Selected projects

Projects in penetration testing, ISMS, and compliance across corporate and industrial environments.

Detailed reports and full case descriptions are available under NDA. Contact us to request access to the full documentation.

BANKING

Web application pentest — financial institution

White-box test of an internet banking application. Verification of authentication mechanisms, session management, and communication encryption.

Key finding: Financial operations executable from outside the application — no anti-CSRF protection combined with outdated transport encryption.

32 vulnerabilities · 3 critical (CVSS 9.1+)
FINTECH

API pentest — payment platform

REST API testing of a fintech platform. Analysis of technical data exposure, DoS resilience, and consistency of authorisation mechanisms across environments.

Key finding: Backend architecture details disclosed through server error messages.

17 vulnerabilities · remediation completed in 6 weeks
E-COMMERCE

Payment application pentest

Black-box test of an e-commerce platform with payment gateway integration. Critical flaws found in financial data handling and validation mechanisms.

Key finding: Customer account number passed in the URL — ending up in server logs and browser history.

16 vulnerabilities · critical issues fixed within 24h
TECHNOLOGY

SPA + REST API pentest — corporate application

Comprehensive testing of a React application with a REST backend. Analysis of session management, API security, and content security policies.

Key finding: Session takeover via a session identifier passed in the URL, with no binding to the user context.

20 vulnerabilities · remediation completed in 8 weeks
INDUSTRY / OT

OT network audit — manufacturing plant

Security audit of an industrial network at a manufacturing facility. Assessment of IT/OT segmentation, communication protocols, and emergency procedures.

Key finding: No segmentation between IT and OT networks — breaching one layer gave access to production controllers.

14-point remediation plan · implemented in 90 days with zero downtime
COMPLIANCE

ISMS implementation — organisation with 200+ employees

Building an information security management system from the ground up. UAM/JML, risk assessments, security policies, preparation for ISO 27001 and NIS2 certification.

ISO 27001NIS2UAM/JML
NIS2-ready in 4 months

Want to know more?

Get in touch — we will share full reports after signing an NDA.

Contact us