In this article
Overview
BrightHR is a fast-growing HR software operating within the Peninsula group. It faced increasing pressure to demonstrate robust application security, both internally and to customers. With frequent releases, high customer expectations, and no dedicated AppSec team, they needed a scalable, modern approach to security testing.
By adopting Cytix, they transformed their security posture from reactive and point-in-time testing to a continuous, developer-driven security model.
The Challenge
BrightHR's development team operated at high velocity, deploying multiple releases per day. This created a fundamental mismatch with traditional security practices.
Key Challenges
Point-in-time penetration testing was insufficient
Annual pentests provided only a snapshot of security at a single moment, yet were treated as valid for 12 months.
High demand for security assurance from customers
As the group's largest and most commercially critical product, the platform required frequent proof of security through accreditations and testing evidence.
Ineffective bug bounty approach
BrightHR invested over £100,000 in a bug bounty programme, but testing was not aligned to newly released features, findings lacked structure and accreditation (e.g. CREST), reports were not widely accepted by customers, and retesting was costly and inefficient.
Security lagging behind development
Vulnerabilities were often discovered after release, increasing risk and remediation costs.
Why Cytix
The team had been actively searching for a solution that could deliver continuous penetration testing, rather than static or purely automated scanning tools. Cytix stood out by offering:
Continuous, release-aligned testing
A combination of automated and human-led validation
Seamless integration into existing workflows
A model that matched how modern development teams actually operate
"It was exactly what we wanted… continuous pentesting for apps."
Aaron Paddison, Associate Director - Cyber Security at Peninsula Group
The Solution
Cytix was integrated directly into the development lifecycle, enabling security testing to happen as code is written and before it reaches production. Key elements of the implementation included:
Direct integration with development workflows (e.g. Jira)
Automated testing triggered by code changes
Human validation layered on top of automated findings
Continuous feedback loops to developers
This shifted security from a reactive function to a proactive, embedded process.
The Impact
1. Developer Engagement & Behaviour Change
One of the most significant outcomes was a cultural shift in how developers approached security.
Developers became active participants in security, not passive recipients of reports
Security feedback is now part of the daily workflow, not a post-release event
Developers think more critically about security before committing code
"It's actually changing how developers code and behave… security is now at the forefront of discussions."
Aaron Paddison, Associate Director - Cyber Security at Peninsula Group
2. Continuous Security & Reduced Risk
Cytix enabled the team to move from delayed, reactive testing to continuous assurance:
Every change is tested before release
Vulnerabilities are identified and fixed immediately
No reliance on periodic testing cycles
"Every change we commit is tested, checked and verified… there are no surprises."
Aaron Paddison, Associate Director - Cyber Security at Peninsula Group
This dramatically reduced the risk of vulnerabilities reaching production and eliminated the need for repeated, costly retesting.
3. Stronger Compliance & Customer Confidence
Customer conversations around security improved significantly.
Previously:
Security assurance relied on outdated pen test reports
Delays in testing and remediation created stress
Customers often questioned the validity of evidence
With Cytix:
BrightHR can demonstrate near real-time security posture
Responses to security questionnaires are clearer and more confident
Larger customers show increased interest and engagement
"It's a much nicer conversation… instead of saying our last test was months ago, we can show continuous testing."
Aaron Paddison, Associate Director - Cyber Security at Peninsula Group
4. Seamless Integration, Zero Operational Burden
Unlike previous solutions, Cytix required minimal overhead:
No need to manually submit applications for testing
No platform 'maintenance' or operational burden
Fully integrated into existing tools and processes
"It's slick, smooth, easy… there's no friction."
Aaron Paddison, Associate Director - Cyber Security at Peninsula Group
Security became part of the workflow, rather than an additional task.
5. Greater Confidence in Security Posture
Despite not having a dedicated AppSec team, BrightHR gained significantly more confidence in its security:
Consistent standards enforced across development
Clear governance through a central security architect
Assurance that code entering production has been properly validated
"I know the code is going to be secure… I've got a lot more confidence as a result of Cytix."
Aaron Paddison, Associate Director - Cyber Security at Peninsula Group
The Results
By adopting Cytix, the organisation achieved:
A shift from point-in-time to continuous security testing
Improved developer accountability and awareness
Reduced cost and inefficiency compared to bug bounty programmes
Stronger customer trust and compliance positioning
A scalable security model aligned with modern development practices
Top 3 Benefits
Developer engagement and behaviour change
"Developers are now consistently committing more secure code and actively engaging with security."
Simpler compliance and customer conversations
"Answering security questionnaires and due diligence is now much easier and clearer."
Strong, continuously validated security posture
"We have confidence that our most critical product maintains a high level of security at all times."
Get started
Get continuous pentesting at Scale








