List of PortSwigger Burp Suite Professional Customers
Knutsford, WA16 0PF,
United Kingdom
Since 2010, our global team of researchers has been studying PortSwigger Burp Suite Professional customers around the world, aggregating massive amounts of data points that form the basis of our forecast assumptions and perhaps the rise and fall of certain vendors and their products on a quarterly basis.
Each quarter our research team identifies companies that have purchased PortSwigger Burp Suite Professional for Application Security (AppSec) from public (Press Releases, Customer References, Testimonials, Case Studies and Success Stories) and proprietary sources, including the customer size, industry, location, implementation status, partner involvement, LOB Key Stakeholders and related IT decision-makers contact details.
Companies using PortSwigger Burp Suite Professional for Application Security (AppSec) include: Microsoft, a United States based Professional Services organisation with 228000 employees and revenues of $331.84 billion, New York Life, a United States based Insurance organisation with 13000 employees and revenues of $50.00 billion, Fairfax County Public Schools, a United States based Education organisation with 25625 employees and revenues of $3.90 billion, HSBC USA, a United States based Banking and Financial Services organisation with 2040 employees and revenues of $3.86 billion, CLA (CliftonLarsonAllen), a United States based Professional Services organisation with 8200 employees and revenues of $2.10 billion and many others.
Contact us if you need a completed and verified list of companies using PortSwigger Burp Suite Professional, including the breakdown by industry (21 Verticals), Geography (Region, Country, State, City), Company Size (Revenue, Employees, Asset) and related IT Decision Makers, Key Stakeholders, business and technology executives responsible for the software purchases.
The PortSwigger Burp Suite Professional customer wins are being incorporated in our Enterprise Applications Buyer Insight and Technographics Customer Database which has over 100 data fields that detail company usage of software systems and their digital transformation initiatives. Apps Run The World wants to become your No. 1 technographic data source!
Apply Filters For Customers
| Logo | Customer | Industry | Empl. | Revenue | Country | Vendor | Application | Category | When | SI | Insight |
|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
Accenture Czech Republic | Professional Services | 800 | $120M | Czech Republic | Portswigger | PortSwigger Burp Suite Professional | Application Security (AppSec) | 2018 | n/a |
In 2018, Accenture Czech Republic began using PortSwigger Burp Suite Professional for Application Security (AppSec) activities across its Cyber Fusion Center in Prague. The deployment positions PortSwigger Burp Suite Professional as a core tool for penetration testing, secure SDLC, and DevSecOps work across client engagements in the Czech Republic and the wider region.
PortSwigger Burp Suite Professional implementation emphasizes both automated and interactive testing capabilities, including out of band application security testing OAST and interactive application security testing IAST features described by the team. The configuration supports vulnerability discovery, exploit validation, and manual penetration testing workflows typical for Application Security (AppSec) operations, with the application used to orchestrate scanning, proof of concept development, and remediation verification.
Governance of usage is anchored in the Cyber Fusion Center, where Burp Suite feeds into secure SDLC and DevSecOps processes for client projects, enabling structured testing handoffs and remediation verification. The Accenture Czech Republic team credits Burp Suite Professional with finding harder to detect vulnerabilities and accelerating testing efficiency and remediation for their clients.
|
|
|
BDO Norge | Professional Services | 2000 | $500M | Norway | Portswigger | PortSwigger Burp Suite Professional | Application Security (AppSec) | 2020 | n/a |
In 2020, BDO Norge implemented PortSwigger Burp Suite Professional as its primary toolkit for manual web application penetration testing. The deployment targets red team and penetration testing workflows to support client engagements across financial services, public sector, and SMEs in Norway. PortSwigger Burp Suite Professional is applied within Application Security (AppSec) operations to standardize manual testing, vulnerability discovery, and exploit verification.
Functional capabilities exercised include proxy based intercept testing, scanner assisted manual workflows, repeater and intruder workflows for exploit development, and extension support consistent with Application Security (AppSec) toolsets. Operational scope centers on BDO Norge security consultants and red team practitioners delivering client facing penetration tests and security assurance reports. Governance changes focused on standardizing test methodology, evidence capture, and client reporting to embed research backed findings into engagements. The implementation has sped up penetration testing and enabled the red team to provide more efficient, research backed security assurance to clients.
|
|
|
CLA (CliftonLarsonAllen) | Professional Services | 8200 | $2.1B | United States | Portswigger | PortSwigger Burp Suite Professional | Application Security (AppSec) | 2020 | n/a |
In 2020 CliftonLarsonAllen implemented PortSwigger Burp Suite Professional as a core tool for web application assessment within its Application Security (AppSec) program. PortSwigger Burp Suite Professional was deployed to provide hands on web vulnerability discovery and dynamic application scanning capabilities as part of the broader vulnerability management initiative led by an Information Security Analyst.
Configuration centered on Burp Suite Professional standard functional modules, including the interception proxy, active scanner, and manual testing toolset to validate server and application exposures. The implementation was operated alongside existing vulnerability and endpoint tooling explicitly named in internal notes, including Tenable.sc, Tenable.io, Microsoft Defender for Endpoint, Kenna Security, and Veracode, to feed findings into a central triage and reporting workflow.
Operational scope focused on internally developed applications, with the security team triaging Burp Suite findings for remediation by infrastructure and application teams and communicating risk to management. The program introduced responsive vulnerability SLAs informed by Kenna Security risk reporting and formalized reporting breakdowns to improve visibility into web application security where no prior process for internally developed applications existed.
