How QMC Achieved 17× Faster Remediation with Agentic Security Testing
Qatar Media Corporation (QMC) is Qatar's national media organization. QMC's security team uses Ostorlab's Rule-Based Scan and Deep Agentic Scan across its application portfolio, combining both to strengthen how findings are identified, contextualized, and prioritized for remediation.
Scanning tools flagged issues without enough context to act on quickly. Security and development teams often needed extra back-and-forth to understand which findings mattered most and why. Manual assessments were thorough but slow to scale across a growing application portfolio, and QMC's team needed an approach that could:
- Surface context around findings, not just flag them, so analysis and validation could move faster
- Support clearer, faster remediation conversations between security and development teams
- Reduce the time to get initial security insights, without giving up the rigor of manual review
- Fit into a broader testing strategy that balances continuous coverage with deeper, targeted investigation
Rule-Based Scan for continuous, automated coverage
QMC uses Rule-Based Scan to automate repeatable security monitoring across its application portfolio, providing consistent baseline coverage without manual effort on every pass.
Deep Agentic Scan for context-rich, deeper analysis
Alongside that, QMC adopted Ostorlab's Deep Agentic Scan for enhanced analysis and deeper investigation of complex attack scenarios, specifically for the additional context it surfaces around findings, including technology stack visibility, attack surface mapping, and the relationships between exposures, compared to traditional automated scanning approaches.

Manual review as the final check
Both automated scan types accelerate the identification and validation of potential security issues, but manual verification and expert review remain the step that confirms findings and assesses business-specific risk.
While automated scanning solutions cannot completely replace manual security assessments, the platform helped accelerate the identification and validation of potential security issues.
— QMC
Context that speeds up analysis and validation
The Deep Agentic Scan's added context, including technology stack visibility, attack surface mapping, and relationships between potential exposures, gave QMC's team a clearer starting point for analysis and validation. By focusing on findings that had already been investigated and validated, QMC accelerated remediation by 17×, bringing the average remediation cycle down from four months to one week.
The Deep Agentic Scan provided broader contextual information around identified findings, including technology stack visibility, attack surface mapping, and relationships between potential exposures.
— QMC

Better-informed conversations with application owners
That same context changed the nature of QMC's remediation conversations with developers and application owners, moving discussions from listing problems to agreeing on what to fix first, based on risk and business impact.
This supported more informed remediation discussions and assisted stakeholders in prioritizing corrective actions based on risk and business impact.
— QMC
Faster initial insight, more frequent assessments
Compared to manual assessment, running Rule-Based Scan and Deep Agentic Scan together significantly reduced the time required to obtain initial security insights and enabled more frequent assessments across multiple applications.
Automated scanning significantly reduced the time required to obtain initial security insights and enabled more frequent assessments across multiple applications.
— QMC
A layered strategy going forward
Looking ahead, QMC plans to lean further into this split: Rule-Based Scan for continuous, repeatable monitoring, and Deep Agentic Scan reserved for enhanced analysis and deeper investigation of complex attack scenarios.
Rule-Based Scans can support continuous and repeatable security monitoring across applications, while Deep Agentic Scans can be leveraged for enhanced analysis and deeper investigation of complex attack scenarios.
— QMC
Applications are assessed on a recurring basis using Rule-Based Scan for continuous coverage
Deep Agentic Scan is run for deeper investigation of complex attack scenarios
Findings from Deep Agentic Scan are enriched with technology stack context, attack surface mapping, and exposure relationships, compared to traditional automated scanning approaches
The security team uses this context to prioritize and frame remediation discussions with application owners
Manual verification and expert review confirm findings and assess business-specific risk
QMC's approach shows how automated detection and agentic testing can work together to move findings toward action faster. With richer context around technologies, attack surfaces, and related exposures, alongside expert review, QMC improved how findings are validated and prioritized and achieved 17× faster remediation.
Get Started
Turn security findings into validated remediation priorities
Deep Agentic Scan adds context around findings, validates true positives, and helps security teams focus remediation on the issues that matter most.
Book a Demo