Resources

BigID: From Friction to Partnership Between Security and Engineering

Case study: BigID, from friction to partnership

BigID builds a data security, privacy and compliance platform for large enterprises. Kyle Kurdziolek, VP of Security at BigID, oversees the company's entire security program. As BigID's codebase grew, open source vulnerabilities turned into a constant source of friction between his team and engineering. With Seal Security, BigID patches those vulnerabilities in the library versions it already runs, and the relationship has flipped: engineering now comes to security asking for Seal.

"Security's no longer nagging engineering. It's now engineering asking us, 'Hey, is this something Seal can do?'" - Kyle Kurdziolek, VP of Security, BigID

The challenge: too many vulnerabilities, and upgrades that break the product

Scanning was not the problem. Fixing was. Every new advisory added to a backlog that BigID could not clear through upgrades alone.

  • Volume: "When you're talking about open source vulnerabilities and libraries, the volume of vulnerabilities just come to a point where it's no longer manageable. You can't really scale that process."
  • Friction: "So that comes a lot of tension between security and engineering, trying to prioritize what vulnerabilities should be tackled first."
  • Risky upgrades: "If there's a high vulnerability that can't be upgraded because you're breaking your product, it becomes this whole problem of upgrade, do I not upgrade?" Working out what an upgrade breaks was, in Kyle's words, "super cumbersome," and it took up a lot of engineering time.
  • SLAs at risk: "When you deal with volume and scale, your SLAs become at risk for a lot of criticality, from critical, high, medium and even some lows."
"If I have a high vulnerability that I won't have a patch for until three or four months' time, therefore SLA is broken." - Kyle Kurdziolek

The solution: patch the version you already run

Seal Security backports the security fix into the exact open source library version BigID already uses, so the vulnerability is gone without a version upgrade or code changes. The patched libraries plug into BigID's existing CI/CD pipelines. Kyle compares it with the upgrade work his engineers used to do:

"We don't have to do that with Seal Security, where we can now patch that same library with that same version, vulnerability free, and deliver our products and our features at the same pace that we have been." - Kyle Kurdziolek

Onboarding was quick. "In the short amount of time of short two weeks, we're actually able to start seeing value from Seal Security," Kyle says.

The results

  • No more prioritization battles: "It's no longer battling prioritization. It's just a matter of: can Seal fix it? Yeah, absolutely."
  • Products ship at the same pace: fixes no longer wait on upgrade work, so feature delivery keeps its schedule.
  • Engineering time back: "We're giving engineers back time that they deserve to continue developing our product, introduce new features, and continue to make BigID a world class cybersecurity solution."
  • Stronger compliance: faster remediation helps BigID meet its SLAs and "better enhance the governance in your compliance program."
"I can maintain the same version of my library, but do it in a way that's vulnerability free." - Kyle Kurdziolek

More from Kyle Kurdziolek

See it on your own stack

Seal Security backports security fixes into the open source versions you already run, across application dependencies, containers and Linux distributions, with no upgrade required. Book a demo to see the CVEs in your backlog fixed.

See Seal on your stack

Get a walkthrough of how Seal backports security fixes into the open source versions you already run, with no upgrade and no code changes.

Book a demoChat with an expert