Home/Case studies/Cooperative banking

Case study · IT Security

Annual security audit of a Cooperative Bank’s infrastructure and systems

A comprehensive annual security audit of a cooperative bank's critical infrastructure, banking application and email systems in light of DORA requirements.

DORACooperative banking

Client

A Cooperative Bank — a pillar of the local financial system and a thriving institution that has earned the long-standing trust of individual customers and local businesses. In the age of digitalization, the bank focuses on modern access channels (online banking) while placing great emphasis on the security of entrusted funds and personal data.

Challenge

The bank engaged Remote Admin to verify the robustness of its IT systems. The work aimed not only to eliminate the risk of attack but also to prepare the bank for new EU requirements under the DORA Regulation.

Scope of work

  • An annual cycle of penetration testing of critical infrastructure, banking systems and mail servers
  • Banking application: verification against the OWASP Top 10 standard, business logic, user session and API testing
  • Server infrastructure: scanning and manual verification of publicly accessible servers, firewalls and network services for known vulnerabilities (CVEs) and misconfigurations
  • Email system: security analysis of mail servers, verification of protections against spoofing of the bank’s domain (SPF, DKIM, DMARC) and resilience testing
  • Black-box methodology — simulating an external attack with no knowledge of the configuration, best reflecting real threats from the internet

How the engagement worked

3-month cycleThe project runs annually over 3 months — recurring verification instead of a one-off audit.
Weekly sprintsFindings reported in short, regular cycles — the bank’s IT team received results on an ongoing basis, not only after the work was finished.
RemediationAfter the bank’s IT department deployed fixes, Remote Admin specialists carried out re-verification.
Re-testsEvery vulnerability was re-checked to confirm it had been effectively closed — 100% of fixes confirmed effective.

Results and value for the client

Over the year-long engagement, a number of weaknesses were identified that could have served as attack vectors for cybercriminals. In the application, High-severity input validation flaws were found that could lead to unauthorized access to customer data. In the infrastructure, outdated server software with publicly known exploits was identified (Critical findings). In email, gaps in the configuration of domain authentication records were found, which would make it easier for potential attackers to send fraudulent messages (phishing) impersonating the bank. Thanks to rapid reporting, the bank’s IT team steadily eliminated the threats, and re-tests confirmed 100% of fixes were effective. The bank’s management board achieved DORA compliance — the audit and testing were a key element in aligning with the Digital Operational Resilience Act — along with stronger infrastructure security and knowledge transfer: regular reports and consultations raised the client’s IT team’s awareness of modern attack vectors.

The engagement concluded with a letter of reference in which the Bank’s Management Board highlighted the Remote Admin team’s professionalism, flexibility and technical precision.

Other projects

See more case studies

All projects →
IT SecurityBanking · ING Bank Śląski S.A.

12-month penetration testing program for ING Bank Śląski

A year-long penetration testing cycle for critical infrastructure and web applications in a sprint model, aligned with DORA and OWASP, with official references.

12 monthscontinuous program
OWASPASVS · black-box
Read the case study →
IT SecuritySoftware House · B2B applications

Securing the software development lifecycle (SDLC) with the Reconmore scanner

How Reconmore continuous vulnerability scanning supports developers: nearly 60 vulnerabilities found over 6 years with a software house building B2B apps.

~60vulnerabilities found
6 yearsof ongoing cooperation
Read the case study →
IT SecurityFinTech · cryptocurrency exchange

Deploying the Reconmore scanner at a cryptocurrency exchange

Protecting a crypto platform from development flaws: 17 vulnerabilities found in month one and 24 months of continuous protection with the Reconmore scanner.

17vulnerabilities found in the first month
24 monthsof continuous protection
Read the case study →