What we've actually done.

SCS doesn't publish case studies to fill a page. These are real engagements — sanitized where required — that reflect the scope, consequence, and technical depth of work delivered since 2014.

50+ Assessments Delivered
3 Published CVEs — zero-days in production federal systems
DHS · Dept of State · Enterprise SaaS
TS/SCI-Cleared Personnel

U.S. Department of Homeland Security — CISA

Penetration Testing & Security Engineering

The Challenge

Validate the security posture of a complex federal application and network environment from both insider and outsider threat perspectives, across a diverse portfolio of 50+ applications ranging from small open-source systems to large multi-tier COTS appliances.

What SCS Did

  • Conducted onsite penetration testing from insider and outsider threat perspectives
  • Identified multiple zero-day vulnerabilities including RCE, XSS, SQL injection, and CSRF
  • Successfully rooted production security appliances (FireEye, BlueCoat) during assessment
  • Built virtualized lab environment for exploit development, malware distribution analysis, and security product testing
  • Performed security reviews of application designs, source code, and deployments across web, mobile, SaaS, and thick-client applications
  • Delivered advisory reports to developers, engineers, and senior leadership

The Outcome

Zero-day vulnerabilities — including remote code execution and root compromise of production security appliances — were identified and reported before adversary exploitation. Findings contributed to CVE publication and provided evidence for federal system accreditation.

Relevant Services

Bishop Fox — Google Partnership Program Validation

Web Application Penetration Testing

The Challenge

Conduct high-stakes web application security assessments for enterprise clients seeking approval for the Google Partnership Program. Assessments carried defined pass/fail security criteria and direct commercial consequences — a failed assessment blocked partnership approval.

What SCS Did

  • Comprehensive web application penetration testing for multiple enterprise clients across travel, media, and SaaS verticals
  • Identified and validated security weaknesses with sufficient specificity to guide targeted remediation
  • Provided clear, actionable findings enabling clients to meet Google's security requirements
  • Supported remediation cycles through to successful re-assessment

The Outcome

100% assessment pass rate across enterprise clients in travel, media, and SaaS. Every assessed client achieved Google Partnership Program approval following remediation of SCS-identified findings.

Relevant Services

Qualtrics (SAP)

Web Application Security & Red Team Assessment

The Challenge

Provide comprehensive security validation of Qualtrics' XM experience management platform — including production application endpoints, beta tooling, and the enterprise network infrastructure spanning thousands of endpoints.

What SCS Did

  • Web application penetration testing across the production XM platform and all beta products
  • Red team assessment of the enterprise network, covering thousands of endpoints
  • Identified pre-release vulnerabilities before broad availability
  • Delivered findings with prioritized remediation guidance

The Outcome

Pre-release vulnerabilities were identified and remediated before general availability across an enterprise platform at scale. Assessment findings were delivered with prioritized remediation guidance to the security and engineering teams.

Relevant Services

U.S. Department of State

Security Engineering & Assessment Services

The Challenge

Provide ongoing security engineering and assessment support across a multi-layer federal IT environment including mobile devices, web applications, local area networks, and wireless infrastructure.

What SCS Did

  • Penetration testing across mobile devices, mobile applications, web applications, LAN, and WLAN environments
  • Research and validation of new cybersecurity tools and techniques
  • Security scanning, discovery, remediation, and configuration hardening across all networked assets
  • Risk and threat exposure assessment for information systems
  • Findings and recommendations presented to management and senior leadership

The Outcome

Ongoing penetration testing, hardening support, and risk exposure assessments delivered across mobile, web, LAN, and WLAN environments at a Tier 1 federal agency. Findings were reported directly to security leadership to support sustained compliance and posture improvement.

Relevant Services

NIST 800-171 / DFARS Compliance Delivery

Gap Assessment, SSP Development & Control Implementation

The Challenge

A defense contractor needed to achieve NIST 800-171 compliance under DFARS 252.204-7012 for CUI handling — minimizing implementation cost and complexity while meeting the actual technical requirements of the standard.

What SCS Did

  • Full gap assessment against NIST 800-171 controls
  • Identified FedRAMP cloud isolation as a scope reduction strategy — reducing costly on-premises hardening burden
  • Developed System Security Plan (SSP), POA&M, and full required documentation set
  • Implemented and validated supporting compliance controls for CUI transmission and storage
  • Developed cost-effective alternative approaches for continuous monitoring

The Outcome

DFARS compliance was achieved at lower implementation cost by using FedRAMP-certified cloud isolation to reduce CUI scope — avoiding full on-premises hardening across the environment. SSP, POA&M, and continuous monitoring were delivered as part of an auditor-ready documentation set.

Relevant Services

Start with an assessment grounded in real operator experience.

Federal and commercial delivery since 2014. Tell us about your environment, constraints, and objectives.