Overview
Enhancing Security Through Automated Code Checking: A Case Study on Cisco Duo SecurityData Theorem |
Application Infrastructure & Middleware - Middleware, SDKs & Libraries Cybersecurity & Privacy - Application Security | |
National Security & Defense Telecommunications | |
Logistics & Transportation Product Research & Development | |
Tamper Detection Time Sensitive Networking | |
Operational Impact
The implementation of Data Theorem's solution has brought significant operational benefits to Duo. The automated scanning of Duo's mobile app both in pre- and post-production has ensured that any code issues are identified early, reducing the risk of app rejection by Google or Apple's stores. The alerts provided by Data Theorem have saved triage time and enabled Duo to manage issues proactively. The detailed notifications from Data Theorem have reduced the forensic research work required by Duo's developers, allowing them to focus on fixing vulnerabilities. Furthermore, the regular tips and updates on current state-of-the-art features provided by Data Theorem have helped Duo's developers stay up-to-date on new features, development cycles and enhancements. Overall, the solution has enhanced Duo's security, without slowing them down or consuming a lot of resources. | |
Quantitative Benefit
Data Theorem scans for critical (P1) security issues on a daily basis, allowing Duo to know about any showstoppers in its pre-production environment, but also knowledge about “zero-days” in the wild on production apps. | |
Data Theorem’s ability to scan 3rd party SDK & Open Source libraries allowed Duo to shed light on an attack surface that would otherwise be a blind spot. | |
Data Theorem was the only company that also offers “Secure Code” directly to developers to help fix identified security issues. This enables Data Theorem's customers to streamline the amount of time and resources required to fix an issue. | |