How Saxion Embedded Security Into the Software Development Life Cycle (SDLC)

Saxion University of Applied Sciences is one of the leading universities of applied sciences. With tens of thousands of students, dozens of bachelor’s and master’s programmes, and a growing portfolio of digital services, Saxion relies heavily on software applications to support both education and business operations.

As the organisation continued to expand its application landscape, maintaining security, quality, and compliance across software development became increasingly important. To reduce security risks and improve development efficiency, Saxion partnered with CAPE to integrate automated security testing directly into the software development lifecycle.

The challenge: security was being validated too late in the process

Saxion managed a growing portfolio of internally and externally developed applications that were deployed through shared development, testing, acceptance, and production environments.

Historically, security audits and penetration tests were often performed by external specialists only after applications had reached a late stage of development.

While this approach identified vulnerabilities, it also meant that security issues were frequently discovered when significant development work had already been completed.

As a result, resolving these issues often required additional effort, introduced delays, and increased costs.

Saxion wanted a more proactive approach that would allow vulnerabilities to be identified much earlier, reducing risk while improving development efficiency.

About this project

Organisation: Saxion University of Applied Sciences
Industry: Higher education
Focus: Application security and software quality
Solution: Security-by-design development process
Key capability: Automated security testing
Outcome: Faster, safer, and more cost-effective software delivery

Why shift security left?

Security vulnerabilities become significantly more expensive and disruptive to resolve as they move further through the development lifecycle.

When security validation only occurs near deployment, issues can impact release schedules and increase development costs.

By integrating security testing earlier in the process, development teams can identify weaknesses while applications are still being built, making remediation faster, simpler, and less costly.

This approach, often referred to as “shifting security left”, enables organisations to embed security into development rather than treating it as a final checkpoint.

The solution: security integrated from day one

Together with Saxion, CAPE redesigned the development approach by embedding security tooling directly into the software development lifecycle.

Rather than waiting until acceptance testing or pre-production reviews, automated security checks now run continuously throughout development.

This gives developers immediate feedback and enables vulnerabilities to be identified and resolved long before software reaches production environments.

The result is a development process where security becomes a standard part of quality assurance rather than a separate activity performed at the end of a project.

Building security into every release

The new approach introduced multiple improvements across Saxion’s development process.

Security integrated into development

Security checks are now incorporated from the earliest development stages.

This ensures security considerations are addressed continuously throughout the lifecycle rather than after development is completed.

Automated security validation

Automated security tooling performs ongoing checks without slowing down development activities.

This provides faster feedback while maintaining development speed and quality.

Early vulnerability detection

Potential security issues are identified much earlier in the process, allowing development teams to act before risks escalate into larger problems.

Reduced remediation costs

Resolving issues during development is significantly more efficient than addressing them during acceptance testing or after release.

By detecting vulnerabilities earlier, Saxion reduces both effort and costs associated with rework.

Delivering measurable benefits

The introduction of automated security testing has strengthened both the security posture and development efficiency of the organisation.

Faster resolution of security issues

Development teams receive immediate visibility into vulnerabilities, allowing problems to be resolved before they grow into larger risks.

Lower development costs

Early detection reduces expensive remediation work later in the project lifecycle and minimises unexpected development effort.

Shorter development cycles

Automated testing reduces dependency on late-stage security reviews and helps maintain project momentum throughout development.

Greater confidence in production releases

Applications reach production environments with fewer vulnerabilities and a stronger security foundation.

Creating a culture of secure development

The project delivered more than technical improvements.

It helped establish a development culture where security is treated as a shared responsibility rather than the task of a separate audit team.

Developers now receive security feedback throughout the development lifecycle, encouraging continuous improvement and more secure coding practices.

This shift supports both faster delivery and higher software quality across the organisation.

Supporting future digital innovation

As Saxion continues to expand its digital services, security remains a critical requirement.

The ability to identify vulnerabilities automatically and continuously provides a strong foundation for future application development.

By embedding security directly into development workflows, Saxion can continue innovating while maintaining trust, reliability, and compliance.

Enabling secure software delivery at scale

For Saxion, improving security was not simply about performing more penetration tests.

It was about fundamentally changing when and how security is addressed during software development.

By integrating automated security tooling early in the development process, Saxion has created a faster, safer, and more efficient way to build and maintain digital solutions.

Looking to strengthen application security without slowing development?

Whether you’re building new applications, modernising legacy systems, or improving software quality processes, CAPE helps organisations embed security directly into development workflows to reduce risk and accelerate delivery.

Ready to explore what’s possible? Get in touch with our team to discuss your challenges.

Harmjan-CAPE digital solutions