Checkmarx | Top 20 DevOps Solution Company - 2017
Checkmarx: Proactive Threat Protection
CIOReview
  • About Us
About UsConferencePartner With Us
  • Technology
      1. ARTIFICIAL INTELLIGENCE
      2. AUDIOVISUAL
      3. BLOCKCHAIN
      4. BUSINESS INTELLIGENCE
      5. CLOUD
      6. DATA ANALYTICS
      7. DEVOPS
      8. DIGITAL TRANSFORMATION
      9. DIGITAL TWIN
      10. LOW CODE NO CODE PLATFORM
      11. NETWORKING
      12. ROBOTIC PROCESS AUTOMATION
      13. SECURITY
  • Industry
      1. CONTACT CENTER
      2. EDUCATION
      3. HEALTHCARE
      4. LEGAL
      5. MANUFACTURING
      6. PUBLIC SECTOR
      7. RETAIL
      8. TELECOM
      9. TRAVEL & HOSPITALITY
  • Solutions
      1. ASSET MANAGEMENT
      2. CUSTOMER EXPERIENCE MANAGEMENT
      3. CYBER SECURITY
      4. DATA CENTER
      5. DOCUMENT MANAGEMENT
      6. ELECTRONIC DATA INTERCHANGE
      7. ENTERPRISE DATA MANAGEMENT
      8. ENTERPRISE RESOURCE PLANNING
      9. ENTERPRISE RISK MANAGEMENT
      10. ENTERPRISE-GRADE WEB DATA SOLUTIONS
      11. FACILITY MANAGEMENT
      12. FIELD SERVICE
      13. IDENTITY AND ACCESS MANAGEMENT
      14. INFRASTRUCTURE
      15. IT SERVICE MANAGEMENT
      16. MANAGED IT SERVICES
      17. PAYMENT AND CARD
      18. PROJECT MANAGEMENT
      19. SOFTWARE TESTING
      20. STORAGE
      21. VIDEO SOLUTIONS
      22. WORKFLOW
  • Platforms
      1. ACUMATICA
      2. AMAZON
      3. IBM
      4. MICROSOFT
      5. ODOO
      6. ORACLE
      7. SAGE
      8. SAP
      9. SERVICENOW
      10. WORKDAY
  • Functions
      1. COMPLIANCE
      2. CONTRACT MANAGEMENT
      3. LOGISTICS
      4. PROCUREMENT
      5. SALES AND MARKETING
      6. SUPPLY CHAIN
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • Magazines
  • News
  • CXO Awards
Menu
  • US
    • US
    • APAC
    • LATAM
    • CANADA
    • EUROPE
CIOREVIEW >> DevOps >> Checkmarx

Checkmarx has been recognized by CIOReview Magazine as the recipient of “Top 20 DevOps Solution Companies - 2017,” based on our proprietary methodology, reflecting its position in the industry. This profile has been developed by the CIOReview research and editorial team based on insights from an interview with Emmanuel Benzaquen, CEO.

Checkmarx
Proactive Threat Protection

Checkmarx

Emmanuel Benzaquen, CEO
Today’s cyber landscape leaves no room for mistakes when it comes to the security of software and applications. Enterprises are well aware of the harsh consequences of a cyberattack. Moreover, with end users expecting software vendors to deliver cutting edge software at the speed of light, enterprises find themselves constantly juggling between quick releases and secure releases. “The current approach toward fixing security vulnerabilities at the end of the software development lifecycle creates a recurring cycle of delivery delays,” states Emmanuel Benzaquen, Checkmarx’s CEO. In light of this, Checkmarx is reshaping the ways of application security testing by tapping into the DevOps cycle as early as where developers are coding, making security a seamless and effortless component of the process. “We believe the sooner security vulnerabilities are fixed, the faster the application delivery will be,” he adds.

Implementing safety measures in earlier stages allows developers to continue coding while addressing security risks within their regular work environment. This enhances secure software delivery by preventing late detection which might impact the release schedule. “We drive the idea of ‘shifting left’ with security, meaning that security should be implemented as early as possible within the SDLC.” To foster fast turnarounds in DevOps, Checkmarx has developed CxSAST, a unique source code analysis solution that provides means for identifying, tracking, educating and remediating technical and logical flaws in the source code. With CxSAST’s incremental scan capability, scanning times are reduced to minutes rather than hours or days. Checkmarx offers a complete set of application security testing solutions providing developers with the ability to scan-as-they-go and automatically finding the best-fix locations within the source code, and later incrementally scanning only newly added code. “We ensure that we fit into the client’s DevOps process, making security seamless and fast paced.”

