Halving security incidents while modernizing a core lending system
Cobalt needed to modernize an aging lending application and tighten security at the same time, under real regulatory scrutiny.
- Client
- Cobalt Financial
- Timeline
- 26 weeks
- Platforms
- Google Cloud, US regions
- Team
- 6 Synabix engineers across security and software
What the engagement changed, in numbers.
Each figure is verified with Cobalt Financial and cited to its source, so it can be defended, not just quoted.
Where they started.
Cobalt's lending system was a decade old, slow to change, and increasingly hard to defend. Audits were stressful, incidents were rising, and every release felt like a gamble. They could not pause the business to fix it.
The stack we worked in
The work, in order.
- 01
We hardened identity and access first, then added detection and logging so the team could see what was happening.
- 02
Using a strangler-fig approach, we peeled the riskiest parts of the monolith into well-tested services without a big-bang rewrite.
- 03
Security review became part of the pipeline, not a gate at the end, so changes shipped safely and often.
- 04
We mapped controls to SOC 2 and the bank's regulatory obligations and left an evidence trail that makes audits routine.
Other engagements.
All case studiesCutting a logistics platform's cloud bill 34% while improving on-time tracking
Read the case studyA governed clinical data platform that passed audit with zero critical findings
Read the case studySurviving a 3.4x peak on a re-architected storefront, then spending less off-peak
Read the case studyLet us write yours.
Tell us where the business hurts, whether that is a climbing cloud bill, a stalled project, or risk you cannot see. We will map a pragmatic next step and a plan you own.
Prefer email? Write to sales@synabix.com. We reply within one business day.