Precision meets scale: How a global payments leader
unblocked their manual pentesters with Burp Suite DAST
Customer snapshot
-
Industry: Global financial services (payments).
-
Size: ~20,000+ employees worldwide. -
Region: Global (EMEA-led adoption). -
Environment : Highly regulated, mix of on-prem and cloud, Kubernetes deployments. -
Key compliance drivers : PCI DSS, global financial data security requirements.
The Company
The Challenge
The organization was already well-versed in static analysis (SAST), but these tools could not expose runtime issues such as missed APIs or authentication flaws in AngularJS-heavy applications. The leadership team wanted to move routine testing into automation, reducing the load on pentesters while ensuring that results would be trusted and actionable.
At the same time, they needed a deployment that would meet strict data privacy requirements, integrate into CI/CD pipelines, and scale from a handful of concurrent scans to hundreds.
The Solution
The rollout began in QA, where automated “observation scans” were introduced to give developers early feedback on their code without adding governance overhead. Higher-stakes “release scans” were still managed by the central security team, ensuring consistency and oversight.
To prepare for enterprise scale, the automation group deployed Burp Suite DAST on Kubernetes, adapting helm charts and database integrations to fit tightly with internal systems. They also built an internal wrapper so application owners could upload Postman collections and trigger scans themselves. This model allowed security teams to triage and prioritize results, while empowering developers to test on demand.
The Impact
Developers gained earlier insight through scans they could trigger independently, while the security team retained governance of critical releases. After the initial onboarding period, concurrent scans ramped up from around 100 to over 1,000. With confidence in their ROI, the organization is now preparing to run DAST at a scale that matches its existing static analysis tools.
The Future
Looking ahead, the organization also plans to align DAST with its enterprise AI strategy, using Burp AI to assist with triaging and escalation. With these steps, it is building a future in which automated runtime testing and deep manual expertise work hand in hand — reducing risk at scale without slowing innovation.