Financial services · Kestrel Capital
External pentest for a regulated investment platform
Annual external test covering internet-facing applications, VPN, and mail. Two high findings: a forgotten staging host with production LDAP, and an SSO bypass on a legacy reporting portal. Both were off the internet before the final report.
- Attack surface reduced by decommissioning shadow IT
- SSO coverage extended to remaining legacy apps
- Three-year testing program put in place

“Quiet, precise, no theatrics. Our audit committee actually read the executive letter.”
Samir Haddad, CISO
Next step
Tell us what you need answered.
A 30-minute scoping call is enough to know whether a pentest, a cloud review, or a retainer is the right buy. We will say if it is not.
