List of IBM Security AppScan Customers
Armonk, NY, 10504,
United States
Since 2010, our global team of researchers has been studying IBM Security AppScan customers around the world, aggregating massive amounts of data points that form the basis of our forecast assumptions and perhaps the rise and fall of certain vendors and their products on a quarterly basis.
Each quarter our research team identifies companies that have purchased IBM Security AppScan for Endpoint Detection and Response (EDR) from public (Press Releases, Customer References, Testimonials, Case Studies and Success Stories) and proprietary sources, including the customer size, industry, location, implementation status, partner involvement, LOB Key Stakeholders and related IT decision-makers contact details.
Companies using IBM Security AppScan for Endpoint Detection and Response (EDR) include: Lockheed Martin, a United States based Aerospace and Defense organisation with 121000 employees and revenues of $71.04 billion, New York Life, a United States based Insurance organisation with 13000 employees and revenues of $50.00 billion, Fiserv, a United States based Professional Services organisation with 38000 employees and revenues of $21.19 billion, HSBC USA, a United States based Banking and Financial Services organisation with 2040 employees and revenues of $3.86 billion, TD Auto Finance, a United States based Banking and Financial Services organisation with 2300 employees and revenues of $850.0 million and many others.
Contact us if you need a completed and verified list of companies using IBM Security AppScan, including the breakdown by industry (21 Verticals), Geography (Region, Country, State, City), Company Size (Revenue, Employees, Asset) and related IT Decision Makers, Key Stakeholders, business and technology executives responsible for the software purchases.
The IBM Security AppScan customer wins are being incorporated in our Enterprise Applications Buyer Insight and Technographics Customer Database which has over 100 data fields that detail company usage of software systems and their digital transformation initiatives. Apps Run The World wants to become your No. 1 technographic data source!
Apply Filters For Customers
| Logo | Customer | Industry | Empl. | Revenue | Country | Vendor | Application | Category | When | SI | Insight |
|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
Fiserv | Professional Services | 38000 | $21.2B | United States | IBM | IBM Security AppScan | Endpoint Detection and Response (EDR) | 2016 | Royal Cyber |
In 2016, Fiserv engaged Royal Cyber to implement IBM Security AppScan for security scanning of its credit-processing applications in the United States. The engagement focused on embedding IBM Security AppScan into Fiserv application-security processes for its financial-services environment, establishing regular vulnerability assessment of credit-processing application portfolios.
Royal Cyber configured IBM Security AppScan, referenced in the case study as IBM Rational AppScan, to perform automated application scanning and to generate prioritized security findings. Configuration work emphasized scan orchestration, scheduled assessments, and the creation of prioritized remediation reports, with the specific AppScan edition inferred from the implementation description.
The deployment was scoped to application-security and development teams supporting Fiserv credit-processing systems, with reporting directed to security operations and remediation owners. Fiserv used IBM Security AppScan as an Endpoint Detection and Response (EDR) aligned capability to strengthen application-security controls, producing prioritized remediation reports that informed triage and remediation workflows.
|
|
|
HSBC USA | Banking and Financial Services | 2040 | $3.9B | United States | IBM | IBM Security AppScan | Endpoint Detection and Response (EDR) | 2016 | n/a |
In 2016, HSBC USA integrated IBM Security AppScan into its Endpoint Detection and Response (EDR) controls to strengthen application security testing across the bank. HSBC Bank USA's Global Security Testing Team in Buffalo, NY used IBM Security AppScan alongside manual techniques to support deep-dive penetration testing of infrastructure and application assets and to meet quarterly PCI-DSS ASV assessment requirements for Asia Pacific and European networks.
IBM Security AppScan was configured to support dynamic application security testing workflows, complementing static testing and source code reviews to enable a combined DAST and SAST approach. The implementation covered automated scanning of web applications and REST APIs, and it was used in conjunction with manual validation processes to reduce false positives and to perform targeted security validation on high risk business critical applications.
The AppScan deployment was integrated into DevOps and CI CD pipelines to support a shift-left security strategy, enabling security testing automation within the bank's SDLC. Explicit integrations and toolchain touchpoints included API testing with Postman and trapped requests via Burp proxy, and linkage to defect and risk management systems such as Confluence, JIRA, Kenna, eGRC Archer, and the internally developed Comet system, plus coordination with Tenable IO and Security Center for broader security telemetry.
Governance for the IBM Security AppScan implementation included weekly risk review meetings with project teams to assess preproduction application design, apply OWASP Top 10 based baselines, and prioritize remediation of open defects. The program supported HSBC's quarterly PCI compliance and attestation activities, and it contributed to achieving PCI compliance and quarterly attestation for HSBC networks in China, Canada, Hong Kong, and the United Kingdom.
|
|
|
Lockheed Martin | Aerospace and Defense | 121000 | $71.0B | United States | IBM | IBM Security AppScan | Endpoint Detection and Response (EDR) | 2008 | n/a |
In 2008 Lockheed Martin implemented IBM Security AppScan as part of its application security tooling footprint, with deployments focused on defense and engineering application areas in the United States. IBM Security AppScan was employed in the Endpoint Detection and Response (EDR) category and is reported to incorporate Ounce Labs technology through AppScan Source after IBM's acquisition of Ounce Labs.
