Financial servicesSecurity and modernization
Halving security incidents while modernizing a core lending system
Cobalt needed to modernize an aging lending application and tighten security at the same time, under real regulatory scrutiny.
52%
fewer security incidents year on year
3x
faster release cadence, from monthly to weekly
SOC 2 Type II
achieved on the first attempt
The challenge
Where they started.
Cobalt's lending system was a decade old, slow to change, and increasingly hard to defend. Audits were stressful, incidents were rising, and every release felt like a gamble. They could not pause the business to fix it.
The stack
Google CloudGoReactHashiCorp VaultGitLab CICloud Armor
What we did
- We hardened identity and access first, then added detection and logging so the team could see what was happening.
- Using a strangler-fig approach, we peeled the riskiest parts of the monolith into well-tested services without a big-bang rewrite.
- Security review became part of the pipeline, not a gate at the end, so changes shipped safely and often.
- We mapped controls to SOC 2 and the bank's regulatory obligations and left an evidence trail that makes audits routine.
More work
Other engagements.
Manufacturing and logistics
Cutting a logistics platform's cloud bill 34% while improving on-time tracking
ReadHealthcare
A governed clinical data platform that passed audit with zero critical findings
ReadRetail and ecommerce
Surviving a 3.4x peak on a re-architected storefront, then spending less off-peak
ReadLower cost, lower risk, one partner
Let's write yours.
Tell us where the business hurts. We will map a pragmatic next step and a plan you own.