Case Study · Financial Services · Procurement Technology
Bedrock

Bedrock Procurement Solutions

Permission confirmed Penetration TestingCISO as a Service
Industry

Supplier management & procurement technology

Engagement

Manual + automated penetration testing, ongoing CISO advisory

Services

Penetration Testing, CISO as a Service

Background

Bedrock is a supplier management technology provider handling vendor and financial data for finance and procurement teams, with deep API connectivity into major ERP and procure-to-pay (P2P) systems and machine learning built in to reduce manual error.

Challenge

Bedrock's platform handles large volumes of sensitive vendor and financial data, where a breach would hit vendor confidence directly. The company started with automated penetration testing on a standard toolset, but the complexity of its ERP and P2P integrations went beyond what those scans could reach, and specific vulnerabilities were going unfound.

Scope of work

Cybecs combined automated detection tooling with comprehensive manual penetration testing to examine Bedrock's systems with the depth its API integrations required. Alongside the testing, Cybecs' CISO as a Service provided ongoing strategic guidance, feeding directly into how Bedrock refined its security strategy over time.

Outcome

Vulnerabilities that a standard automated scan had missed were identified and addressed, and Bedrock now maintains a security posture that matches the trust its vendor and client relationships depend on.

“Supplier management in this digital age goes beyond transactions; it's about trust and secure data-sharing. Our collaboration with Cybecs Professional Services has solidified our commitment to vendors, clients, and employees. Their tailored approach pinpointed and addressed our vulnerabilities. Now, Bedrock stands as both a leader in supplier management and a model for cybersecurity excellence.”

Osama Sabbah, Founder & CEO, Bedrock

Related

More case studies

Facing a similar challenge?

Let's talk about what a comparable engagement would look like for your organization.

Discuss a Similar Engagement →