All case studies

Case Study: Increase AppSec Outcomes by 840%

The Challenge

Pearson's security team of 12 was completing just 44 security assessments annually across a global organization of 40,000 employees. Over 60% of the team's time was consumed by reports, metrics, and manual processes instead of actual security testing.

The Turning Point

Pearson adopted DevSecOps principles, producing an immediate breakthrough: 224 assessments in the first year, a 450% increase. But manual intake, fragmented tooling, and siloed results analysis were still bottlenecks.

The DefectDojo Implementation

Two years after their initial DevSecOps adoption, Pearson implemented DefectDojo as their security tools command center. The platform let them streamline intake and automate security testing queues through CI/CD, automatically send scan results to a centralized management layer, manage false positives and results analysis in one place, and maintain a single comprehensive view of their security metrics.

The Results

With DefectDojo in place, Pearson completed over 400 scans, a 100% year-over-year increase and over 840% from their pre-DevSecOps baseline of 44. Their scanning and ingestion processes became nearly fully automated, replacing the manual review that had consumed the majority of their team's capacity.

Most remarkably, this transformation happened while the team shrank. Today, a single application security engineer manages testing for Pearson's global operations across every country but two.