Build your future with us.

Enable continuous compliance with a unified, intelligent platform

Let's Discuss

Payments Bank

Client is a leading Payments Bank, empanelled vendors to provide services for VAPT, Secure Code Review and Configuration Review. The scope included IT Infrastructure and over 50 applications (web and mobile) servicing different portfolios

Problem Statement –

  • Client is a leading Payments Bank, empanelled vendors to provide services for VAPT, Secure Code Review and Configuration Review. The scope included IT Infrastructure and over 50 applications (web and mobile) servicing different portfolios.
  • The Bank engaged CyRAACS to conduct periodic assessments to identify vulnerabilities, provide recommendations for mitigation, assess and improve the security posture.

Services Delivered –

  • Developed a calendar for conducting VAPT, Secure Code Review and Configuration Review based on study of application and IT environment and the risk assessment
  • Conducted a comprehensive Vulnerability Assessment and Penetration testing for applications, servers, security devices and network devices against OWASP Top 10, SANS Top 25, WASC etc.
  • Conducted a Secure Code Review for applications and identified application security and business logic errors
  • Conducted a comprehensive Secure Configuration Review for servers, security devices and network devices against NIST
  • Conducted API Security Testing for APIs
  • Conducted assessment activities with custom inhouse scripts to identify issues and vulnerabilities
  • Conducted ad-hoc scans and testing for emergency releases and bug-fixes

Value Provided –

  • Worked as an Extended Security Arm to the Bank by overseeing the Vulnerability Management program
  • Provided real-time information on issues and vulnerabilities identified to Bank teams to ensure quicker remediation, remediation times decreased considerably during the engagement
  • Provided a detailed remediation plan for issues identified in VAPT, Secure Configuration Review, API Security Testing and Secure Code Review
  • Conducted briefing sessions on issues identified and recommendations provided to guide Bank internal teams
  • Improved security posture, reducing vulnerabilities significantly due to rigorous testing, educating the teams and incorporating best practices

Provided Visibility and Assurance to Senior Management and Regulators on the security posture

Let us help you

By click on this button you can connect with us. Let's make your brand secure.