About the Client
The e-Health Centre is a state budget entity subordinate to the Minister of Health, responsible for key digitalization processes within the Polish healthcare sector. The institution designs, implements, and maintains IT systems holding critical infrastructure status, which are used daily by millions of patients, doctors, pharmacists, and public officials in Poland.
The e-Health Centre’s portfolio includes the management of over 50 central IT systems.
Duration
- 45 days
Industry
- Public health
Public office
Introduction
As a public entity, the e-Health Centre selected its contractor through a transparent public procurement procedure. We entered the tender as a consortium consisting of SoftwareMill (a VirtusLab company) and Aikido Security BV.
Aikido Security is an integrated SaaS platform designed for scanning code, cloud infrastructure, and production environments for vulnerabilities and security loopholes. The solution stands out in the market for its high cost-effectiveness and a unique, developer-oriented approach that minimizes false positives.
As part of the winning tender, we delivered and secured:
- 330 Pro licenses for a period of 36 months (base order),
- Full platform configuration, deployment, and dedicated training for technical teams,
- Comprehensive, detailed as-built documentation.
The contract also includes an option for a pool of up to 400 hours of expert support and the possibility to expand the deployment by an additional 330 licenses.
Project Funding: The platform implementation was funded by the European Union under the NextGenerationEU program.
Challenges
Delivering a solution for an essential entity like the e-Health Centre involved meeting strict technical, formal, and time-related criteria. The key challenges included:
- NIS2 and UKSC Compliance in Practice: The e-Health Centre required a tool capable of providing continuous, systematic application vulnerability scanning and effective management of software supply chain security, including the generation and analysis of Software Bill of Materials (SBOM) components.
- On-Prem Environment: Although Aikido Security is most commonly deployed as a cloud platform, the specific nature of the e-Health Center’s infrastructure required the scanners to be run within an isolated, secure internal network. The challenge was to deploy local scanning agents and ensure fully secure, controlled outbound communication (via dedicated proxies and network gateways) without the risk of source code leaking outside the institution’s security perimeter.
- Secure Systems Integration: It was necessary to integrate the platform with internal code repositories, CI/CD tools, and other tools and environments while maintaining the highest standards of authorization and authentication.
- Strict Timeline (45 Days): According to the contractual terms, the consortium had only 45 calendar days to complete the full deployment, including configuration, testing, integrations, training, and delivering the final documentation.
Solution
Most traditional AppSec (Application Security) tools force the source code to be uploaded to the vendor's cloud, which is often a significant barrier for public sector institutions. The Aikido Security platform offers a model where the analysis takes place entirely locally – code repositories never leave the Client's secure infrastructure. As part of the implementation, we launched the full range of Aikido vulnerability scanning, creating a security ecosystem for the entire development process:
- Static Application Security Testing (SAST): Static analysis of source code for security vulnerabilities introduced by developers (e.g., SQL injection, unsafe deserialization, path traversal).
- Software Composition Analysis (SCA): Monitoring open-source libraries and external components for known vulnerabilities (CVEs, such as Log4Shell-type vulnerabilities).
- Container Scanning: Scanning container images (Docker) for known vulnerabilities (CVE), including those at the system level, as well as configuration errors in the images themselves and in Dockerfiles (e.g., running a container as root, excessive permissions)
- Secret Scanning: Detection of secrets – API keys, passwords, tokens – accidentally left in the code, covering the full history of repositories.
- SBOM (Software Bill of Materials) Management: Generating an automatic, detailed “bill of materials” for software. This is a key element that directly addresses the NIS2 directive’s requirements regarding supply chain auditability. Aikido enables exporting SBOMs to auditable formats such as SPDX/CycloneDX, monitoring licensing risks, and immediately searching all dependency trees by CVE number to answer the question “does this vulnerability affect us and where exactly does it occur.”
Furthermore, to ensure a smooth workflow for over 300 developers, we integrated the Aikido platform with local source code repositories and the internal tools of the e-Health
Results
The full deployment of the platform was completed within the tight 45-day contractual deadline. Within this timeframe, we successfully launched security monitoring for the e-Health Centre's systems and development teams.
An additional benefit is the support for NIS2 and UKSC compliance. The deployment satisfies the statutory technical requirements for systematic vulnerability scanning and supply chain auditability (SBOM).
Furthermore, Aikido's advanced algorithms effectively filter out false positives before they reach the developers. As a result, engineers do not waste time verifying superficial issues and can focus on real vulnerabilities.
A crucial final element of the project was the handover of comprehensive as-built documentation totaling 66 pages. This documentation serves not only as formal confirmation of work executed to the highest standards but also currently acts as a complete best-practices manual and technical guide for the e-Health Centre's internal teams. Thanks to it, the institution's engineers can independently and efficiently deploy Aikido across subsequent IT systems.
.png?g-d9dbf2fe)