ResourcesCase studiesHow Tradesolution secures Norway’s grocery supply chain with continuous attack surface monitoring

Customer story: Tradesolution

How Tradesolution secures Norway’s grocery supply chain with continuous attack surface monitoring

Tradesolution powers the digital backbone of the Norwegian grocery and foodservice industry. As their digital footprint expanded, the security team needed a scalable way to continuously monitor internet-facing assets without increasing manual workload or relying solely on annual penetration tests.

Tradesolution's achievements:

By implementing Detectify, Tradesolution has:

  • 115% Expansion in subdomains with no visibility gap: Seamlessly gained total oversight of an attack surface that grew from 140 to over 300 subdomains without increasing manual overhead.
  • Resolved 30+ High-Impact remediations: Identified and solved critical vulnerabilities that would have otherwise waited months for a manual audit.
  • Accelerates the Mean Time to Remediation (MTTR): By automating the triage-to-ticket workflow with AI to translate complex vulnerabilities into actionable developer tasks, fostering a culture of shared responsibility.
  • Cost-Efficient security budget usage: Achieved high-fidelity security monitoring that fits a medium-sized budget, outperforming the value and noise-reduction of legacy cloud providers.
  • Continuous security posture: Transitioned from "point-in-time" yearly reviews to a weekly cadence of discovery and remediation.

The failure of "Point-in-Time" security

As Tradesolution expands its attack surface to support the logistics and transport integrations of ASKO and Orkla Health, legacy security models become increasingly difficult to scale. Øyvind recalls that "a yearly review didn't cover everything we wanted." Moving away from annual penetration tests became necessary because yearly reviews created data gaps regarding newly exposed assets and infrastructure changes between audits. Given the increased speed of system development, Tradesolution replaced infrequent manual audits with a continuous monitoring solution to maintain visibility across its environment and reduce the high costs associated with traditional "point-in-time" assessments.

It’s not enough to just do this yearly, Øyvind explains.

Tradesolution requires a solution that scales at the speed of development to protect stakeholders such as Coop and REMA 1000, especially when "functionality and system development have sped up a lot more."

Continuous, automated asset discovery and assessment

Tradesolution utilizes Detectify to maintain a continuous defense-in-depth strategy. By leveraging Surface Monitoring, Application Scanning, and API Scanning, the team maintains 24/7 visibility into its 300+ subdomains.

To maximize operational efficiency, Tradesolution leverages the Detectify API as a core part of its security stack. The team feeds high-fidelity scan data into an internal AI engine that "sorts them in user cases. These tickets populate directly, providing developers with the exact context needed to remediate risks.

"That's very important if you want to have attention from the developers," Øyvind adds, "trying to bridge security concepts to developer concepts.

Monitoring Frequency
Before Detectify
Point-in-time: Yearly penetration tests and manual audits
After Detectify
Continuous: Weekly cadence of discovery and 24/7 automated auditing
Attack Surface Visibility
Before Detectify
Limited to 140 subdomains with significant visibility gaps
After Detectify
300+ subdomains (115% expansion) with total oversight and no gaps
Remediation Speed
Before Detectify
Slow: Critical vulnerabilities could wait months for a manual audit to be identified.
After Detectify
Accelerated: 30+ high-impact remediations resolved via automated triage
Developer Workflow
Before Detectify
Manual, complex security concepts that were difficult for developers to implement
After Detectify
AI-Integrated: Automated "triage-to-ticket" workflow that translates risks into developer tasks
Asset Discovery
Before Detectify
Manual: Inefficient discovery that failed to keep pace with rapid development
After Detectify
Automated: Continuous discovery that scales at the speed of infrastructure changes
Budget & Value
Before Detectify
Costly: High-cost manual reviews with noise and legacy provider overhead
After Detectify
Cost-Efficient: High-fidelity monitoring that fits a medium-sized budget with reduced noise
Security Culture
Before Detectify
Reactive and siloed
After Detectify
Proactive: A safety net fostering a culture of shared responsibility
A side-by-side comparison table showing how Detectify transforms Tradesolution's security posture — from point-in-time, manual processes to continuous automated monitoring, faster remediation, and proactive full-surface visibility.

Resulting in a continuous safety net

Today, Tradesolution maintains a highly secure and transparent baseline across its entire infrastructure. By automating discovery and triage, the IT team eliminates the infeasible manual workload of tracking an ever-growing attack surface. Detectify functions as the "Continuous Safety Net" within Tradesolution’s DevSecOps ecosystem. With this continuous oversight, Detectify acts as an automated, 24/7 auditor that validates every deployment, ensuring that security awareness persists as a weekly habit. Detectify provides the accuracy required to reduce "noise," as "it’s easier for me to filter out which ones I want to do something with." The result is a more resilient supply chain that secures the data of over 2,500 Norwegian customers. "It helps solve the challenges you don't know you have," Øyvind concludes.

Detectify has been instrumental in strengthening our security posture by giving us clear visibility into vulnerabilities across our systems that we simply wouldn’t have found on our own. The support from the Detectify team has been outstanding — responsive, knowledgeable, and genuinely invested in our success. We feel significantly more confident in our security today because of Detectify.

— Øyvind, IT Manager at Tradesolution

Know what's exposed. Fix what matters.

Start scanning to find exploitable vulnerabilities across your entire attack surface.