ShadowSec Lab

Financial services · Kestrel Capital

External pentest for a regulated investment platform

Annual external test covering internet-facing applications, VPN, and mail. Two high findings: a forgotten staging host with production LDAP, and an SSO bypass on a legacy reporting portal. Both were off the internet before the final report.

  • Attack surface reduced by decommissioning shadow IT
  • SSO coverage extended to remaining legacy apps
  • Three-year testing program put in place
Start a similar engagement
Samir Haddad, CISO
Quiet, precise, no theatrics. Our audit committee actually read the executive letter.

Samir Haddad, CISO

Next step

Tell us what you need answered.

A 30-minute scoping call is enough to know whether a pentest, a cloud review, or a retainer is the right buy. We will say if it is not.