Integrated within CxSAST is Checkmarx’s AppSec Coach that provides developers the critical knowledge they need, when they need it most.

We believe the sooner security vulnerabilities are fixed, the faster the application delivery will be


This is done by providing on-the-spot, interactive, and easy educational models to ensure developers are well trained on what they need and when to use it, without interrupting their daily work routine. Under the same platform, Checkmarx also delivers open source software analysis to validate license regulations and ensure vulnerable open source components do not expose the application to additional risks. Numerous large enterprises including Fortune 500 companies working with Checkmarx have successfully delivered secure software without compromising on time-to-market.

Checkmarx also offers a range of developer friendly solutions to make security an integral part of coding. Among the application security solutions Checkmarx offers, its Best Fix Location algorithm helps developers with code remediation. “Best Fix Location aggregates multiple issues into unique spaces in the code and facilitates vulnerabilities to be patched at a single point,” says Benzaquen. Checkmarx builds a code flow structure which can then be presented in a graphical manner, showing developers the right point to fix vulnerabilities to save their time and effort.

Benzaquen asserts, “At the end of the day, even the best security software in the world isn’t going to protect you from attacks if it’s sitting on a shelf collecting dust.” An absolute must for the right application security testing system is developer adoption, which is Checkmarx’s biggest strength. The company continues to vest its focus on shifting application security testing to the left within the SDLC—as far left as back to the coding stage. “Checkmarx leads the shift security left movement as it is the only way to align the software world’s intense need for speed along with the necessary and critical application security requirements,” he concludes.

Checkmarx

News

Checkmarx Wins 2023 DEVIES Award in DevSecOps Category

Friday, February 17, 2023

Checkmarx One™ Application Security Platform recognized for outstanding design, engineering and innovation in developer technology

ATLANTA and RAMAT GAN, Israel -
Checkmarx, announce that the Checkmarx One™ Platform has received a 2023 DEVIES Award in the DevSecOps category. The 11th annual DEVIES Awards are the definitive annual awards for the software industry recognizing outstanding design, engineering, and innovation in developer technology across 31 categories.

"Developer tools and technology product solutions are leading the way for software developers & engineers to build upon the foundation of the ever-expanding technology sector. Checkmarx's win is evidence of their leading role in the growth and innovation in the software industry," said Jonathan Pasky, Executive Producer of DevNetwork, producer of DeveloperWeek and the 2023 DEVIES Awards.

Award winners were selected from a record-high 310 nominations by an expert-led panel of the DevNetwork Advisory Board, based on the following criteria: 1) attracting notable attention and awareness in the software industry; 2) general regard and use by the developer, engineering and IT communities; and 3) being a technical leader in its sector for innovation.

"As we work to help our customers shift everywhere, Checkmarx is honored to be recognized as the DevSecOps category winner in the 2023 DEVIES Awards," said Ori Bendet, VP of Product Management at Checkmarx. "Developers are at the heart of every organization's application security efforts, and it is therefore critical for Checkmarx One to be integrated in a completely frictionless way into their ecosystem."

Checkmarx Releases Version 3.0 of AI-Powered Checkmarx One™ Enterprise AppSec Platform

Monday, October 16, 2023

Industry’s most complete, cloud-based enterprise AppSec solution leverages groundbreaking AI technology, streamlines end-to-end developer experience and expands Supply Chain Security capabilities

ATLANTA, GA –
Checkmarx, the industry leader in cloud-native application security for the enterprise, today released version 3.0 of its AI-powered Checkmarx One™ enterprise AppSec platform. Purpose-built for enterprise cloud development, Checkmarx One 3.0 dramatically improves the end-to-end developer experience while expanding the AI-driven security capabilities of the platform’s CheckAI Plug-in, its reporting and analytics capabilities and its Supply Chain Security solution.

“Checkmarx One is the AI-driven AppSec platform for today and for the future. Enterprise CISOs now see the strength of their application security as critical to their overall security postures,” said Sandeep Johri, CEO at Checkmarx. “Leveraging the power of AI to protect the most complex enterprise applications is critical. Yet it’s also important to ensure that the platform is easy and rewarding for developers to use and offers the most robust defense possible against software supply chain attacks.”

