DORA compliance audit for an institution of national importance
Audit planning and delivery: ICT risk, incidents, resilience testing and third-party risk — under strict confidentiality.
Case study · Audit
Crypto-asset security with MiCA and DORA compliance: exchange app pentests, Pentest as a Service, Hybrid Vulnerability Scanner and a MiCA RTS audit.
Kanga Exchange — one of the leaders of the cryptocurrency market, operating a crypto exchange and a network of brick-and-mortar exchange offices. Kanga Exchange is growing rapidly, offering a wide range of FinTech services in an environment where transactions are irreversible and the risk of hacker attacks is as high as it gets.
Kanga takes an uncompromising approach to protecting user funds and platform stability. The goal of the engagement was to thoroughly verify the security of the entire ecosystem ahead of tightening EU regulatory requirements (MiCA), and then to move from one-off testing to continuous security monitoring and hybrid vulnerability scanning.
The engagement delivered measurable benefits critical to the stability of a blockchain-based financial institution. Asset protection: eliminating critical vulnerabilities in the exchange’s business logic protected the platform from potential financial losses. Regulatory readiness (MiCA / DORA): the audit provided a roadmap for aligning systems with the rigorous EU requirements for crypto-asset service providers (CASPs). Continuous monitoring: moving to a continuous scanning model cut the mean time to detect new vulnerabilities (MTTD) from weeks to hours.
The partnership with Kanga Exchange has been exemplary. After completing the first phase and implementing the fixes, the client issued references for Remote Admin, recognizing our expert support on blockchain specifics and our flexible approach to the platform’s rapid growth.
Other projects
Audit planning and delivery: ICT risk, incidents, resilience testing and third-party risk — under strict confidentiality.
A complete set of answers and evidence for the ICT vendor questionnaire: policies, procedures and records required under banking outsourcing rules.
A year-long penetration testing cycle for critical infrastructure and web applications in a sprint model, aligned with DORA and OWASP, with official references.