Selected projects
Projects in penetration testing, ISMS, and compliance across corporate and industrial environments.
Web application pentest — financial institution
White-box test of an internet banking application. Verification of authentication mechanisms, session management, and communication encryption.
Key finding: Financial operations executable from outside the application — no anti-CSRF protection combined with outdated transport encryption.
API pentest — payment platform
REST API testing of a fintech platform. Analysis of technical data exposure, DoS resilience, and consistency of authorisation mechanisms across environments.
Key finding: Backend architecture details disclosed through server error messages.
Payment application pentest
Black-box test of an e-commerce platform with payment gateway integration. Critical flaws found in financial data handling and validation mechanisms.
Key finding: Customer account number passed in the URL — ending up in server logs and browser history.
SPA + REST API pentest — corporate application
Comprehensive testing of a React application with a REST backend. Analysis of session management, API security, and content security policies.
Key finding: Session takeover via a session identifier passed in the URL, with no binding to the user context.
OT network audit — manufacturing plant
Security audit of an industrial network at a manufacturing facility. Assessment of IT/OT segmentation, communication protocols, and emergency procedures.
Key finding: No segmentation between IT and OT networks — breaching one layer gave access to production controllers.
ISMS implementation — organisation with 200+ employees
Building an information security management system from the ground up. UAM/JML, risk assessments, security policies, preparation for ISO 27001 and NIS2 certification.
Want to know more?
Get in touch — we will share full reports after signing an NDA.
Contact us