFy
- HCL SX
- HCL TX Platform
- HCL Unica
- HCL Vector Analytics
- HCL Verse
- HCL Volt MX
- HCL Workload Automation
- HCL Z Asset Optimizer
- HCL Z Abend Investigator
- HCL Z and I Emulator
- HCL Zeenea Data Discover Platform
- HCL Zen Edge Data Management
- HCL Aftermarket Cloud Aftermarket-led growth platform
- HCL Commerce Cloud Enterprise e-commerce for B2C and B2B
- HCL CDP Flexible and customizable customer data platform
- HCL Discover Behavioral insights for customer journeys
- HCL Marketing Cloud Fueling precision marketing at scale with AI
- HCL Unica Enterprise marketing automation platform
- HCL AppScan Scans for application vulnerabilities
- HCL BigFix Secure endpoint management
- HCL BigFix Compliance Ensure security with continuous, real-time compliance monitoring
- HCL BigFix CyberFOCUS Supercharging IT operations to secure the enterprise
- HCL BigFix Remediate Automate, remediate & secure endpoints
- HCL Actian Empowers the data-driven enterprise
- HCL Actian Data Platform Data services suite; flexible deployment
- HCL Actian Ingres Legendary transactional RDBMS
- HCL DataConnect Low-code integration platform
- HCL Zeenea Data Discover Platform Cloud-native data governance solution
- HCL Zen Embeddable edge data management
- HCL Automation Orchestrator Suite Accelerate IT and business automation
- HCL BigFix Secure endpoint management
- HCL BigFix AEX AI-driven employee experience accelerating productivity and innovation
- HCL BigFix Enterprise+ An all-in-one IT infrastructure automation offering enabling you to stay ahead of cyber threats
- HCL BigFix Workspace+ Fueling GenAI within the Digital+ experience
- HCL iControl HCL iControl is a business flow and process observability solution
- HCL MyXalytics Cloud finOps visibility and insights
- HCL SX Service management for everything-as-a-service delivery
- HCL Workload Automation Simplify and automation business workflows
- HCL Connections Collaboration and task management in one workspace
- HCL Domino Rapid application development platform
- HCL Leap No code citizen app dev
- HCL Link Connectivity across your digital ecosystem
- HCL Notes Comprehensive email and collaboration hub
- HCL SafeLinx Secure and flexible remote access to enterprise applications
- HCL Sametime Secure meetings, video, and chat communications
- HCL Verse Smart and secure enterprise email for seamless workflow
- HCL Augmented Network Automation (SON)Intelligent RAN automation platform
- HCL Automation Orchestrator Suite Accelerate IT and business automation
- HCL DFMProCAD integrated Design-for-Manufacturing platform
- HCL CAMWorksCAM for machining productivity
- HCL GloviusModern lightweight CAD Viewer
- HCL Mainframe Optimization Optimize, modernize, and innovate your mainframe investments
- HCL Secure DevOps Automated testing and security scanning
- Industries
- Partners
-
Persona
- HCL Commerce Cloud Enterprise e-commerce for B2C and B2B
- HCL CDP Flexible and customizable customer data platform
- HCL DX The DXP for the moments that matter
- HCL Marketing Cloud Fueling Precision Marketing At Scale with AI
- HCL Unica Enterprise marketing automation platform
- HCL Volt MX Multi-experience low code app dev
- HCL Actian Ingres Legendary transactional RDBMS
- HCL Actian Data Platform Data services suite; flexible deployment
- HCL AppScan Scans for Application Vulnerabilities
- HCL BigFix Secure endpoint management
- HCL BigFix AEX AI-driven employee experience accelerating productivity and innovation
- HCL BigFix Enterprise+ An all-in-one IT infrastructure automation offering enabling you to stay ahead of cyber threats
- HCL BigFix Workspace+ Fueling GenAI within the Digital+ experience
- HCL DataConnect Low-code integration platform
- HCL Foundry Secure Backend Services
- HCL iControl HCL iControl is a business flow and process observability solution
- HCL MyXalytics Cloud FinOps visibility and insights
- HCL SX Service management for everything-as-a-service delivery
- HCL Universal Orchestrator Orchestrate and optimize business automation
- HCL Vector Analytics A high-performance, secure vectorized columnar analytics database
- HCL Workload Automation Simplify and automation business workflows
- HCL Zen Embeddable edge data management
- Learn & Support
What we achieved
-
Reduced risk
-
Lowered costs
-
Improved efficiency
To who
-
Industry: Telecommunication
-
Products: HCL AppScan
-
Region: North America/US
Overview
-
Part 1
Challenge
The client was faced with the following challenge: Being able to test roughly 4,000 applications, both employee and customer-facing. The client also needed to verify post-development that their applications had been developed securely, without security gaps that could potentially lead to breach vectors within the enterprise.
