Storebrand is a leading Nordic financial services company with operations spanning banking, insurance, asset management, and pension solutions. With over 2 million customers and more than NOK 1,000 billion invested in more than 5,000 companies globally, Storebrand is one of the largest private asset managers in the Nordic region and has earned a reputation for sustainable finance and innovative investment strategies. Recognized globally for its sustainability initiatives, the company was ranked as the highest-rated Norwegian company on TIME Magazine’s World’s Most Sustainable Companies 2024 list.
As a financial institution managing vast amounts of sensitive customer data and handling complex financial transactions, Storebrand faces a dual challenge: maintaining robust cybersecurity while ensuring the agility of its cloud-native digital services. With the rise of threats targeting financial applications, Storebrand sought a proactive security approach to protect its applications and APIs—without disrupting developer workflows or slowing innovation. Given its cloud-first strategy and recent acquisitions, a scalable, unified security framework became imperative.
To maintain its competitive edge and provide seamless financial services, Storebrand has embraced cutting-edge technology. By modernizing its infrastructure, Storebrand ensures high performance, scalability and security across its diverse business units.
Operating across Norway and Sweden, Storebrand delivers critical financial services through a diversified portfolio of subsidiaries, including:
Storebrand has embraced modern cloud architectures and open-source financial modeling to optimize operations.
Key technological advancements include:
This technology-driven approach allows Storebrand to deliver innovative financial solutions while ensuring security at scale across business units, improving operational efficiency and customer experience.
As financial services continue to digitize, the industry faces an increasing number of cyber threats. A single security breach could expose sensitive customer data, damage brand reputation, and result in regulatory fines. Storebrand recognized the need for a proactive and integrated approach to security to protect its critical applications and maintain customer trust.
The company faced several key risks:
Previously, Storebrand relied primarily on perimeter-based security models that lacked deep visibility into runtime vulnerabilities. The shift to microservices and cloud-based architectures demanded a more dynamic approach, especially as API exposure increased. The company needed real-time security insights to detect, prioritize, and remediate vulnerabilities efficiently.
Given the scale of its cloud-based operations and increasing complexity, Storebrand needed a security solution that could evolve alongside its technology infrastructure. The company was particularly focused on improving application security posture while maintaining development velocity.
Storebrand identified several critical security gaps:
To bridge these gaps, Storebrand needed a developer-friendly security solution that could provide automated insights, reduce false positives, and seamlessly integrate into its CI/CD pipelines to enable secure, agile software development.
After evaluating several security solutions, Storebrand selected Contrast Security due to its ability to provide real-time, automated application security without impacting development speed. Contrast offered a scalable, agent-based approach that allowed Storebrand to identify and mitigate vulnerabilities dynamically at runtime.
By adopting Contrast Security, Storebrand embedded security directly into the development process, empowering developers to address vulnerabilities at the source rather than reactively patching threats post-deployment.
A crucial factor in Storebrand’s security implementation was the choice of an instrumentation-based security model to augment existing eBPF (Extended Berkeley Packet Filter) solutions. While eBPF operates at the kernel level and provides observability across network traffic and system calls, it lacks the deep application context needed to pinpoint vulnerabilities within the software itself. Contrast embeds directly within applications, providing real-time detection of security flaws at the code level. This approach ensures higher accuracy, reduced false positives and the ability to dynamically block threats within the application, offering a more precise and proactive security posture compared to relying solely on eBPF’s broader but less application-aware monitoring.
Storebrand rolled out Contrast Security using a phased deployment strategy, ensuring a seamless transition without disrupting core operations. The implementation prioritized automation and efficiency to effectively scale.
Key steps included:

One of the most significant security wins was detecting previously undiscovered XML injection vulnerabilities.
Contrast’s real-time analysis helped Storebrand pinpoint risks as they emerged, allowing proactive mitigation before exploitation. Traditional security tools, such as Web Application Firewalls (WAFs) and static scanners, failed to detect these vulnerabilities due to their lack of application-layer visibility.
By embedding security into the development lifecycle, Storebrand significantly improved its security posture while driving operational efficiency.
Results achieved:
Storebrand’s journey highlights the critical need for embedded, real-time security in financial services. By automating security enforcement, enabling real-time vulnerability detection, and seamlessly integrating with developer workflows, Storebrand has built a scalable security model that enhances resilience while supporting business growth.
Schedule a demo and see how to eliminate your application-layer blind spots.
Book a demo