How Telefónica went from a week to a day and a half for security assessments with Strike.

Telefónica needed a faster way to run offensive security assessments across teams of varying seniority and a growing attack surface. Find out how Strike helped make its security validation more agile, accessible, and reliable.

Client
Telefónica
Date
September 2, 2026
Industry
Telecom
Country
GLOBAL

Security that drives business forward.

UP TO

[01]
6.7x

faster for Threat Emulation exercises.

UP TO

[02]
85%

less work time compared to the usual manual process.

ISO 27001, SOC 2 Type II, HIPAA: 1

[03]

Strike's information security, certified.

Telefónica is one of the largest telecommunications companies in the world, with a presence in more than twelve countries and enterprise-scale technology infrastructure. Its internal Red Team manages between 10 and 15 pentesting exercises per week across a broad universe of assets, ranging from internet-exposed platforms to critical internal systems.

Industry: Telecommunications, multinational enterprise scale.

Product: Telecommunications services (mobile and fixed telephony, internet, and connectivity) for consumers and businesses.

Context and challenges

Telefónica's Red Team operates with a constant flow of testing requests across web assets, APIs, and critical authentication flows: between 10 and 15 exercises per week. The challenge wasn't a lack of methodology, but speed and accessibility: manual exercises took between one week and a week and a half end to end, and the tools they used required complex installation and senior profiles to operate smoothly — something hard to sustain on a team that includes interns and analysts in training.

The need was clear: automate testing without losing depth, and without every exercise depending on a senior profile being available to run it.

Working with Strike

[1] Speed that changes the equation

The underlying reason for trying Strike was to align the security operation with the automation logic Telefónica was already applying in other areas of the business.

"Here in security, at least at Telefónica, we're always looking for continuous improvement with artificial intelligence, automating any repetitive process that takes up a lot of our time. When they mentioned Strike to us, with artificial intelligence, we said: we have to take advantage of this."
Jean Carlo Rosas, Red Team Coordinator at Telefónica

That logic was confirmed in the very first evaluation. Telefónica obtained results equivalent to those of its usual manual process, but in a fraction of the time — what normally took a week or a week and a half was completed in 36 hours.

That speed comes from Threat Emulation tests running automatically and continuously, without depending on a senior profile's availability for each exercise: the team can launch an emulation, let it run, and get results without blocking their daily operations.

[2] Accessible platform for the whole team

One of the most valued findings was that Strike democratizes the execution of pentesting within the team. Unlike tools that require advanced technical knowledge to install and use, Strike allowed junior profiles to operate the platform autonomously.

"You don't need to have a lot of technical knowledge to be able to run the exercises. That's a big help, since I work with interns."
Jean Carlo Rosas, Red Team Coordinator at Telefónica

This has a direct impact on the team's operational capacity: instead of concentrating execution on the most senior profiles, the work can be distributed without sacrificing quality or requiring extensive technical onboarding.

[3] Trust in how information is handled

In an enterprise context, the question of where sensitive information ends up is no small matter. Telefónica highlighted that Strike builds a level of trust that other tools on the market failed to convey.

"With this platform we have the confidence that the information stays with you. And if you find things — maybe not to the depth a human would reach — it's generally a very good tool."
Jean Carlo Rosas, Red Team Coordinator at Telefónica

That point of trust was decisive compared to other solutions evaluated, where a lack of clarity about data handling raised doubts about where the tested assets' information was going.

[4] Guided migration process

The migration to the new platform was carried out with support from the Customer Success team. The process included walkthrough and onboarding sessions for different profiles within Telefónica: first for the person operationally responsible for the platform, then for another team member, and finally for the department head. This helped resolve doubts during the transition and move forward without relying solely on technical documentation or self-guided training.

"From the moment they invited us to migrate, from the moment they held meetings to walk us through it step by step... the patience they had with us. Everything perfect, nothing to complain about."
Jean Carlo Rosas, Red Team Coordinator at Telefónica

In a context where Telefónica manages between 10 and 15 testing exercises per week across enterprise-scale infrastructure, Strike enabled them to dramatically reduce execution times, distribute the workload across profiles of different seniority levels, and build trust in the handling of sensitive information. The clearest differentiator was speed: assessments that used to take between one week and a week and a half are now resolved in 36 hours, with equivalent results and no need for advanced technical knowledge to operate the platform.

This is how Strike's Continuous Hybrid Validation works in practice: automation that keeps pace with the business, without giving up trust or quality.

No previous success case
No next success case
Let’s Talk About Your Industry

See what Strike could do for your business

We’ve helped companies in fintech, healthcare, insurance, and beyond build stronger security stacks. Let’s explore how our offensive approach can work for you.

Manufacturing

Energy

Telecom

Technology

Finance

Healthcare