12-month penetration testing program for ING Bank Śląski
A year-long penetration testing cycle for critical infrastructure and web applications in a sprint model, aligned with DORA and OWASP, with official references.
Case study · IT Security
A comprehensive annual security audit of a cooperative bank's critical infrastructure, banking application and email systems in light of DORA requirements.
A Cooperative Bank — a pillar of the local financial system and a thriving institution that has earned the long-standing trust of individual customers and local businesses. In the age of digitalization, the bank focuses on modern access channels (online banking) while placing great emphasis on the security of entrusted funds and personal data.
The bank engaged Remote Admin to verify the robustness of its IT systems. The work aimed not only to eliminate the risk of attack but also to prepare the bank for new EU requirements under the DORA Regulation.
Over the year-long engagement, a number of weaknesses were identified that could have served as attack vectors for cybercriminals. In the application, High-severity input validation flaws were found that could lead to unauthorized access to customer data. In the infrastructure, outdated server software with publicly known exploits was identified (Critical findings). In email, gaps in the configuration of domain authentication records were found, which would make it easier for potential attackers to send fraudulent messages (phishing) impersonating the bank. Thanks to rapid reporting, the bank’s IT team steadily eliminated the threats, and re-tests confirmed 100% of fixes were effective. The bank’s management board achieved DORA compliance — the audit and testing were a key element in aligning with the Digital Operational Resilience Act — along with stronger infrastructure security and knowledge transfer: regular reports and consultations raised the client’s IT team’s awareness of modern attack vectors.
The engagement concluded with a letter of reference in which the Bank’s Management Board highlighted the Remote Admin team’s professionalism, flexibility and technical precision.
Other projects
A year-long penetration testing cycle for critical infrastructure and web applications in a sprint model, aligned with DORA and OWASP, with official references.
How Reconmore continuous vulnerability scanning supports developers: nearly 60 vulnerabilities found over 6 years with a software house building B2B apps.
Protecting a crypto platform from development flaws: 17 vulnerabilities found in month one and 24 months of continuous protection with the Reconmore scanner.