Case Study

Continuous Pentesting at Scale: How BrightHR Transformed Developer Security with Cytix

From reactive, point-in-time testing to continuous developer-driven security at the pace of modern development

5 min

Case Study

Continuous Pentesting at Scale: How BrightHR Transformed Developer Security with Cytix

From reactive, point-in-time testing to continuous developer-driven security at the pace of modern development

5 min

Case Study

Continuous Pentesting at Scale: How BrightHR Transformed Developer Security with Cytix

From reactive, point-in-time testing to continuous developer-driven security at the pace of modern development

5 min

In this article

No headings found on page
No headings found on page

Join our newsletter

Receive the latest advancements, playbooks, and industry insights in software change security understanding.

Join our newsletter

Receive the latest advancements, playbooks, and industry insights in software change security understanding.

Overview

BrightHR is a fast-growing HR software operating within the Peninsula group. It faced increasing pressure to demonstrate robust application security, both internally and to customers. With frequent releases, high customer expectations, and no dedicated AppSec team, they needed a scalable, modern approach to security testing.

By adopting Cytix, they transformed their security posture from reactive and point-in-time testing to a continuous, developer-driven security model.

The Challenge

BrightHR's development team operated at high velocity, deploying multiple releases per day. This created a fundamental mismatch with traditional security practices.

Key Challenges

Point-in-time penetration testing was insufficient

Annual pentests provided only a snapshot of security at a single moment, yet were treated as valid for 12 months.

High demand for security assurance from customers

As the group's largest and most commercially critical product, the platform required frequent proof of security through accreditations and testing evidence.

Ineffective bug bounty approach

BrightHR invested over £100,000 in a bug bounty programme, but testing was not aligned to newly released features, findings lacked structure and accreditation (e.g. CREST), reports were not widely accepted by customers, and retesting was costly and inefficient.

Security lagging behind development

Vulnerabilities were often discovered after release, increasing risk and remediation costs.

Why Cytix

The team had been actively searching for a solution that could deliver continuous penetration testing, rather than static or purely automated scanning tools. Cytix stood out by offering:

  • Continuous, release-aligned testing

  • A combination of automated and human-led validation

  • Seamless integration into existing workflows

  • A model that matched how modern development teams actually operate

"It was exactly what we wanted… continuous pentesting for apps."

Aaron Paddison, Associate Director - Cyber Security at Peninsula Group

The Solution

Cytix was integrated directly into the development lifecycle, enabling security testing to happen as code is written and before it reaches production. Key elements of the implementation included:

  • Direct integration with development workflows (e.g. Jira)

  • Automated testing triggered by code changes

  • Human validation layered on top of automated findings

  • Continuous feedback loops to developers

This shifted security from a reactive function to a proactive, embedded process.

The Impact

1. Developer Engagement & Behaviour Change

One of the most significant outcomes was a cultural shift in how developers approached security.

  • Developers became active participants in security, not passive recipients of reports

  • Security feedback is now part of the daily workflow, not a post-release event

  • Developers think more critically about security before committing code

"It's actually changing how developers code and behave… security is now at the forefront of discussions."

Aaron Paddison, Associate Director - Cyber Security at Peninsula Group

2. Continuous Security & Reduced Risk

Cytix enabled the team to move from delayed, reactive testing to continuous assurance:

  • Every change is tested before release

  • Vulnerabilities are identified and fixed immediately

  • No reliance on periodic testing cycles

"Every change we commit is tested, checked and verified… there are no surprises."

Aaron Paddison, Associate Director - Cyber Security at Peninsula Group

This dramatically reduced the risk of vulnerabilities reaching production and eliminated the need for repeated, costly retesting.

3. Stronger Compliance & Customer Confidence

Customer conversations around security improved significantly.

Previously:

  • Security assurance relied on outdated pen test reports

  • Delays in testing and remediation created stress

  • Customers often questioned the validity of evidence

With Cytix:

  • BrightHR can demonstrate near real-time security posture

  • Responses to security questionnaires are clearer and more confident

  • Larger customers show increased interest and engagement

"It's a much nicer conversation… instead of saying our last test was months ago, we can show continuous testing."

Aaron Paddison, Associate Director - Cyber Security at Peninsula Group

4. Seamless Integration, Zero Operational Burden

Unlike previous solutions, Cytix required minimal overhead:

  • No need to manually submit applications for testing

  • No platform 'maintenance' or operational burden

  • Fully integrated into existing tools and processes

"It's slick, smooth, easy… there's no friction."

Aaron Paddison, Associate Director - Cyber Security at Peninsula Group

Security became part of the workflow, rather than an additional task.

5. Greater Confidence in Security Posture

Despite not having a dedicated AppSec team, BrightHR gained significantly more confidence in its security:

  • Consistent standards enforced across development

  • Clear governance through a central security architect

  • Assurance that code entering production has been properly validated

"I know the code is going to be secure… I've got a lot more confidence as a result of Cytix."

Aaron Paddison, Associate Director - Cyber Security at Peninsula Group

The Results

By adopting Cytix, the organisation achieved:

  • A shift from point-in-time to continuous security testing

  • Improved developer accountability and awareness

  • Reduced cost and inefficiency compared to bug bounty programmes

  • Stronger customer trust and compliance positioning

  • A scalable security model aligned with modern development practices

Top 3 Benefits

Developer engagement and behaviour change

"Developers are now consistently committing more secure code and actively engaging with security."

Simpler compliance and customer conversations

"Answering security questionnaires and due diligence is now much easier and clearer."

Strong, continuously validated security posture

"We have confidence that our most critical product maintains a high level of security at all times."

Get started

Get continuous pentesting at Scale

Eagle House, 64 Cross Street, Manchester, M2 4JQ, United Kingdom

© 2026 Cytix Ltd. All rights reserved.

Eagle House, 64 Cross Street, Manchester, M2 4JQ, United Kingdom

© 2026 Cytix Ltd. All rights reserved.

Eagle House, 64 Cross Street, Manchester, M2 4JQ, United Kingdom

© 2026 Cytix Ltd. All rights reserved.