Checkmarx One Version 3.0 now offers:

• AI-Powered Application Security: The CheckAI Plugin for ChatGPT is joined by AI Query Builder for SAST, AI Query Builder for Infrastructure-as-Code (IaC) Security, and AI Security Champion to both secure changing developer workflows and make AppSec easier for overburdened enterprise AppSec teams.

• Seamless Developer Experience: Checkmarx One integrates easily into the most popular integrated development environments (IDEs) and feedback tools to increase adoption and help teams find and fix vulnerabilities swiftly. New features such as the presentation of the attack vector, linked directly to the line of code within the developer IDE, save substantial time for developers.

• Expanded Supply Chain Security Capabilities: In addition to the detection of malicious packages and the Checkmarx Supply Chain Threat Intelligence feed, Checkmarx One now includes a Secrets Detection Engine and Project Scorecard.

• Advanced API Security: Checkmarx One offers the industry’s most complete API Security solution, automating the discovery and testing of an organization’s shadow APIs and expanding from pre-production to runtime.

• Consolidated, Simplified AppSec: Through integration of runtime insights from Sysdig as well as App Risk Management, Checkmarx One now consolidates vulnerabilities, risk ratings and prioritization guidance across an organization’s entire application portfolio. One comprehensive dashboard helps direct developers toward the riskiest application vulnerabilities first.

• Advanced Reporting and Analytics: An all-new reporting module elevates risk comprehension through sharper insights and drill-down analytics.

Checkmarx One links the attack vector directly to the line of source code, showing developers the data coming into an application all the way to the sink.

“Checkmarx One offers tremendous and measurable benefits for our customers, improving both application security and developer experience for a more seamless AppSec experience and faster time-to-market,” said Amit Daniel, Chief Marketing Officer at Checkmarx. “One Fortune 500 customer customized their AppSec solution, strengthened their AppSec skills with secure code training and created a security champions program to build a bridge between development and AppSec teams. All of this resulted in a 1600x increase in the number of vulnerabilities remediated for a significant boost to enterprise security.”


Our vision: Securing the entire software supply chain

Monday, October 30, 2023

The use of open-source software has quickly exposed all parts of the software development process as part of the overall attack surface, and has even lead to the creation of new attack types.

Organizations must take steps at every stage of the software supply chain to ensure developers’ environments. Enterprises must also make sure processes and secured, so you aren’t leaving your business vulnerable to next-generation SCS attacks, like AI package hallucinations, dependency confusion, typosquatting, and repojacking.

Let’s dive into a brief history of how “supply chain security” has evolved to the point we are today, what organizations must consider when securing their software supply chain, and how
Checkmarx is proactively building new solutions to address this complex and ongoing issue.

Our mission to secure the entire software supply chain

For the past 10 years, security professionals have been trained that before you release code, all high vulnerabilities need to be identified and fixed. But over the last few years especially, the world has changed. According to GitHub, open source is now the foundation of more than 90% of the world’s software. Organizations are now facing a shifting attack landscape, along with an overwhelming number of vulnerabilities. The attack landscape is moving from the application itself, to where there are new vulnerabilities and weaknesses – in the process surrounding your development, and the components you use to build your application.

What software supply chain security really means

Traditionally, supply chain security was to a way to gain visibility and mitigate 3rd-party code vulnerabilities through SCA. But as time went on and as new attack types emerged. In a 2021 executive order, software bill of materials, or SBOMs, are required for all software sold to the US federal government. The mandate underscores the importance of an accurate list of all open-source software ingredients found in a software-based product. The market quickly realized that the scope of software supply chain attacks, and how we prevent these attacks, go way beyond SBOMs and malicious packages.

Supply chain security is defined as a specific aspect of application security that focuses on protecting the software development process and the components used in that process. Software supply chain security is not a single solution; it is a discipline.

Supporting the SLSA Framework

The Supply-chain Levels for Software Artifacts (SLSA) framework, developed in collaboration with the OpenSSF and Google, addresses the growing concern of software supply chain security, offering a structured approach to assessing and improving the integrity of software components used in development.

SLSA introduces key concepts like artifacts, provenance, digests, immutable references, and build integrity, that provide a systematic way for the software industry to secure the development lifecycle and promote consistent security standards.

Understanding that the full scope of SCS is beyond a single tool, Checkmarx has implemented a broader strategy to cover things outside of your typical application security posture management, in full alignment with the SLSA framework.

How Checkmarx is helping you secure your software supply chain

Today, Checkmarx is providing expert guidance and proven solutions to manage open-source risk, along with new and exciting solutions to start protecting your entire supply chain today.

