How CEGID Made Validation Continuous Across 2,000+ Assets and 20+ Companies

Link copied!
Jorge Monteiro

Jorge Monteiro

CEOEthiack

January 24, 2024

CEGID is a Lyon-headquartered conglomerate of software companies operating across critical sectors handling deeply sensitive customer data. Listed on Euronext, it serves enterprises across Europe and beyond.

André leads SecOps for CEGID's infrastructure across Portugal, Spain, and Africa, covering more than twenty companies inside the group, each with its own products, teams, and exposure.

Why annual pentests stopped working

After five years running CEGID's offensive security programme, André reached a conclusion that has since become consensus across mature security teams: annual, checklist-based pentesting cannot defend a multi-company group whose products ship code every week.

He tried other approaches and ran into a familiar wall: false positives, often in the thousands. The signal-to-noise ratio was unworkable. Real exploitable risks got buried under flagged versions and theoretical issues.

He needed three things at once: full visibility across 20+ company surfaces, validation of what attackers could actually exploit, and a velocity that matched the product teams shipping into production.

Continuous AI pentesting plus elite human events, one platform

CEGID deployed Ethiack across the group. Hackian runs continuous, autonomous pentesting against more than 2,000 exposed assets, validating exploitability and surfacing prioritised risk to the security and product teams in real time. Ethiack's elite ethical hackers run in-depth events on the most critical assets, where human creativity uncovers the chained, business-logic attacks that automation alone can miss.

The numbers speak for themselves: under 0.5% false positives, real-time prioritisation across 20+ companies, and over €12M in prevented cybersecurity risk.

The way Ethiack incorporates EASM with Automated Pentesting has brought us simplicity and proactivity in solving large-scale problems. As a group with so many exposed assets, doing this work manually was simply impossible. The main transformation was the gaining a complete view on our surface, which we previously lacked. What we have publicly exposed, their vulnerabilities, and our impact in the cyberspace.

CEGID now runs an offensive security programme that scales with the group, not against it.

Operating across multiple companies and exposure surfaces? Start a 30-day trial →

Don’t wait for the attack.

Secure Your Future with Ethiack

Try Ethiack

If you're still unsure convince yourself with a 30-day free trial. No obligation. Just testing.

signup(datetime.now());

def hello(self): print("We are ethical hackers")

class Ethiack: def continuous_vulnerability_discovery(self: Ethiack): self.scan_attack_surface() self.report_all_findings() def proof_of_exploit_validation(self: Ethiack): self.simulate_attack() self.confirm_exploitability() self.validate_impact()

while time.time() < math.inf: ethiack.map_attack_surface() ethiack.discover_vulnerabilities() ethiack.validate_exploits() ethiack.generate_mitigations() ethiack.calculate_risk() ethiack.notify_users() log.success("✓ Iteration complete")

>>> show_testimonials() They found vulnerabilities no one else did. Fast, real, and actionable results. It's like having a red team on call. >>> check_socials()

signup(datetime.now()) meet(ethiack)

def actionable_mitigation_guidance(ethiack): ethiack.generate_mitigation_steps() ethiack.prioritize_fixes() ethiack.support_teams() def attack_surface_management(ethiack): while time.time() < math.inf: ethiack.map_attack_surface() ethiack.monitor_changes() def quantifiable_risk_reduction(ethiack): ethiack.check_risk_metrics() ethiack.calculate_delta() return ethiack.report_real_risk()

Activate AI penTesting

Start a Free 30-day trial
Ethiack — Autonomous Ethical Hacking for continuous security Continuous Attack Surface Management & Testing