Annual security audit of a Cooperative Bank’s infrastructure and systems
A comprehensive annual security audit of a cooperative bank's critical infrastructure, banking application and email systems in light of DORA requirements.
Case study · IT Security
A year-long penetration testing cycle for critical infrastructure and web applications in a sprint model, aligned with DORA and OWASP, with official references.
ING Bank Śląski S.A. — one of the largest and most innovative financial institutions in Poland, serving millions of retail and corporate customers.
As an institution of public trust, the bank places the highest priority on data security, system stability and compliance with international security standards. In the face of growing cybercrime threats and new EU regulations (DORA), ING Bank Śląski partnered with Remote Admin to carry out comprehensive security testing. Before the engagement began, the bank needed to be certain it was entrusting its security to a partner with the highest standards — the initial vetting, conducted by two ING security departments, covered our procedures, data processing security and team qualifications.
Over the year-long engagement, the team proved highly effective at identifying threats that could have exposed the bank to financial or reputational losses. Critical and High vulnerabilities (per CVSS classification) were discovered, including potential unauthorized privilege escalation and access to sensitive data. All reported vulnerabilities were verified against the OWASP Top 10 most common web threats and banking-specific attack vectors. The bank achieved full OWASP-aligned testing and readiness for DORA’s digital operational resilience requirements set by supervisory authorities.
The project culminated in ING Bank Śląski issuing official references for Remote Admin, confirming the professionalism, timeliness and high technical quality of the audits performed.
Other projects
A comprehensive annual security audit of a cooperative bank's critical infrastructure, banking application and email systems in light of DORA requirements.
How Reconmore continuous vulnerability scanning supports developers: nearly 60 vulnerabilities found over 6 years with a software house building B2B apps.
Protecting a crypto platform from development flaws: 17 vulnerabilities found in month one and 24 months of continuous protection with the Reconmore scanner.