Aikido

How Tyro Payments runs pentests in hours with Aikido

5.5h
For a pentest
6x
More issues surfaced by Aikido's AI Pentest
10k to 100
Vulnerabilities filtered
80k+
Merchants whose payment Tyro protects

At a glance

  • Ran a full pentest in about five and a half hours, where the previous human test took roughly 15 business days
  • Surfaced more issues than the human pentest, including more high-severity findings
  • Cut alerts from tens of thousands to a few hundred by consolidating tools and clearing out duplicates and false positives
  • Gave developers one-click AutoFix, so remediation stopped eating hours per issue
  • Caught supply chain exposure early, including a fast check during the Axios incident
  • Turned security from a blocker into a team that developers bring problems to

Keeping security in step with a growing payments business

Tyro Payments has been working to make payments the easy part of running a business since 2003. The Sydney company is a listed Australian bank, regulated by Australia's banking regulator APRA, and it powers more than 80,000 merchants across the country with in-store, online and mobile payments alongside a growing set of banking products.

Arun Singh is the information security officer at Tyro. He is responsible for protecting the private data of those merchants, including the sensitive know-your-customer (KYC) information the business holds. For a payments company, that responsibility sits right next to the core promise it makes to every merchant.

"We get a lot of sensitive data from the merchants, a lot of KYC information. Protecting them is one of the core promises of the business. It's a promise we make when they first sign on, that we'll keep them secure."

The hard part is keeping that promise while developers ship quickly. The clearest sign of how far Tyro has come is what happened to its pentesting.

The challenge

Decentralized tools and a growing backlog

Before adopting Aikido, the team ran on a spread of separate vulnerability management tools, and the findings piled up faster than anyone could work them.

"Pre-Aikido we had several different vulnerability management tools that were quite decentralized. There was a significant percentage of false positives, and the security team especially was drowning in alerts. Giving engineering thousands of alerts to investigate always meant the work got deprioritized. Our backlog just kept growing. It became overwhelming."

Pentesting that couldn't keep up

Pentesting was slow and expensive, and it rarely paid back the wait. A single test tied up a project for weeks and returned little.

"A pentest would take approximately 15 business days. It would delay a project, and it would cost a couple of tens of thousands of dollars. The findings were not great, we would get a handful."

Why Tyro Payments chose Aikido

Findings the team could trust

The change that mattered most was accuracy. Older tools assumed that if a package carried a CVE, Tyro was exposed, so developers burned time patching code that was never at risk. Aikido reads the source and checks whether the vulnerable code is actually reachable.

"Something that should take 10 or 15 minutes would take half a day, only for us to realize the vulnerable function within the CVE we never actually used. So we weren't actually vulnerable. With Aikido, it looks at our source code, contextualizes the vulnerability, and tells us whether the vulnerable code is actually in use."

A choice made on the numbers

Tyro did not pick Aikido on reputation. The team ran it against the alternatives and it came out in front.

"We compared Aikido to Snyk, to Checkmarx, and to CrowdStrike's application security posture management. It always came out in front, in how it presented the information, how it reduced false positives, and how it guided engineers through discovery, impact and remediation. It was a pretty easy choice."

A product team that moved fast

The people behind the product stood out as much as the product.

"If there was a new function or improvement we wanted, we would message the Aikido team, and within 24 hours they would turn around and release the fix. Seeing the product evolve over the last few years has been great."

From tens of thousands of alerts to a few hundred

Consolidating onto Aikido gave the team end-to-end visibility, from direct dependencies through to the transitive ones the old tools stopped short of, and it cleared out the noise that had buried the real work.

"It gives us end-to-end visibility from direct dependencies all the way through to transitive dependencies, which a lot of our other tools didn't. It triages, de-dupes, and removes false positives. We went from tens of thousands of alerts at any given time to a few hundred."

Fixing what remained got faster too. Instead of developers spending hours working out how to patch something and whether the fix would break anything, AutoFix does the work and hands them a change to review.

"With Aikido's AutoFix, they click a button, they get the actual fix, review it, raise the PR, test it, done. It really streamlined their workflows."

A pentest that finished in hours

The sharpest result came from AI pentesting. Tyro ran a proof of concept on a new health product it was launching, and put the AI pentest side by side with its incumbent human testers.

"Our incumbent penetration testers took approximately 15 days. We did the same thing with Aikido. It took five and a half hours and found approximately 30 issues, nine high, whereas the human pen testers found five issues, one high."

The plan from here is to keep the people and add the speed, using AI to widen coverage and human reviewers to confirm it.

"Our plan is a hybrid model, AI penetration testing and AI code audit with a human review from our pentesting partners. The costs are significantly less than what we were paying, so we can do a lot more with what we have."

Training developers actually use

Security awareness had been its own line item, and not a well-liked one. The tool Tyro paid for sat apart from the work and taught developers little. The bite sized educational videos that Aikido constantly shares on YouTube and other social media platforms got developers more engaged than the full blown security awareness platforms of choice up until that point.

"When I joined, we had a developer security program that cost about $100,000. Developers always gave negative feedback on it. It was never contextualized to their workload, so they never really learned from it. It was more of a tick-box exercise. With Aikido, a vulnerability is now a bite-sized video you watch to learn how to prevent it. We started noticing secure development practices we had advocated for years actually being implemented early on."

Seeing the whole supply chain

Supply chain risk is a board-level topic at Tyro, and it is where malware scanning and threat intel earn their place, catching compromised packages before they reach production. The value showed during the Axios incident, when the team could answer a hard question fast.

"Supply chain security is top of mind. We talk about it at board level. With Aikido's malware scanning and threat intel, we pick up findings early and prevent them before they hit production. When the Axios breach happened, the team said we don't use it. We went into Aikido, presented it back, validated the version, and checked if we were compromised. Thankfully we weren't, but it was an eye opener."

A red team exercise then exposed the next gap. Tyro simulated a malicious IDE extension published to the VS Code marketplace that stole a developer's secrets, and found it had no coverage at that layer. Closing it is the reason device protection is next on the list.

Where Tyro Payments goes next

Tyro currently uses Aikido for software composition analysis, static analysis (SAST), dynamic analysis (DAST), AutoFix, reachability analysis, malware scanning and threat intel, and developer training.

From here the direction is to expand AI pentesting into the hybrid model with human review, to explore AI code audit alongside it, and to run a device protection pilot to close the developer-device gap the red team exercise exposed.

Final verdict

What changed most for Arun is how developers now treat security.

"Their perception of security was quite negative previously. Now the relationship is quite excellent. They come to us when they find issues or hear about a breach, wanting to engage and wanting to learn."

Asked what it adds up to, he keeps it simple.

"We can do a lot more with what we have than we could previously."

Get secure now

Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.

No credit card required | Scan results in 32secs.