The implementation centered on static application security testing capabilities, specifically AppScan Source SAST modules derived from Ounce Labs, to perform source code analysis and vulnerability detection during development. Configuration work included rule set tuning, scanning profiles for codebases used in defense engineering, and scheduling of static analysis runs to catch security issues early in the software lifecycle.
Operationally the AppScan Source edition was integrated into software development and code review workflows used by engineering teams, providing automated scans of source artifacts and a centralized findings repository. Coverage emphasized application security for engineering projects, with scans scoped to project repositories and development sites in the United States.
Governance adjustments supported SAST adoption, introducing standardized triage workflows, issue classification and developer remediation processes to act on AppScan Source findings. The deployment established structured static testing practices within software development lifecycles, aligning security testing responsibilities across engineering and security operations teams.
|
|
|
New York Life | Insurance | 13000 | $50.0B | United States | IBM | IBM Security AppScan | Endpoint Detection and Response (EDR) | 2021 | n/a |
In 2021 New York Life implemented IBM Security AppScan as a core component of an enterprise Application Security program that tied application vulnerability testing into Endpoint Detection and Response (EDR) workflows. The deployment emphasized dynamic application security testing across development and production environments, aligning IBM Security AppScan with broader DAST, SAST, and IAST processes to surface OWASP Top 10 and SANS 25 findings for remediation.
The implementation configured IBM Security AppScan for automated DAST runs alongside static analysis tools such as Checkmarx and Veracode, and exercised IAST and RASP agents during penetration testing to validate runtime vulnerabilities. Functional capabilities implemented included automated scanning, triage reporting to SOC and leadership, integration into incident response playbooks, and coordination of vulnerability prioritization using CVSS scoring and enterprise risk frameworks.
Integrations explicitly included Checkmarx SaaS integrated with CI/CD pipelines in Jenkins, GitLab, and Azure DevOps for secure code scanning, and IBM Security AppScan used in conjunction with Burp Suite, HP Web Inspect, Nexpose, Nessus, Rapid7, Qualys, and Kenna Security for layered vulnerability assessment. Operational coverage spanned application development teams, SOC L1 and L2, incident response and threat hunting groups, and cloud and on-premises environments including AWS and Azure, with API Gateway and Web Access Management controls enforcing SSO, OAuth, and SAML where applicable.
Governance and process changes established enterprise reporting and alerting to meet SOC, client, and leadership requirements, improved SOC L1 and L2 process documentation, and formalized remediation workflows that tied SAST/DAST/IAST findings into ticketing and prioritization processes. The program also orchestrated endpoint hardening and EDR policy enforcement and conducted threat hunting using MITRE ATT&CK and UEBA informed by endpoint telemetry, reducing dwell time of malware and unauthorized access as part of the integrated security posture.
|
|
|
Spectrum | Communications | 1800 | $55M | United States | IBM | IBM Security AppScan | Endpoint Detection and Response (EDR) | 2023 | n/a |
In 2023, Spectrum deployed IBM Security AppScan as part of its Endpoint Detection and Response (EDR) tooling to centralize application and web vulnerability assessment and reporting. IBM Security AppScan was used by Spectrum security engineers to evaluate attack vectors, identify application and system vulnerabilities, and produce remediation plans for application teams and IT operations.
Spectrum configured IBM Security AppScan to run recurring web application vulnerability assessments, support threat modeling and secure code review workflows, and generate daily and weekly remediation reports. The team incorporated CWE and CVSS scoring practices and prioritized findings against the OWASP Top 10, using AppScan output to drive triage and remediation with development and operations teams.
The AppScan implementation operated alongside a multi-tool vulnerability ecosystem, explicitly integrating scan and reporting workflows with Nessus, InsightVM, Qualys, and Kenna for CVE correlation and vulnerability balancing. Scan engines were added to the production environment to scale coverage, and AppScan findings were routed into SOC monitoring and ticketing processes feeding IBM QRadar and Splunk SIEM correlation, IDS and IPS rule sets, and device configuration reviews.
Operational governance centered on a 24x7 SOC model and formalized collaboration with application owners, network and system administrators, and compliance stakeholders. Spectrum led kickoff and remediation coordination meetings, aligned AppScan findings to PCI DSS, NIST, SOC2 and ISO review activities, and maintained processes for incident response, patching coordination, and separation of network asset and interface scan data.
Outcomes from the IBM Security AppScan deployment included routine vulnerability reporting for network and application teams, documented remediation plans and faster triage, and SOC process improvements such as streamlined IPS event filtering and optimized IPS signatures to reduce false positives. AppScan functioned as a persistent application security sensor in Spectrum security operations, supporting continuous assessment and coordinated remediation across application security, network engineering, and SOC functions.
|
|
|
|
Banking and Financial Services | 2300 | $850M | United States | IBM | IBM Security AppScan | Endpoint Detection and Response (EDR) | 2017 | n/a |
|
|
|
|
Education | 3224 | $782M | United States | IBM | IBM Security AppScan | Endpoint Detection and Response (EDR) | 2010 | n/a |
|
Buyer Intent: Companies Evaluating IBM Security AppScan
- Samsung Electronics, a South Korea based Manufacturing organization with 262647 Employees
Discover Software Buyers actively Evaluating Enterprise Applications
| Logo | Company | Industry | Employees | Revenue | Country | Evaluated |
|---|---|---|---|---|---|---|
| Samsung Electronics | Manufacturing | 262647 | $203.5B | South Korea | 2026-03-16 |