In the last few years, one of the biggest emerging threats have been malicious packages – notably different from vulnerable packages. In the SLSA framework, malicious packages are a form of dependency attack where attackers inject or contribute malicious code into open-source projects that your developers download and build into your applications. Once downloaded, the attacker's malicious code is running within your applications, with whatever unknown intent the package carries.

Checkmarx SCA, introduced in 2021, was a major step in helping organizations identify and start reporting on their open-source vulnerabilities. We were the first vendor to include malicious package detection inside our SCA solution. Since then, our research team has inspected over 7.6 million open-source packages for all kinds of threats, finding 200,000+ malicious packages. We make that threat intelligence available to you, either in our SCA product, where findings are in the portal or directly in developers’ IDE, or through an API-based threat intelligence feed.

Checkmarx SCA enables automated SBOM generation, and Checkmarx Container Security, which works with Checkmarx SCA, identifies vulnerabilities in open-source packages included in container images. Together with our partners at Sysdig, we recently announced runtime insights, so organizations can get the full picture of pre-production and deployment, gaining visibility into which container images are in-use and prioritize the ones that pose the most risk.

We realized customers need support in prioritization, especially with all these newly discovered vulnerabilities, so we released Exploitable Path. It’s a unique feature that allows our customers to prioritize vulnerabilities in open-source libraries.

When you look at the SLSA framework, we also have always led the way in terms of identifying Infrastructure-as-Code (IaC) misconfigurations. We are the driving force behind the most downloaded open-source tool in this area – Keep Infrastructure as Code Secure, or KICS for short.

All of these are important tools in managing open-source risk, but we are not stopping there.

Since GenAI is becoming a popular resource for developers to generate code, a variety of new SCS attacks have recently emerged, such as:

• AI hallucinations: These are false data points or patterns that AI models might "perceive" due to adversarial inputs or misinterpretations, which can be exploited by malicious actors.

• Prompt injections: Threat actors can manipulate AI models by introducing or “injecting” specially crafted prompts, tricking the system into undesired behaviors or outputs.

• AI secret leakage: There's a potential risk of AI models inadvertently revealing confidential information they were trained on, offering a goldmine for cybercriminals.

In August, Checkmarx introduced the industry’s first plugin to detect and prevent attacks against ChatGPT-generated code. The plugin enables developers to easily scan their ChatGPT-generated code for vulnerabilities within the ChatGPT interface, receive instant feedback on potential vulnerabilities or validation of open-source packages, and employ protection against malicious open-source packages.

Now, we’re leading the way again, and broaden the definition of software supply chain security, beyond just malicious packages, to every component in, and every tool used to build your applications. As part of the Checkmarx One 3.0 launch, we’re taking it one step further, introducing two new capabilities –Secrets Detection and Project Scorecard.

Prevent secrets from leaking on external tools with Secrets Detection

Secrets, such as passwords, API keys, cryptographic keys, and other confidential data, are a frequent target of a distributed supply-chain attack.

Secrets can easily be mistakenly shared on external tools like slack, confluence, twitch, and documentation pages.

Secret detection isn’t new – we have one of the most popular open-source tools for secret detection. 2MS from Checkmarx has over 2 million downloads, and anyone can get started today by detecting secrets such as login credentials, API keys, SSH keys and more hidden in code, content systems, chat applications and more.

If you are a Checkmarx One user, Secret Detection is now available directly in the Checkmarx One platform.

Tackle the most vulnerable projects first with Project Scorecard

One of the latest additions to the Checkmarx Supply Chain Security portfolio is Project Scorecard, which enables organizations to check their own projects quickly and see the most vulnerable or at-risk projects, allowing enterprises to prioritize which to tackle first.

Project Scorecard leverages the format from a popular tool, the OSSF Scorecard, which assesses open-source projects for security risks through a series of automated checks.

These checks cover different parts of the software supply chain including source code, build, and dependencies, and assigns each check a score of 1-10. An auto-generated “security score” helps users as they decide the trust, risk, and security posture for their specific application.

While an important tool in combating the uptick of open-source software attacks, open-source projects are only a portion of the projects in your application. Checking the process and components of owned projects is an important element in securing the total software supply chain.

With Project Scorecard, users can auto-generate a security score for their own projects based on a series of checks, including:

• Binary Artifacts – Is the project free of checked-in binaries?

o Branch Protection – Does the project use branch protection?

o CI Tests – Does the project run tests in CI, e.g., GitHub Actions, Prow?

o Code review – Does the project practice code review before code is merged?

o Dangerous workflow – Does the project avoid dangerous coding patterns?

o Vulnerabilities – Does the project have unfixed vulnerabilities?

