Customers

Trade Republic

How Trade Republic facilitated Snyk adoption for application security

Customer Spotlight

Benjamin Igbeka

Security Engineering Lead

Industry: Finserv
Location: Germany

Highlights:

Improved visibility into vulnerabilities across the technology stack

Systems scanned by Snyk on a daily basis

90% lower average time to fix issues than the industry standard

Improved security posture of infrastructure and software supply chain

The Challenge: Implementing comprehensive vulnerability scanning

As a licensed bank, Trade Republic focuses on security and adequate application security measures. The company decided to implement Snyk to comprehensively scan for vulnerabilities across its code repositories and throughout its build pipelines.

“We were looking for automated scanning of our container images and infrastructure as code templates,” stated Benjamin Igbeka, Security Engineering Manager at Trade Republic Bank. “From the start, we integrated open-source dependency scanning properly into our development pipelines.”

The Solution: Adopting Snyk for centralized visibility

After evaluating numerous security tools and providers, Trade Republic decided to implement Snyk because the company wanted centralized visibility. Using multiple tools was too difficult to maintain and didn’t allow Trade Republic to easily track all the issues in Jira. Snyk, on the other hand, could immediately enable all developers and cover open source code, containers, and infrastructure configurations.

In addition, Trade Republic integrated Snyk scanning into the company’s overall vulnerability management process. This enabled the company to gain visibility into third-party or supply chain security risks, which is crucial for adhering to regulatory requirements.

Snyk’s developer-friendly approach facilitates adoption

Trade Republic has seen a very high developer usage rate for Snyk since its initial roll out because the platform provides numerous integration options. Development teams could easily run scans from the Snyk CLI or by using IDE plugins. Snyk can also give developers security recommendations within pull requests. Ease of integration, therefore, was crucial for scaling Snyk across the organization. Thereby, Trade Republic identifies security risks already during the development phase of its software.

“Snyk is one of our most comprehensive security testing tools,” Benjamin said. “It covers our open-source libraries, containers, and infrastructure as code. So far, we’ve seen a huge adoption of Snyk by the developers.”

In order to further facilitate this adoption, Trade Republic’s security team offered training sessions and resources to help developers adopt Snyk for different languages and technology stacks. After a few months, the process was mostly hands-off for the security team because developers had become skilled at integrating Snyk for new projects themselves.

Snyk’s developer-friendly approach also helps Trade Republic prioritize vulnerability remediation effectively. A risk-based approach – where only higher severity vulnerabilities block developers from pushing code to the development environment – enables development teams to develop rapidly while also improving application security.

"The ability to give developers context early on was crucial,” explained Benjamin. “I wanted to ensure developers could check for security issues while writing code before committing to Git and get actionable remediation advice.”

The Impact: Improving application security posture

Through the adoption of Snyk, Trade Republic has been able to ensure the protection of sensitive customer data and elevate the security posture of its software from day one.

Gaining visibility into potential vulnerabilities and having confidence that they weren’t false positives was a crucial first step. Then, the teams were able to address newly identified possible vulnerabilities as part of the day-to-day development process. In the end, these improvements have solidified the security of Trade Republic’s infrastructure, software supply chain, and applications.

"Our developers integrated Snyk in their pipelines because it provides fast analysis with fewer false positives, and the remediation advice is actionable, even for non-security folks," concluded Benjamin.

About Trade Republic

Trade Republic is on a mission to democratize wealth.  Trade Republic sets up millions of Europeans for wealth with fast, easy, and free access to capital markets.  With over one million customers, Trade Republic is one of the largest savings platforms in Europe.

Patch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo SegmentPatch Logo Segment

Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer’s toolkit.

Start freeBook a live demo

© 2024 Snyk Limited
Registered in England and Wales

logo-devseccon