Casestudy

Our latest case studies

Casestudy
How We Secured a Cloud Service Provider’s Network in 5 Days
Executive Summary To better serve clients and maintain trust, an IT/Cloud Engineering Service Provider sought to enhance the security of its network infrastructure to better serve its clients and users. A thorough Vulnerability Assessment and Penetration Testing (VAPT) was conducted,...
Casestudy
Firewall Rule Review for a Research Organization
Executive Summary A firewall rule review was conducted for a large academic and research institution to assess potential security vulnerabilities and performance inefficiencies in its network security configurations. The evaluation revealed broad and outdated firewall rules, disabled security features, and...
Casestudy
Misconfigured EC2 Instance Leads to SSH Brute Force Breach
Overview A mid-sized SaaS company deployed a cloud server (EC2 instance) to support internal development activities. However, due to a misconfigured security group, Secure Shell (SSH) access was left exposed to the entire internet. This oversight allowed attackers to launch...
Casestudy
The Supply Chain Attack on a Tech Company
Background A leading software company that provides enterprise cloud solutions faced a supply chain attack where malicious code was injected into one of its software updates. The company’s Security Operations Center (SOC) detected anomalous behaviour in customer environments, indicating a...
Casestudy
Privilege Escalation via Overly Permissive IAM Roles
Background A cloud-native SaaS provider hosting its core applications and customer data on AWS had embraced automation through extensive use of Identity and Access Management (IAM) roles. These roles were used to facilitate deployment processes, grant temporary access, and support...
Casestudy
Ransomware Attack on a Financial Institution
Background A mid-sized financial institution with over 500 employees experienced a sophisticated ransomware attack. The organization had a well-established Security Operations Center (SOC) that monitored and responded to cyber threats in real time. Incident Summary One morning, employees reported being...

Explore our blogs

Which Compliance Standards Require Penetration Testing?
Which Compliance Standards Require Penetration Testing?
Not every compliance framework treats penetration testing the same way. Some name it explicitly and set a strict schedule. Others imply it through a broader control requirement and leave the frequency to your auditor's judgement. Knowing which is which before you scope an engagement saves you from either under-testing and failing an audit, or over-testing and spending on evidence nobody...
10 Questions to Ask Before Hiring a Pentest Company
10 Questions to Ask Before Hiring a Pentest Company
Most penetration testing quotes look identical on paper: a scope, a timeline, a price. The difference between a vendor who finds the vulnerability a real attacker would use and one who hands you a scanner printout with a logo on it only shows up in how they answer questions before you sign anything. Three questions expose weak vendors fastest: whether...