Comprehensive audit for a bank with 150,000 clients

1. Situation

The client is a banking institution with over 150,000 clients, 540 employees, and 50 offices across Spain, handling a business volume of 6 billion euros.

An external company had developed an application for managing online banking, and a thorough analysis was requested to identify vulnerabilities that could compromise the systems.

2. Problem

The application required a deep evaluation to identify weaknesses, including pentesting, denial of service, cross-site scripting, data validation, and communication security.

3. Solution

A black-box audit was conducted on two access points provided by the client. The tests included:

  • Pentesting and denial-of-service tests.
  • Data validation and cross-site scripting tests.
  • Evaluation of communication security.

4. Results

A report was delivered evaluating the vulnerabilities found using the CVSS scoring system, classifying the severity of each and providing specific recommendations such as patches or configuration adjustments.

After implementing the proposed solutions, additional tests verified that all issues were resolved, ensuring the system was secured.

Optimize security and minimize risks in your financial systems.

Audit Coverage

Vulnerability Reduction