The situation.
A research supplier with an existing codebase and an outside development team asked us to look at what they had before they built more on top of it.
The constraint.
The code was in production and serving customers. The assessment had to be authorized in writing, scoped so it could not disrupt the business, and delivered in a form the existing developers could act on without us standing over them.
What we found.
Forty-one findings, including database credentials exposed in the codebase and issues across the application's security boundaries. Several were the kind that become a breach on a quiet weekend.
What we built.
A written report, generated from our findings, with each issue rated by severity, explained in terms of what could actually happen, and paired with a specific fix. Ordered so the developers could start at the top and work down.
What changed.
The client's developers received a prioritized remediation list they could work from. The client now knows what they are running and where to focus first.
- 41 findings
- written report, prioritized
- authorized assessment
Related work
If this sounds like your operation, apply to work with us.
Apply