-
Part 2
Solution
HCL offers several commercial options to meet clients’ licensing needs, and they are either SaaS-based or on-prem-based. A workshop was initiated to understand the client’s requirements, their current state and their aspirational state. We architected a solution to meet the client’s needs with HCL AppScan Enterprise, our on-premise dynamic application security testing solution.
-
Part 3
Results
The client realized greater value through our ability to act as a trusted advisor in developing an end-to-end solution to meet their needs. We established a true partnership and stayed synchronized throughout strategic roadmap updates, where we discussed our latest research and development efforts and sought input and validation about HCL’s progress in meeting the future needs of the client and the industry.
The Challenge
Overview
Our client is one of the world’s largest telcos and they offer the following services: mobile, 5G, internet and networking, IoT, Voice and collaboration, cybersecurity, cloud, content and entertainment and digital capabilities.
The 4 challenges they faced were:
- Concern with their existing enterprise production application infrastructure’s vulnerability to attacks.
- Existing tools were slow and difficult to manage, because of the large scale of their applications.
- Existing tools did not support modern web applications, such as new languages and web application frameworks and technologies that they were developing.
- Existing tools could not be automated to plug into their continuous integration pipeline.
As a result, they were looking for a more sophisticated application security platform that could support today’s modern web applications technologies such as secure APIs and new application frameworks such as reactJS. They were also looking for a solution that offered enterprise-class scalability without slowing them down and the ability to handle large amounts of data, along with integration into their DevOps pipeline. That would enable our client to scan consistently and frequently, so vulnerabilities could be caught earlier in the lifecycle, resulting in lower development costs. Such an approach also reduced overhead, since a lot of the testing could be automated, with a significant reduction on teams’ requirements to manage testing.
The Solution
Scaling up and optimizing customer experiences
AppScan Enterprise allows the client to test their modern web applications, analyze their entire applications for accurate results and have the confidence that the platform is testing their applications against an extensive list of vulnerabilities to confirm that applications are secure. Our solution was able to scale up to the client’s large workload, integrate into their DevOps pipeline to be able to incorporate their dynamic application testing into their software development lifecycle, while meeting their requirements for optimized development practices that incorporate security as foundational.
- The HCL application security team, comprised of lab services and advocacy, established a center of excellence that would provision the enablement materials and best practice approaches for use of AppScan Enterprise. This was a critical element to leverage productive use and master functionality of the platform. It would establish the prerequisite skills to onboard and ramp up a consistent and optimized use of the tools and ensure desired standards, governance and outcomes.
- In addition, we integrated AppScan Enterprise into the client’s DevOps pipeline, enabling dynamic application security testing more frequently and consistently. This helped in the process of shifting left, by incorporating security earlier in the software development lifecycle, in order to catch and fix vulnerabilities more effectively. We also developed a process to capture metrics on applications that enabled transparency to the quality of the scans based on breadth, scope and a few other scan factors. Additional benefit was realized on visibility into the risk posture of every application we tested, specific vulnerabilities that affected each application tested and whether vulnerability remediation was addressed.
The Results
The client realized greater value through our ability to act as a trusted advisor in developing an end-to-end solution to meet their needs. We established a true partnership and stayed synchronized throughout strategic roadmap updates where we discussed our latest research and development and sought input and validation of HCL’s progress in meeting the future needs of the client and the industry.
The solution we architected and implemented to roll out a dynamic application security testing program added value in the following ways:
- Improved efficiency by allowing the client to scale up a large number of applications that needed to be tested and evaluated.
- Shifted Development left to run scans earlier and more frequently in the software development lifecycle (SDLC), which allowed our client to catch security vulnerabilities earlier. As a result, it reduced development costs.
- Enabled the capture of more metrics, which resulted in more informed business decisions.
About the company
The company offers broadband connectivity and high-speed fiber and wireless networks that connect people and businesses across the USA.
Related Capabilities
Business & Industry Applications
Robust business applications designed to set a new benchmark in organizational efficiency. Encompassing marketing, e-commerce, value chain, and behavioral insights.
Learn moreAI and Intelligent Operations
AI and automation combined with simplicity, security and ease of use — empowering you to make informed decisions, predict market trends and enhance agility and efficiency to an unprecedented degree.
Learn moreTotal Experience
TX software that interconnects the best to solve the most complex challenges organizations face, incorporating customer experience (CX), employee experience (EX), user experience (UX) and multi-experience (MX).
Learn moreData and Analytics
The tools you need to distill complex data into clear, actionable insights — to predict outcomes, profile customers, optimize operations and identify new opportunities through data patterns and market analysis.
Learn moreCybersecurity
Vulnerability detection, mitigation and remediation solutions that deliver secure DevOps and compliance from application to endpoint.
Learn more