By utilizing the Project Scorecard, as part of the Checkmarx Supply Chain module, we allow enterprises to quickly see the most vulnerable or at-risk projects, and ultimately help prioritize which to tackle first.

Taking the next step to secure your software supply chain

It’s important to take steps to secure your software supply chain today; detecting supply chain attacks in code packages, securing your developer’s evolving workstations supports rapid development while reducing risk.

Current Checkmarx One or Checkmarx SCA customers will have access to all these tools within the platform.

If you’re not already a Checkmarx One customer, you can start securing your software supply chain today with too many secrets (2MS), available as an open-source project on GitHub.

We’re incredibly excited to announce these new features to help you secure your software supply chain, but we’re only getting started. The work of securing the software supply chain is never done, as bad actors identify innovative new ways to capitalize on gaps in process and components, so stay tuned for more exciting announcements.

If you’d like to learn more register now to join us for our technical deep dive webinar on Nov 6th, “Secure your software supply chain”.


Checkmarx and DXC Technology Team Up to Deliver Scalable, Holistic Application Security Worldwide

Friday, June 21, 2024

Enhanced collaboration will reduce risk, improve software quality and accelerate digital transformation and cloud migration for global enterprises

PARAMUS, N.J:
Checkmarx, the industry leader in cloud-native application security for the enterprise, is stepping up collaboration with DXC Technology (NYSE: DXC), a leading Fortune 500 global technology services company, to offer robust and fully scalable application security (AppSec) programs and services around the world. DXC Technology will now sell and support the Checkmarx One™ application security platform at its customer sites to enable enterprise-grade, comprehensive protection across the software development life cycle and help them find and fix software vulnerabilities faster.

Together, Checkmarx and DXC Technology have over 5000 experts and a vast ecosystem of partners to design, build, deliver and support holistic application security programs to:

• Protect all applications and application footprints on a single platform that covers the entire software development life cycle (SDLC), from code to cloud

• Reduce cost and risk while improving customer outcomes

• Help organizations take applications to market faster

• Tailor and customize services to match each customer’s needs

“DXC and Checkmarx have built a powerful relationship to significantly reduce risk and ensure faster innovation for enterprise organizations around the world,” said Yigal Elstein, Chief Revenue Officer at Checkmarx. “The enterprise has a critical need to speed and scale business-critical projects without compromising application security, including digital transformation and cloud migration. Checkmarx and DXC deliver a real solution through Checkmarx One with DXC’s global reach that enables alignment of processes, tools and methodologies across regions and business units.”

Remarked Roger Smith, Global Testing and Digital Assurance Practice Leader at DXC, “I’m excited about the new partnership with Checkmarx and the advanced capabilities of the Checkmarx One platform as an integral part of DXC Application Security on Demand services to proactively integrate security into the development lifecycle through developer-friendly features that accelerate speed to value.“

In addition to selling and supporting Checkmarx One, DXC will provide the following services:

• Application security strategy and consulting

• Comprehensive application threat analysis

• Project-level optimization to ensure high-fidelity results and priority-based remediation

• Query customization, triage and remediation

• Static, dynamic, API, IaC security testing

• Open-source software composition analysis

• Migration to Checkmarx One

Purpose-built for enterprise cloud development, Checkmarx One is a highly scalable platform that addresses the need to close application security gaps while speeding time to delivery. The platform integrates into any workflow or tool, delivering security with the speed, scale and flexibility to support the latest development requirements, seamlessly working with all modern frameworks and development infrastructures through webhook integrations, a standard set of APIs or command-line interface. Checkmarx One dramatically improves the end-to-end developer experience of AppSec while expanding the AI-driven security capabilities across the platform, its reporting and analytics capabilities and its software Supply Chain Security solution.


Top 20 DevOps Solution Companies - 2017

Company
Checkmarx

Headquarters
Atlanta, GA

Management
Emmanuel Benzaquen, CEO

Description
Provides enterprises with application security testing products and services that empower developers to deliver secure applications

Top 20 DevOps Solution Companies - 2017

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

CIOReview
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@cioreview.com
  • sales@cioreview.com
  • marketing@cioreview.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 CIOReview. All rights reserved.

 

companies_description
This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://www.cioreview.com/checkmarx-2017