Energy Leader Moves from Vulnerability Noise to Engineering Action

How Repsol transformed millions of disconnected security findings into a prioritized, context-driven remediation program.

Key results:

reduction
%

in exposures requiring remediation

reduction
%

in MTTR for business-critical exposures

of assets
%

enriched with ownership context

time savings
%

per FTE each week on alert triage and contextualization

Industry

Energy

HQ

Madrid, Spain

Size

24,000+ employees, operations in 20+ countries

Featured Leader

Javier García Quintela, CISO

Book a demo

“The pain points that brought us to Tonic were the amazing amount of vulnerabilities that we had from different sources and the difficulties in order to prioritize the efforts in what is more relevant to be protected.”

Javier García Quintela, CISO, Repsol

The Challenge: Too Many Findings, Not Enough Context

Repsol is a global energy leader operating across complex enterprise, cloud, application, and operational environments. Like many large organizations, Repsol had no shortage of vulnerability data. Findings were pouring in from infrastructure, applications, APIs, cloud environments, and industrial control systems.

The challenge was not visibility alone. It was smart prioritization and fast action.

Each tool provided a partial view of risk, but security teams still had to manually connect technical findings to application layers, business workflows, asset context, ownership, and threat relevance. This investigative process required analysts to move across disconnected systems and repositories before they could determine which issues deserved engineering attention first.

This manual investigative phase dragged on for days, delaying remediation and leaving the business exposed.

Repsol evaluated the market, but traditional vulnerability management approaches or newer point solutions could not fully adapt to the complexity of its environment. The company needed a way to unify fragmented signals, enrich them with relevant context, and create a prioritization model that reflected its own architecture, workflows, and security operating model.

Repsol chose Tonic as a strategic partner to help build a risk funnel tailored to its environment.

The Solution: A Unified, Context-Driven Risk Funnel

Tonic sits on top of Repsol’s existing security stack and brings together findings from multiple sources into a unified exposure view. The platform enriches those findings with the context needed to make better and faster remediation decisions, including asset information, ownership, business relevance, internet exposure, exploitability, and threat activity.

Instead of requiring analysts to manually investigate every signal, Tonic helps Repsol automatically connect technical findings to the broader context around them. This allows the security team to move from fragmented vulnerability lists to a prioritized remediation flow, focused on the issues that are most relevant to the business.

Tonic also helps Repsol maximize the value of its existing security investments. Rather than replacing scanners and security tools, Tonic makes their output more actionable by transforming disconnected findings into a single, context-rich risk funnel.

The Impact: Clearer Priorities, Faster Engineering Action

With Tonic, Repsol has been able to reduce friction between security and downstream teams by giving application, development, and data/AI teams clearer guidance on what needs to be fixed first.

Security teams can now translate large volumes of vulnerability data into prioritized, actionable remediation guidance. This helps reduce unnecessary back-and-forth, improves alignment with engineering teams, and allows remediation owners to quickly focus on the exposures with the highest impact.

“What I like best is the effectiveness and performance of the security team. They can clearly show application, developer, and data/AI teams which vulnerabilities they need to fix.”

Javier García Quintela, CISO, Repsol

Built to Scale

As Repsol’s environment continues to evolve, the number of security findings will continue to grow. Tonic provides Repsol with a scalable operational foundation for exposure management, helping the organization continuously prioritize, route, and expedite remediation based on context. By unifying fragmented security data and enriching it with business, ownership, and threat context, Repsol can focus its engineering efforts on the risks that matter most and strengthen its ability to reduce exposure at scale.

Summary

With Tonic, Repsol turned millions of disconnected findings into a prioritized, context-driven remediation program. By connecting security data with business, ownership, and threat context, Repsol can focus remediation efforts on the exposures that matter most, accelerate engineering action, and scale security operations as the business grows.

About Tonic Security

Tonic Security delivers an agentic decision and execution platform for exposure management. Its AI-native platform transforms fragmented security and IT signals into business-aligned risk decisions and verified remediation outcomes. By combining a self-maintaining security Data Fabric with governed workflows, Tonic enables organizations to move beyond vulnerability management toward continuous risk reduction at scale. Leading enterprises, including Fortune 500 companies, rely on Tonic to reduce noise, accelerate remediation, and improve operational efficiency.

More customer stories