Governance and process changes included creation of new procedure documents, enforcement of security requirements as a liaison between IT projects and business stakeholders, and incorporation of Burp Suite outputs into incident response and vulnerability remediation workflows. The Information Security Analyst retained responsibility for triage, high level incident investigations, documentation of acceptance of risk with executive management, and hiring input for security roles tied to the Application Security (AppSec) function.
|
|
|
Fairfax County Public Schools | Education | 25625 | $3.9B | United States | Portswigger | PortSwigger Burp Suite Professional | Application Security (AppSec) | 2022 | n/a |
In 2022, Fairfax County Public Schools deployed PortSwigger Burp Suite Professional to strengthen its Application Security (AppSec) capabilities within the Office of Cybersecurity. The implementation centered on supporting the Threat and Vulnerability Management team, integrating interactive web application testing into existing vulnerability validation and remediation workflows.
PortSwigger Burp Suite Professional was configured to perform interactive validation of findings from automated scanners, and to support penetration testing and red team activities. The tool was used alongside automated scanning workflows to confirm exploitable web application vulnerabilities, feed validated findings into ticketing and remediation processes, and inform adjusted Common Vulnerability Scoring System scores based on asset priority.
The deployment operated within a broader toolchain that included Tenable Vulnerability Management, Cisco Vulnerability Management, Crowdstrike, Axonius, Randori, theHarvester, Recon-ng, EyeWitness, Nmap, Nikto, OWASP Zed Attack Proxy, Flashpoint, Echosec, and Microsoft Purview, reflecting an integrated approach to discovery, scanning, validation, and incident response. Processes were established to ingest scanner output into vulnerability management, set user permissions and reporting, and coordinate validation results with system owners for remediation engagement.
Governance changes included regular and ad hoc web application scans, formalized validation workflows using PortSwigger Burp Suite Professional, and engagement procedures for system owners to prioritize fixes. The broader Threat and Vulnerability Management program reported a reduction in tracked vulnerabilities from over 400,000 to approximately 200,000 in six months, illustrating the operational scale and cross-functional impact of Application Security (AppSec) tooling, scanning, validation, and governance across Fairfax County Public Schools.
|
|
|
HSBC USA | Banking and Financial Services | 2040 | $3.9B | United States | Portswigger | PortSwigger Burp Suite Professional | Application Security (AppSec) | 2016 | n/a |
In 2016, HSBC USA deployed PortSwigger Burp Suite Professional to strengthen its Application Security (AppSec) testing capabilities. HSBC USA PortSwigger Burp Suite Professional Application Security (AppSec) supported application security testing for the Global Security Testing Team and application development functions across the bank.
PortSwigger Burp Suite Professional was used as an intercepting proxy to trap and validate HTTP requests and as a core tool in both manual and automated DAST workflows. The implementation emphasized manual validation and automated scanning of web applications, thick clients, and REST APIs, and was operated alongside SAST practices to support a shift left Sec DevOps agenda. The team used Burp proxy captures with Postman to exercise and validate API vulnerabilities as part of functional testing.
The Burp Suite deployment coexisted with a portfolio of AppSec tooling that included IBM AppScan, Netsparker, Checkmarx, Tenable IO and Security Center, and integrated outputs into defect and risk management systems such as Confluence, JIRA, Kenna, eGRC Archer and an internal Comet system. Operational scope covered deep dive penetration testing on internal infrastructure and quarterly PCI DSS ASV assessments for 11 HSBC Asia Pacific and European countries including Hong Kong China and the United Kingdom, and included testing of external networks and ATMs where mandated by card schemes.
Governance and process workstreams were formalized through weekly meetings with project teams to review pre production application design documentation, perform likelihood analysis and risk rate defects discovered during testing. The security testing program collaborated with application development teams to provide mitigation recommendations aligned to OWASP Top 10 and internal security standards, and to integrate DAST and SAST into CI CD driven DevOps SDLC workflows.
The deployment of PortSwigger Burp Suite Professional served as a central manual and automated application security capability within HSBC USA Application Security (AppSec) practices, and supported achieving PCI compliance and quarterly attestation for HSBC China Canada Hong Kong and the United Kingdom networks.
|
|
|
|
Professional Services | 228000 | $331.8B | United States | Portswigger | PortSwigger Burp Suite Professional | Application Security (AppSec) | 2022 | n/a |
|
|
|
|
Insurance | 13000 | $50.0B | United States | Portswigger | PortSwigger Burp Suite Professional | Application Security (AppSec) | 2021 | n/a |
|
|
|
|
Aerospace and Defense | 4800 | $1.8B | United States | Portswigger | PortSwigger Burp Suite Professional | Application Security (AppSec) | 2022 | n/a |
|
|
|
|
Government | 988 | $240M | United States | Portswigger | PortSwigger Burp Suite Professional | Application Security (AppSec) | 2017 | n/a |
|
|
|
|
Government | 3000 | $489M | United States | Portswigger | PortSwigger Burp Suite Professional | Application Security (AppSec) | 2023 | n/a |
|
Buyer Intent: Companies Evaluating PortSwigger Burp Suite Professional
Discover Software Buyers actively Evaluating Enterprise Applications
| Logo | Company | Industry | Employees | Revenue | Country | Evaluated | ||
|---|---|---|---|---|---|---|---|---|
| No data found | ||||||||