Results
The tests strengthened platform security and exposed an industry critical vulnerability disclosure.
A telecom provider needed to secure a new cloud analytics platform handling sensitive data.
We ran focused penetration tests, uncovering a critical zero-day vulnerability.
A major European telecommunications and IT services provider wanted to launch a new cloud-based platform to centralise all business analytics, including sensitive data such as call detail records and retail transaction histories. Because the platform was strategically important and handled critical data, the company made security its top priority.
Security was a top priority because of the platform’s critical role and the sensitivity of the data it would handle. To protect its strategic digital assets before launch, the company developed a comprehensive testing program involving multiple security providers.
Demonstrating the company’s confidence in our expertise, our penetration testing team was selected to evaluate the most complex and high-risk components, including authentication flows, data pipelines and role-based access controls.
While carrying out what was expected to be a routine security assessment on a platform used by call centre agents to provide remote technical support, our penetration testing team quickly revealed a high-risk, zero-day vulnerability within an hour, in a widely deployed third-party product.
The software in question is produced by a well-known security vendor, increasing the significance of the finding. The vulnerability was discovered within hours of testing, immediately disclosed to the software provider, and remediation efforts are now underway.
This discovery highlights the importance of third-party risk assessments, even for systems built by security-focused vendors. Our testing team is currently applying for a CVE (Common Vulnerabilities and Exposures) listing to ensure the issue is properly documented and recognised.
Within hours of conducting the pen tests our team identified a severe vulnerability, enabling rapid mitigation and preventing broader impact. By pursuing a CVE for the issue, we also contributed to wider cyber security awareness. This shows how expert-led pen testing can uncover critical risks, validate resilience and strengthen the security posture of high-value digital platforms.
Powering your standard security testing with results within 24 hours.
The Vital Importance of Regular Pen Testing and Vulnerability Scanning