Case Study
Checkmarx One enabled Best Buy to secure one of the most challenging digital ecosystems in retail, reducing false positives by 80%, scanning billions of lines of code monthly, and empowering 3,000 engineers to release software at speed without compromising security.
Industry
Retail & Technology
Location
United States
Checkmarx Solutions & Services
Static Application Security Testing Software Composition Analysis CI/CD Integration Checkmarx OneCut false positives
by 80%
27,000 scans/month secured 2.1B LoC across thousands of CI/CD pipelines
Empowered 3,000+ engineers
across 300 teams
The Need
Best Buy’s application environment is massive, comprising:
“Our environment is deceptively large,” says Matthew Hurewitz, Director of Application Security, when addressing Best Buy’s complex security posture. “We support nearly every language and framework you can imagine” Mathhew explains further and adds jokingly -“Some of our applications are old enough to drink.”
To secure this scale and complexity, Best Buy needed a modern AppSec platform that could:
The Solution
Best Buy used Checkmarx One to centralize scanning, triage, and remediation across SAST, SCA, and CI/CD pipelines. With strong support from Checkmarx, the Best Buy team was able to:
The Results
Real-Time Risk Reduction and Streamlined Operations at Peak Enterprise Scale
Following its adoption of Checkmarx One, Best Buy cut false positives by 80%, secured 27,000 monthly scans across thousands of CI/CD pipelines, and empowered more than 3,000 engineers across 300 teams to release software quickly and securely.
These improvements streamlined vendor management, reduced technical debt, and gave leadership clear analytics to demonstrate ROI and prioritize risk with confidence.
“Who you do business with is ultimately about relationships. After many years of partnership, Checkmarx is deeply invested in our relationship. They really care about our ability to meet the needs of our engineering organizations and ultimately our customers.”
”Matthew Hurewitz
Director of Application Security
Industry
Retail & Technology
Location
United States
Checkmarx Solutions & Services
Static Application Security Testing Software Composition Analysis CI/CD Integration Checkmarx OneLooking for a deeper dive on Checkmarx security solutions?