Building a security validation program across global manufacturing environments requires more than deploying another scanning tool. Security teams need to identify which weaknesses attackers can actually exploit, prioritize remediation, and validate risk without disrupting production.
Kyocera AVX faced that challenge across 33 manufacturing sites worldwide. With no formal vulnerability management or pentesting program, the company needed a practical way to understand real exposure and build a repeatable validation process that could coexist with complex production environments.
This customer story explores how Kyocera AVX used NodeZero® to build a global, evidence-driven security validation program, remediate more than 30,000 vulnerabilities and misconfigurations, and establish a pentesting cadence four times higher than the industry norm.
Key Insight
Traditional vulnerability findings show teams what might be vulnerable. Kyocera AVX needed an attacker’s perspective to understand which weaknesses could actually be exploited and chained into meaningful attack paths.
By making NodeZero the engine behind its vulnerability management and pentesting program, Kyocera AVX gained:
- Visibility into real, exploitable attack paths
- A repeatable validation program across global manufacturing sites
- Actionable Fix Actions that IT teams could use to remediate risk
- Targeted retesting with 1-Click Verify
- Executive visibility through NodeZero data integrated with Splunk
- A sustainable testing model designed around production realities
What You’ll Learn
- How to build a security validation program from the ground up
- Why exploit-based testing provides context traditional vulnerability findings cannot
- How Kyocera AVX scaled autonomous pentesting across global manufacturing environments
- How attack-path evidence helps overcome operational resistance to security testing
- Why Fix Actions can make remediation clearer and more actionable for IT teams
- How targeted retesting verifies whether security fixes actually reduce exposure
- How NodeZero data and Splunk dashboards help communicate risk to executives
- How continuous pentesting can coexist with production and OT-adjacent environments
Why It Matters
Manufacturing security teams have to balance cyber risk with business continuity and production safety. That can make organizations understandably cautious about introducing testing they perceive as invasive.
But avoiding validation leaves another risk: vulnerabilities, misconfigurations, credential exposures, and attack paths can remain hidden because no one has demonstrated how an attacker could actually use them.
Kyocera AVX changed that dynamic.
NodeZero reached most manufacturing sites in roughly one to two years, compared with the four to five years typically required to fully roll out comparable tools in the company’s environment. Today, approximately 34 NodeZero hosts support regular assessments, with about four pentests per site each year plus targeted validation.
In approximately three years, Kyocera AVX remediated more than 30,000 vulnerabilities and misconfigurations, transforming a program with essentially no formal vulnerability management or pentesting coverage into a global, evidence-driven security validation practice.
Download the customer story to see how Kyocera AVX used NodeZero to build a global security validation program, expose real attack paths, and turn more than 30,000 weaknesses into measurable risk reduction.

