Case Study: Enabling DevSecOps for LATAM’s Largest E-Commerce Company

See how senhasegura empowered LATAM’s largest e-commerce company to streamline their DevSecOps initiative, securing thousands of applications and AWS secret keys and improving security through access management and auditing.
I prefer to download this customer case to read it later.
Download
Icon Rounded Closed - BRIX Templates

The Situation

A DevOps pipeline (CI/CD) managing thousands of secret hard-coded keys and operating thousands of permanent and ephemeral cloud servers, supported by over 200 admin developers.Over 2,000 hardcoded access keys were used indiscriminately, lacking traceability for privileged access to cloud servers.

The Challenge

Shared secrets led to malicious actions without accountability, resulting in operational errors, data leakage, and service unavailability. These were made worse by uncontrolled access proliferation and inadequate security governance.

The Solution

Integrate senhasegura into the DevOps pipeline for scanning and rotating hardcoded access keys during deployment, along with the cloud providers to automatically identify ephemeral servers, manage credentials, and record sessions. senhasegura mapped 100% of applications and secret keys.

See how PAM Core works »

The Results

Implementing senhasegura enabled the e-commerce company to significantly accelerate its DevSecOps initiative, securing thousands of applications and AWS secret keys while enhancing security through access management and auditing.
100%
applications and AWS secret keys mapped.
40%
of AWS unnecessary users were deleted, reducing the attack surface and therefore the risks.
80%
admin access recorded and audited.

Details

Introduction

In the dynamic landscape of Latin America's e-commerce sector, one company emerged as the leader, driving digital innovation across its diverse portfolio of brands, including Americanas.com, Submarino, and Shoptime. This retail giant faced a critical challenge in managing its extensive DevOps infrastructure. With over 200 admin developers overseeing a complex CI/CD pipeline managing thousands of permanent and ephemeral cloud servers, and burdened by 2,000 indiscriminately used hardcoded access keys, the company grappled with significant security vulnerabilities and compliance risks.
Major Challenges with Security and Compliance

The sprawling DevOps pipeline posed challenges beyond operational efficiency. Shared secrets and uncontrolled access practices led to operational errors, data leakage, and service disruptions. A lack of traceability and governance over privileged access to critical cloud servers compounded these issues, threatening the company's reputation and regulatory compliance.
The team faced immense pressure as the DevOps pipeline continued to grow.

Transformative Solutions with senhasegura

Recognizing the urgency to enhance its security posture and meet stringent compliance standards, the company embarked on a transformative journey. They integrated senhasegura into their DevOps pipeline strategy, harnessing the power of GitLab and Kubernetes for robust scanning and rotation of hardcoded access keys during deployments. Moreover, with seamless integrations with AWS and GCP, they automated the identification of ephemeral servers and implemented secure credential management through AD authorization. This strategic implementation ensured the comprehensive mapping of applications and secret keys across their infrastructure.


Witnessing the Transformation

The outcomes were profound and far-reaching. By adopting senhasegura, the company accelerated its DevSecOps initiative, achieving measurable improvements in security and operational efficiency. A notable 40% reduction in unnecessary AWS users streamlined their attack surface, while the comprehensive auditing of 80% of admin access bolstered accountability and compliance efforts. This strategic overhaul not only fortified their security but also laid a resilient foundation for future growth and innovation in the fiercely competitive e-commerce market of Latin America.
Moving DevSecOps forward fast bolstered the company's security.
Conclusion

In conclusion, the integration of senhasegura into their DevOps ecosystem exemplifies the company's commitment to digital transformation and operational excellence. By addressing critical security challenges head-on and implementing robust compliance measures, the company not only safeguarded its operations but also positioned itself for sustained success in an ever-evolving digital landscape. This case study underscores the transformative impact of proactive security measures and strategic technology partnerships in driving business resilience and growth.

Explore more from senhasegura

senhasegura DevOps Secrets Manager
A secure and efficient way for tools and applications to request confidential information such as secrets, credentials, and other sensitive data used throughout the DevOps lifecycle.
Product Tour »
senhasegura Endpoint Manager
Manage and monitor privileged sessions on workstations, ensuring secure access control, auditing, and compliance with IT security policies and regulations.
Product Tour »
senhasegura Certificate Manager
Centralize, manage, and automate the lifecycle of digital certificates, ensuring compliance and reducing operational risks.
Product Tour »

Get a VIP experience

Discover the value senhasegura can bring to your organization by streamlining your access and identity management while lowering costs.
Book a demo to:

See how our PAM solution can be customized to address your unique security challenges. 

Explore the multitude of features and functionalities within our all-in-one platform in depth.

Discover the tangible benefits and immediate ROI that come with our cutting-edge processes.