Column
COLUMN

IssueHunt Launches Security Consulting Services for SAST, SBOM, and CSPM — Identifying "Real Risks" from vast alerts and providing remediation plans in as little as one month —

IssueHunt Consulting Service Launch

IssueHunt Inc. (Headquarters: Chuo-ku, Tokyo; CEO: Kazumasa Yokomizo), provider of the integrated product security support service "IssueHunt One," announced on March 4 the launch of a one-stop consulting service. The service covers the entire security spectrum, from "risk identification" to "remediation methods and operational support" for SAST, SBOM, and CSPM.

By combining AI with expert security engineers, the service visualizes only the "real risks" within software. This intensive, short-term program can be completed in as little as one month, leading development teams to effective solutions for their security challenges.

■ Beyond Detection: Partnering Through to "Remediation"

Overview of Consulting Services

With the spread of agile development and the advancement of AI utilization, software vulnerability risks are becoming increasingly complex. While many organizations have introduced security tools, they face severe shortages of talent and resources, often finding themselves "unable to determine which of the massive volume of alerts should be prioritized."

The new consulting service provided by IssueHunt aims to break this "detection-only" cycle. Through the following three plans, the company supports both business risk reduction and maintaining release speed:

  • 1. SBOM Consulting:
    Analyzing vast dependencies in used libraries to identify vulnerabilities with a high risk of actual exploitation (KEV/EPSS), thereby visualizing supply chain risks.
  • 2. SAST Consulting:
    Analyzing source code quality to identify critical flaws such as SQL injection and XSS, followed by providing specific remediation proposals.
  • 3. CSPM Consulting:
    Analyzing cloud environments like AWS, Google Cloud, and Azure to identify misconfigurations that lead directly to data leaks, such as "publicly accessible S3 buckets."

■ Strengthening Comprehensive Security Support

Guided by the vision "To be the baseline for a connected world," IssueHunt operates a bug bounty platform and other security solutions. The company already supports security measures for a wide range of clients, from major corporations like SUBARU, CyberAgent, and LINE WORKS to prominent mega-ventures.

With the expansion of these consulting services, IssueHunt is poised to provide even more flexible and practical support for the diversifying security needs of modern enterprises.

■ ICT Startup League
This support program was launched in FY2023, triggered by the Ministry of Internal Affairs and Communications' "Project for Supporting Budding R&D for Startup Creation."
The ICT Startup League supports startups through four main pillars:
1. R&D Funding / Hands-on Support
Up to 20 million yen in R&D funding is provided in the form of subsidies. Furthermore, the selection committee members who participate in the screening process stay close to the startups even after selection to promote growth. For companies highly rated by committee members, a "supportive fan" (Oshikatsu) style system is built where the evaluators themselves continuously provide advice on business plans and growth opportunities.
2. Discovery & Nurturing
The league provides opportunities for learning and networking to accelerate the business growth of its members. It also works to discover future entrepreneurs to expand the startup ecosystem.
3. Competition & Co-creation
Functioning like a positive competitive sports league, the system allows startups to learn together and compete to win the necessary funding (up to 20 million yen). It also offers a "co-creation" space where league members can collaborate and expand their businesses through sessions with selection committee members and various other opportunities.
4. Promotion
The initiatives of league members are promoted in collaboration with the media. By making their businesses known to a wider audience, the program aims to expand matching opportunities and create new chances for success.

Other Columns

For more details on STARTUP LEAGUE's startup support, please see here.