Home/Case studies/ING Bank Śląski S.A.

Case study · IT Security

12-month penetration testing program for ING Bank Śląski

A year-long penetration testing cycle for critical infrastructure and web applications in a sprint model, aligned with DORA and OWASP, with official references.

DORA · OWASPBanking

Client

ING Bank Śląski S.A. — one of the largest and most innovative financial institutions in Poland, serving millions of retail and corporate customers.

Challenge

As an institution of public trust, the bank places the highest priority on data security, system stability and compliance with international security standards. In the face of growing cybercrime threats and new EU regulations (DORA), ING Bank Śląski partnered with Remote Admin to carry out comprehensive security testing. Before the engagement began, the bank needed to be certain it was entrusting its security to a partner with the highest standards — the initial vetting, conducted by two ING security departments, covered our procedures, data processing security and team qualifications.

Scope of work

  • The project covered a year-long cycle of penetration testing of critical infrastructure and web applications
  • Black-box methodology: without specialist knowledge of the internal code and infrastructure — simulating the actions of external cybercriminals
  • Verification against the OWASP Top 10 most common web threats and banking-specific attack vectors
  • Compliance with the OWASP Application Security Verification Standard (ASVS) and the requirements of the Digital Operational Resilience Act
  • Assessment of procedures, data processing security and team qualifications

How the engagement worked

Vendor vettingBefore testing began, ING verified our procedures, data security and expertise — the vendor audit was conducted by two of the bank’s security departments.
Weekly sprintsInstead of a one-off audit — a “Continuous Security Testing” model: reporting took place in weekly cycles, allowing the bank’s development team to review discovered vulnerabilities on an ongoing basis.
Remediation and re-testsRemote Admin reported a flaw, the ING team deployed a security fix, and our engineers performed a penetration re-test to confirm the patch was effective.
ReferencesAfter 12 months, the program concluded with a number of Critical and High vulnerabilities identified and eliminated, and with official references from ING Bank Śląski for Remote Admin.

Results and value for the client

Over the year-long engagement, the team proved highly effective at identifying threats that could have exposed the bank to financial or reputational losses. Critical and High vulnerabilities (per CVSS classification) were discovered, including potential unauthorized privilege escalation and access to sensitive data. All reported vulnerabilities were verified against the OWASP Top 10 most common web threats and banking-specific attack vectors. The bank achieved full OWASP-aligned testing and readiness for DORA’s digital operational resilience requirements set by supervisory authorities.

The project culminated in ING Bank Śląski issuing official references for Remote Admin, confirming the professionalism, timeliness and high technical quality of the audits performed.

Other projects

See more case studies

All projects →
IT SecurityCooperative banking

Annual security audit of a Cooperative Bank’s infrastructure and systems

A comprehensive annual security audit of a cooperative bank's critical infrastructure, banking application and email systems in light of DORA requirements.

3 monthstesting cycle
100%fix effectiveness in re-tests
Read the case study →
IT SecuritySoftware House · B2B applications

Securing the software development lifecycle (SDLC) with the Reconmore scanner

How Reconmore continuous vulnerability scanning supports developers: nearly 60 vulnerabilities found over 6 years with a software house building B2B apps.

~60vulnerabilities found
6 yearsof ongoing cooperation
Read the case study →
IT SecurityFinTech · cryptocurrency exchange

Deploying the Reconmore scanner at a cryptocurrency exchange

Protecting a crypto platform from development flaws: 17 vulnerabilities found in month one and 24 months of continuous protection with the Reconmore scanner.

17vulnerabilities found in the first month
24 monthsof continuous protection
Read the case study →