Ir para o conteúdo
  • +55 (11) 3375 0133
  • contato@nova8.com.br
Linkedin-in Facebook-square Instagram Youtube
  • EN-US
  • PT-BR
  • ES-MX
Nova8
  • #Nova8é10!
  • Portfólio

    Checkmarx

    Segurança de Aplicações (AppSec) de Ponta a Ponta​

    Cequence

    Proteção Contra Fraudes e Bots com Segurança de APIs​

    Snyk

    Segurança Dev-First para Desenvolvimento Seguro e Ágil

    IRONSCALES

    Antiphishing Inteligente com IA Adaptativa e Generativa​

    Upwind

    Segurança em Tempo Real para Ambientes em Nuvem e Containers

    CORO

    Cibersegurança Simples e Modular para Empresas Enxutas

    Inviciti

    Segurança web com detecção de vulnerabilidades

    Conheça o portfólio completo
  • Serviços

    VAD

    Única Distribuidora de Valor Agregado (VAD) de cibersegurança da América Latina citada no Gartner Market Guide

    Centro de Excelência Nova8 em Cibersegurança

    Acelere sua capacitação técnica e estratégica com o hub de inovação da Nova8.

    Consultoria Nova8 em Cibersegurança

    Estratégia, eficiência e proteção real para aplicações e dados críticos.

  • Cases
  • Blog & Materiais
Fale Conosco
Nova8
  • Home
  • Blog

Featured Client: Pismo Builds a Strong Security Culture

  • Nova8 Security Research Team
  • fevereiro 16, 2023
  • Cases, Materials

Since its founding in 2016, Pismo has quickly gained global recognition for driving innovation and improving the operational capacity of some of the largest banks and financial institutions, maintaining high standards of security and availability at the forefront of the digital banking and payment solutions it provides to the market.

The technology company, headquartered in Brazil and with offices in the United States and the United Kingdom, offers a comprehensive cloud-native platform for banking and payment processing via Amazon’s AWS cloud platform. Its solution provides APIs for clients’ web or mobile applications so they can leverage Pismo’s infrastructure as their operations back-end. Using Pismo, banks and financial technology companies can quickly bring secure payment solutions to market.

Since payment applications host a large amount of personal information, they must be demonstrably secure, and companies repeatedly choose Pismo because they take security very seriously.

In a recent effort to further ensure the security of its software, Pismo brought on Ubirajara Aguiar Jr. to build and lead the DevSecOps team. Aguiar immediately took control with a comprehensive view of systems development, assessing the state of application security (AppSec) in his organization and identifying potential areas of improvement.
His recommendations included the concept of ‘shifting security left’—considering security from the outset of the software development lifecycle (SDLC)—and seeking an AppSec vendor with a more comprehensive and scalable set of test types for this environment.
“We evaluated the top-rated AppSec vendors, and as a leader in the Gartner Magic Quadrant, Checkmarx was a strong contender in this area”, said Aguiar.

Banner Nova 8 Grande (900 × 200 px)

To narrow down the list of potential vendors, Pismo’s DevSecOps team presented a list of ‘must-have’ features. For starters, the chosen solution needed to support multiple development languages, offer bidirectional integration with bug tracking tools, create and close tickets automatically, and identify recurring false positives. The solution also needed to be developer-friendly, with the capability to integrate and automate existing developer tools and processes.

“We always think about our developers when looking for new tools”, explained Aguiar. “We wanted the transition to be smooth and transparent and did not want them to worry about handling tickets or managing cards. We specifically looked for tools that would make our developers’ work easier and more productive.”

Last but equally important, the tool needed to enable flexible policies to break the build if high- or medium-risk vulnerabilities were identified.

Checkmarx met this list of requirements and many others, becoming the clear winner in the comparison. The first Checkmarx solution Pismo invested in was Static Application Security Testing (SAST).

SAST is an enterprise-level application security testing solution that provides high-speed, fully automated, flexible, and accurate source code analysis to identify security flaws that could lead to vulnerabilities in the code. With the flexibility to perform full and incremental scans whenever necessary, Checkmarx SAST provides Pismo’s team with comprehensive and highly accurate reports that prioritize vulnerabilities by severity, guiding developers on what to fix first. Checkmarx SAST also supports a complete list of programming languages and frameworks.

Pismo also invested in Checkmarx Software Composition Analysis (SCA), which integrates with SAST. They use SCA in the cloud to provide extensive security coverage for open source and custom code. With Checkmarx SCA, Pismo is able to uncover vulnerabilities not only in third-party code their developers use directly but also vulnerabilities in any dependencies that third-party code might call.

Since implementing the tools, there has been a significant shift in Pismo’s security culture. “Developers have been actively using Checkmarx SAST and SCA.” As Aguiar highlights, it certainly helps that “the tools are so well integrated into our processes.”

