How Patria went from ten- day security assessments to two or three with Strike.
Patria needed a faster, more scalable way to run security assessments across a growing attack surface of applications, APIs, ETLs, and cloud environments. Find out how Strike helped make its security validation faster, more preventive, and more comprehensive.

Security that drives business forward.
Faster
To complete security assessments.
Accuracy
With the ability to add context to each asset.
Automatic retesting
No fix goes unvalidated.
About Patria
Patria is an alternative asset manager with more than 35 years of experience in Latin America, a global presence, and eight active business lines, ranging from private equity to infrastructure and wealth management.
Industry: Financial services / alternative asset management
Product: Private market investment solutions and wealth management
Context and challenges
Patria was going through an evolution in the way it worked, with more technology initiatives, in-house development, and new assets requiring security assessment. The challenge was to scale the validation of applications, APIs, ETLs, and cloud environments without becoming a bottleneck for the business.
Many initiatives arrived correctly resolved from a functional standpoint, but without an equivalent security review. Patria also wanted to broaden its scope beyond publicly exposed assets, incorporating internal developments and environments into its validation strategy as well.
Facing an expanding attack surface and a growing need for speed, Patria needed an approach that combined automation, continuous visibility, and specialized expertise to detect and prioritize vulnerabilities more proactively.
The need was clear: scale security assessments to keep pace with new initiatives, reduce response times, and expand coverage across an increasingly dynamic attack surface.
Working with Strike
[1] The speed that changes the equation
The most tangible improvement was the reduction in assessment times: processes that used to take around ten days are now resolved in two or three. That represents a reduction of up to 80% in the time needed to complete an assessment.
"What used to take ten days on average, I now get done in two or three days. I improved response times, and it's much more preventive."
Sebastián Zuloaga Araya
Cyber Security Architect at Patria
Beyond operational efficiency, the impact lies in the ability to respond at the pace of the business. By shortening assessment cycles, Patria can bring security into new initiatives earlier, speed up feedback to technical teams, and move toward a more preventive posture.
That speed is no coincidence: it results from tests running continuously rather than in one-off runs, and from the fact that retesting a specific finding doesn't require waiting for the next full run.
In Strike's model, that revalidation mechanism is designed to resolve in minutes, not days — which helps explain why a cycle that used to take ten days is now resolved in two or three.
The result: Less waiting for visibility, better response times, and a greater ability to keep pace with a growing attack surface.
[2] Extending security beyond the perimeter
Patria identified that limiting assessments to internet-exposed assets leaves relevant risks out of scope. Internal applications, development environments, and new services can also expand the attack surface, especially as technology initiatives grow.
"That answer keeps me up at night, because it's false.""I can see my security gaps in almost real time."
Sebastián Zuloaga Araya
Cyber Security Architect at Patria
The need was to gain visibility into those assets and not rely on exposure assumptions to decide what to review. With Strike, Patria highlighted a greater ability to identify gaps quickly and move toward a more continuous validation strategy.
This connects directly to Strike's Live Asset Radar module, which continuously maps the attack surface, combining automatic discovery of external assets (domains, subdomains, APIs) with direct integration into the client's cloud environments — so an asset doesn't need to be publicly exposed to enter the security radar.
The result: A broader security view that helps prioritize risks before they become incidents.
[3] From isolated assets to context-driven assessments
Beyond the results, Patria highlighted improvements in the platform's operational experience. The configuration of each assessment and the ability to incorporate context and technical documentation made it easier to prepare tests across different assets.
"The configuration part improved for me. Now I add context, which I didn't have before, and that helps a lot too. I think that's great — keep it."
Sebastián Zuloaga Araya
Cyber Security Architect at Patria
Strike's Asset Context is the configuration field where each client describes what the asset does, how it's used, and why it's critical to the business. This makes it possible to add technical documentation directly to that assessment: API specs (Postman, Swagger/OpenAPI), flow diagrams, JSON, images.
It's not an isolated free-text field — it's the input the Threat Emulation Engine uses to prioritize what to test in each run, instead of starting from scratch every time. That's why the more technical documentation a client uploads, the better calibrated the emulation engine begins to work.
The result: Less friction when starting assessments, and more context so tests are relevant from the outset.
Patria needed to support an operation with more assets, internal initiatives, and security validation needs without slowing down the business. Strike enabled it to gain speed, improve response times, and adopt a more preventive approach. The team highlighted the ability to add context and technical documentation to each assessment, along with more agile configuration. The most concrete impact was on timing: assessments that used to take around ten days can now be resolved in two or three, with greater visibility into security gaps.