Home All services
Start a project → Call Now

Bank security assessment case study

47 findings, 9 of them critical — and two we would not inflate.

A mid-sized bank needed an independent security assessment of its network, web applications and mobile app before a regulatory review. Until then, its only security checks had been automated scans run in house. We ranked every finding by how exposed it really was. Two issues had high scores on paper but could not be reached in the bank's setup, and our report said so instead of inflating them.

  • Network, web and mobile in one report
  • Fixes ranked by exposure, not raw score
  • Every fix retested
  • Security assessment
  • Remediation roadmap
  • Banking
Illustration: a sample remediation roadmap layout with 47 findings and 9 critical at the top, and placeholder rows ordered by exposure, each marked for a retest after its fix

In brief

The client
A mid-sized bank with a regulatory review coming up and only in-house scan results to show.
The problem
No independent assessment and no fix order. A general score can't say which findings matter in one bank's own setup.
The result
One independent report across network, web and mobile: 47 findings, 9 critical, fixes ranked by exposure, and every finding retested.

The challenge

Plenty of scan output, but no fix order.

Everything had to be covered in one engagement, and the results had to stand up in front of a regulator.

A scanner is good at spotting an outdated component or a missing security header, and it gives each finding a general score. That score can't say which findings matter most in one bank's own deployment, or which to fix first.

The bank had plenty of scanner output. What it lacked before the review was an independent assessment of every surface a customer touches, with findings its engineers could work through in order.

A wide scope and a scoring problem

  • Three surfaces at once. The network, the web applications and the mobile app were all in scope at the same time.
  • Nothing to compare against. There was no earlier independent assessment, only in-house scan results.
  • Scores without context. CVSS base scores (the standard way to rate a vulnerability's severity) describe a weakness in general. They say nothing about whether it can be reached in this bank's deployment.
  • A fix order, not a flat list. Engineers needed an order they could follow, not a list sorted by score.

What we did

Findings ranked by exposure, fixes retested.

We judged severity in the context of the bank's own environment, not by score alone.

One report, three surfaces

A single report covered the network, the web applications and the mobile app. The bank saw every surface a customer touches in one place, assessed by someone independent.

Severity set by real exposure

We rated each finding by how exposed it was as deployed. Two issues scored high on paper but could not be reached in this environment, and the report said exactly that.

A fix order, then a retest

A remediation roadmap (the ordered list of fixes) put the most exposed issues at the top, so engineers knew what to fix first. Once the fixes were in, we retested every finding.

The results

A report the bank could work through in order.

Ahead of its regulatory review, the bank had an independent assessment of all three surfaces and a fix order its engineers could follow. Figures are the client's own, as reported to us.

47
findings across network, web and mobile
9
rated critical
100%
of findings retested

What made it work

Why we did not pad the count.

An honest report is one engineers keep reading.

Nine of the 47 findings were rated critical. Two more issues looked high-severity by score, but nobody could reach them in the bank's deployment, and we said so plainly.

That matters more than it sounds. Engineers sent after problems that aren't there learn to skim security reports, and a skimmed report is how a real critical gets missed.

What changed for the bank

  • More than scan output. Scans were no longer the only evidence. The bank had an independent assessment, with every finding retested after its fix.
  • Engineering time well spent. The roadmap put reachable issues first, so engineering time went to what could actually be reached in the bank's deployment.

Related services

The work behind this project.

Start from the question closest to yours.

More case studies: the ISO 27001 certification program, the patient care management app and the hotel management platform. Or see every case study.

Let's talk

Facing a review with nothing but scan reports?

We confirm which findings are real, rank the fixes by what is exposed in your own deployment and check each fix once it is in. Tell us what is in scope and when the review is. We reply within one working day.