At a glance
- Came to Aikido because no other tool on the market flagged end-of-life software.
- Automated the daily triage of 40 to 50 findings, saving the team at least an hour a day.
- Replaced a patchwork of point tools, including a separate dark-web monitoring vendor, with one platform.
- Got Scala coverage that several other scanners could not match.
- Stood up every capability in a few days, where older tools took days or weeks to configure just one.
- Freed the team to spend time on incident response and fixes instead of manual triage.
Challenge
Kristina Holovka is a vulnerability and incident engineer at Cognism, a B2B sales intelligence company based in London. Cognism handles large volumes of business contact data for thousands of revenue teams, so security and compliance sit close to the product. Kristina’s team owns vulnerability and incident response. They field alerts, decide what gets fixed, and work with engineering to get it done.
One gap shaped everything before Aikido. Nothing in the stack flagged end-of-life software, the outdated packages and unsupported language versions that quietly become unpatched attack surface. Finding them meant reviewing repositories by hand, or noticing by accident. For a team responsible for posture across the whole codebase, that was a blind spot they could not close with the tools they had.
"We didn’t have a tool that detected end-of-life software. Aikido was the only one on the market doing that."
The wider setup was a patchwork. Security ran several separate tools, roughly one per feature, with nothing tying them together. Each had a failure mode. Some were too noisy, flooding the team with findings that took hours to review. Others were too quiet, missing real issues because they lacked the rules to cover parts of Cognism’s stack. A separate vendor handled dark-web monitoring for leaked credentials, which meant one more console to check. And standing any of it up was slow. Configuring a single capability like SAST could take days or weeks.
"Some vendors were too noisy, so we spent a lot of time reviewing findings. Others were too quiet, without enough rules, for example for Scala."
Solution
Aikido replaced the patchwork. The team brought their code scanning, end-of-life detection and the dark-web feed onto one platform and had it running in a few days. The contrast with the old setup was sharp. What used to take days or weeks to configure for a single capability now covered everything in the same short window.
"Configuring our old tools took days or weeks. Aikido was enabled in a few days for everything."
The detection fit Cognism’s stack instead of fighting it. The team writes Scala, which several scanners handle poorly because it is not a widely used language. That was the same gap that had left their old tools too quiet, missing issues they should have caught. Aikido detected Scala well, and that alone ruled out some of the tools on their shortlist. A scanner that covers the languages you actually ship lets a security team trust the results rather than second-guess them.
"A lot of vendors don’t cover Scala because it isn’t widely used. Aikido detects it well."
The clearest day-to-day change was triage. Every day, 40 to 50 new findings used to land on the team, each one reviewed by hand to sort the real issues from the noise. AutoTriage, AutoFix and reachability analysis now carry that load. Reachability matters most here. It filters out findings that don’t apply because the vulnerable code can’t be reached, so the team stops chasing issues that were never a real risk. What is left arrives already sorted, and the team gets at least an hour back every day.
"We used to triage 40 to 50 findings a day by hand. Aikido does that for us now, and it saves us at least an hour a day."
The original gap closed in the process. Where the team once combed through repositories looking for outdated packages and unsupported language versions, they now open one tab and see what needs updating. Work that used to depend on someone remembering to look is simply there when they need it.
"Now I just open the tab and see what needs updating."
Why Cognism chose Aikido
- End-of-life detection that no other vendor on the shortlist offered.
- Language coverage that fit their stack, including Scala, where other tools came up short.
- AutoTriage, AutoFix and reachability analysis that took daily triage off the team.
- Dark-web monitoring in the same view as code findings, replacing a separate vendor.
Results
Automating the daily 40 to 50 findings gives the team at least an hour back every day, and the manual work that used to fill mornings is largely gone. With fewer false positives to chase, that time goes back to the team’s actual job: responding to incidents and working with engineering on the fixes that matter. Issues resolve faster too, because the findings arrive triaged and prioritised rather than raw.
"A lot of the manual work is gone, and we resolve issues faster. The hours we get back go to more important work."
Pulling dark-web monitoring in from a separate vendor was the clearest piece of consolidation, but not the only one. Code scanning, end-of-life detection, reachability and the leaked-credentials feed now live in one place, and that is where the team starts the day. Instead of moving between consoles that each reported in their own way, they work from a single view of what needs attention.
The partnership has been hands-on. Requests reach Aikido’s leadership directly, and the team has had answers and turnarounds inside a day. For a security team that has to move quickly, a vendor that responds at that pace is a real part of the value.
"We get feedback directly from the CEO and CRO, which we’ve never had anywhere else. Every request was answered and every task done in under 24 hours."
How Cognism is expanding its use of Aikido
Already using
- End-of-life detection.
- SAST and SCA scanning with reachability analysis.
- AutoTriage and AutoFix.
- Dark-web monitoring for leaked credentials.
Planning to adopt
- Device protection, to see the packages and extensions installed on developer machines, coverage the team says other endpoint tools do not provide.
- Safe Chain, to be rolled out to developers.
Final verdict
"More time, fewer false positives, and more time to focus on what matters."

