Outcome

Assurance Testing: Penetration Retest

European bank

“Resolved” is one of the most dangerous words in a remediation report. It can mean a vulnerability is genuinely fixed and verified, or simply that someone closed the ticket. For anyone relying on that report, the difference is everything.

This client, a European bank, had completed a security assessment and a round of fixes, and needed independent proof that the vulnerabilities were actually closed, not just marked resolved internally. The stakes were external: the sign-off would feed directly into investor and regulatory confidence, where a self-assessment carries little weight.

The approach

KASP scoped a focused, three-day retest of all 17 previously identified vulnerabilities across the bank’s customer-facing web portal. We tested at admin, merchant, and customer privilege levels, deliberately using the same methodology as the original assessment so the results were directly comparable: a like-for-like verdict rather than a fresh, unrelated opinion.

Why independence mattered

The retest itself was straightforward. Its value was in who performed it. A board, an investor, or a regulator can place far more trust in a verdict from an independent party than in an “all fixed” from the same internal team that built the remediation. Independence is not a nicety here; it is the entire point of the exercise.

By confirming, vulnerability by vulnerability, what had genuinely been resolved, and holding the result to the original standard, KASP gave the bank something it could put in front of the people who mattered: proof rather than assurance.


Start a conversation

Book a Consultation