Results: Accelerated Development with Actionable Vulnerability Insight and Automation
Since deploying Black Duck SCA, Austrian Post Group has moved from a state of unknown software supply chain risk to active risk management.
Enhanced Visibility and Workflow
The organization now consistently maintains a complete inventory of the third-party and open source components within its applications. Black Duck SCA automatically detects new vulnerabilities impacting any associated projects and prioritizes issues for remediation. This has created a powerful audit trail that was previously nonexistent.
The BDSA Advantage
For the security champions within the organization, the standout feature has been the BDSAs. Unlike standard NVD data, BDSAs provide actionable vulnerability insight— sourced and curated by Black Duck’s Cybersecurity Research Center—that helps developers understand detected issues and take decisive, effective action.
“My favorite feature is the BDSAs. They not only give faster and deeper insights than CVEs, they also flag hidden risks and adjust severity based on real impact,” said Hahna Christian, delivery systems support engineer and security champion at Austrian Post.
Ease of Management
Features like complete single sign-on support have streamlined user management, a critical requirement for Mosler’s team, while the flexibility of Black Duck SCA’s automation templates for Azure DevOps allow development teams to customize scan parameters and pipeline triggers to balance insight and efficiency across projects.
By partnering with Black Duck, Austrian Post Group has successfully embedded application security and open source risk management into the fabric of its development life cycle. It bridged the gap between security and development, ensuring that its software supply chain remains secure, compliant, and resilient.
When asked if he would recommend Black Duck SCA to a colleague, Mile Bernad is clear: “I would recommend Black Duck SCA. The ease of implementation [is the biggest reason].”