Pismo already has policies in place for Checkmarx SAST. “The teams only fix issues considered low-risk, and Checkmarx prevents new high- or medium-risk issues from being incorporated into the code. It feels great to see this happening.”

The team is also working hard on the SCA strategy using Checkmarx. “We are now focused on evaluating vulnerabilities and assigning them to one of four classifications: one being the most critical and vulnerable; two being potentially vulnerable but lacking sufficient information; three using packages with reported vulnerabilities but not in vulnerable conditions; and four using outdated packages without vulnerabilities”, said Aguiar.

The risk reduction has been so impressive that Aguiar and his DevSecOps team have been able to show Pismo’s Information Security Head/CISO, Leonardo Carmona, and the company’s business executives the critical metrics and KPIs that indicate progress since the implementation of Checkmarx.
“We made a chart tracing risks and vulnerabilities, and initially there was a large number of high-risk issues. Now, each one is at the zero mark, as they have all been corrected”, concluded Aguiar. In summary, “the money we invested in Checkmarx was well spent.”

Pismo is excited to continue working with Checkmarx and keep their applications and clients permanently safe.

To learn more about the challenges and solutions that led to Pismo’s success, download the full case study by clicking here.

Want to understand how our solution works? Click here and request a Checkmarx demo

Navegue por solução

  • Segurança
  • Gestão de segurança
  • #cybersecurity
  • Notícias
  • Upwind
  • #cybercrime
  • Segurança na Nuvem
  • Cequence
  • Checkmarx
  • Containers

Navegue por solução

  • Snyk
  • Upwind
  • Cequence
  • Coro
  • Ironscales
  • Checkmarx

Segurança começa pelo Colaborador

Mantenha-se à frente das ameaças cibernéticas

Explore nossos materiais ricos em insights como e-books, whitepapers, artigos e conteúdos do blog para saber tudo sobre as tendências de cibersegurança.

Veja mais
OUTPUTFILMS-06854.jpg
  • abril 22, 2026
  • Ecossistema Nova8

Vision Cybersecurity lança marca com conversa sobre APIs, IA e risco real

A participação da Nova8 no lançamento da Vision Cybersecurity reforçou uma discussão cada vez mais relevante para o mercado: como proteger operações digitais modernas em um cenário cada vez mais dependente de APIs, bots e inteligência artificial.
Leia mais
Nova8 Snyk
  • abril 22, 2026
  • Soluções

Da descoberta ao controle: por que a segurança precisa evoluir na era da IA – Snyk

Na era da IA, a capacidade de descobrir vulnerabilidades cresceu rápido. O problema é que mais sinais não significam mais segurança. O que diferencia organizações maduras agora é a capacidade de transformar descoberta em contexto, priorização, remediação e governança real.
Leia mais
Nova8 Coro
  • abril 22, 2026
  • Coro

CORO: como reduzir a complexidade da operação de segurança sem perder cobertura

A CORO ajuda empresas a centralizar a operação de segurança, automatizar tarefas recorrentes e reduzir a sobrecarga gerada por ferramentas desconectadas. Neste artigo, mostramos onde a solução faz sentido, o que ela entrega na prática e como a Nova8 apoia uma adoção mais aderente ao cenário real.
Leia mais
Linkedin-in Facebook-square Instagram Youtube

Al. Rio Negro, 585 - Torre Jaçarí - 13º andar Conjunto 134 - Alphaville, Barueri - SP, 06454-000

  • +55 (11) 3375 0133
  • contato@nova8.com.br

Empresa

  • #Nova8é10!
  • Eventos
  • VAD
  • Centro de Excelência
  • Consultoria
  • Trabalhe conosco
  • Política de Privacidade
  • Código de Ética

Portfólio

  • Checkmarx
  • Upwind
  • Cequence
  • CORO
  • Snyk
  • IRONSCALES
  • Invicti
  • Bright
  • Riskified
  • MazeBolt
  • Mend
  • Solicite um orçamento

Conteúdo

  • Blog Nova8
  • Clientes e Cases
  • Materiais

Copyright © Nova 8 Cybersecurity - 2026 - Todos os direitos reservados

Desenvolvido por Tech4Biz

Pesquisar
Nova8
  • EN-US
  • PT-BR
  • ES-MX
  • #Nova8é10!
  • Sobre nós
  • Portfólio
  • Serviços
    • Consultoria em Cibersegurança
    • Centro de excelência
    • Distribuidora de Cibersegurança de Valor Agregado
  • Cases
  • Blog & Materiais
  • Fale Conosco
  • #Nova8é10!
  • Sobre nós
  • Portfólio
  • Serviços
    • Consultoria em Cibersegurança
    • Centro de excelência
    • Distribuidora de Cibersegurança de Valor Agregado
  • Cases
  • Blog & Materiais
  • Fale Conosco
  • +55 (11) 3375 0133
  • contato@nova8.com.br
Linkedin-in Facebook-square Instagram Youtube
Saiba mais
Pesquisar