February 9, 2017 By Marc van Zadelhoff 2 min read

Building on a history of collaboration between the two companies, IBM and HCL have entered into a partnership that takes the best of their shared knowledge and teaming experience to build industry-leading application security solutions.

Application security is a critical component for enterprises to have a robust security posture that functions like an immune system, detecting and preventing threats wherever they occur in the system. As developers create more applications for both businesses and consumers, application security becomes increasingly important.

IBM and HCL Team Up to Enhance Application Security

IBM Security and HCL recognize these needs and have committed to investing in the capabilities for application security. HCL has licensed IBM Security application technology and will build additional features and functionalities based on business realities and client priorities. With this renewed commitment, the two companies will collaborate on the road map and development of these solutions.

Clients using application security solutions will continue to engage with IBM as the primary partner, with HCL broadening the reach to the developer community. HCL’s specialized customer advocacy group fosters collaboration with HCL technical and engineering teams to advance customer interests and develop product road maps for new releases.

A Longstanding and Successful Partnership

This partnership plays on both companies’ strengths. IBM Security is the world’s fastest-growing enterprise security company, and a leader and innovator in security products and managed security services. IBM has been a major player in the application security market, integrating application security as an essential component in the chief information security officer’s (CISO’s) agenda for enterprise security. For example, IBM appears as a “Leader” in the 2018 Gartner Magic Quadrant for Application Security Testing and The Forrester WaveTM: Application Security, Q4 2014.

HCL is a recognized leader in outcome-driven managed security services and security intelligence in an end-to-end enterprise security portfolio. The agreement enhances each partner’s ability to protect clients’ digital and confidential assets, intellectual property and all other forms of business-critical information.

Both companies have enjoyed a longstanding and successful partnership across technology, software and services. With a history of collaboration and innovation, we’re excited about the opportunity to jointly address our clients’ needs for transformation security.

Click here for a complimentary trial of IBM Application Security on Cloud.

More from

FYSA — VMware Critical Vulnerabilities Patched

< 1 min read - SummaryBroadcom has released a security bulletin, VMSA-2025-0004, addressing and remediating three vulnerabilities that, if exploited, could lead to system compromise. Products affected include vCenter Server, vRealize Operations Manager, and vCloud Director.Threat TopographyThreat Type: Critical VulnerabilitiesIndustry: VirtualizationGeolocation: GlobalOverviewX-Force Incident Command is monitoring activity surrounding Broadcom’s Security Bulletin (VMSA-2025-0004) for three potentially critical vulnerabilities in VMware products. These vulnerabilities, identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, have reportedly been exploited in attacks. X-Force has not been able to validate those claims. The vulnerabilities…

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today