Penetration Testing
Manual testing of web applications, APIs, mobile apps, infrastructure and cloud that goes where a scanner can’t.
Industry
SBS and PCI DSS requirements, digital fraud and exposed APIs. We assess your risk through an attacker’s eyes.
The context
Mobile banking, instant payments, digital wallets and APIs open to third parties have transformed how people use financial services. Every new channel is also a new attack surface.
Entities supervised by Peru’s SBS must demonstrate cybersecurity management in line with SBS Resolution No. 504-2021, and those who process cards must comply with PCI DSS. Fintechs, meanwhile, grow fast with small teams and must earn the trust of customers, partners and regulators.
We assess your channels through an attacker’s eyes and provide technical evidence that helps both reduce risk and respond to auditors and regulators.
Key threats
We focus on the scenarios that translate into financial losses, penalties and loss of trust.
Account takeover, abuse of transaction logic and automated attacks against apps and online banking.
Third-party integrations, open banking and mobile services with authorization flaws that expose other customers’ data.
Fake sites, messages and calls targeting customers and employees to steal credentials or authorize transactions.
System encryption combined with the threat of leaking customer data to pressure payment.
Core banking, cloud, payment processor and fintech partners with access to your systems or data.
Misuse of privileged access by internal or third-party staff, whether intentional or accidental.
Regulation and frameworks
Regulation for information security and cybersecurity management for companies supervised by Peru’s SBS.
Mandatory standard for anyone who stores, processes or transmits payment card data.
An internationally recognized information security management system.
A framework to govern cybersecurity risk and communicate it to the board.
Security controls of the SWIFT program for entities connected to its network.
Protection of your customers’ and employees’ personal data under Peruvian law.
How we help
We test your channels like an attacker would and help you prove your controls work.
Manual testing of web applications, APIs, mobile apps, infrastructure and cloud that goes where a scanner can’t.
Human-led adversary exercises that test whether your organization detects and contains a real attack, with tactics mapped to MITRE ATT&CK.
We prepare your organization for ISO 27001, SBS Resolution No. 504-2021, PCI DSS and Law No. 29733, with controls that work in practice.
We find vulnerabilities in your code before they reach production, in any language.
Controlled phishing, vishing and malicious QR campaigns that measure the human factor and turn it into a line of defense.
We design and run your responsible disclosure and bug bounty program with our own community of researchers.
Frequently asked questions
Yes. We structure our reports to serve as evidence of cybersecurity control assessments for internal and external auditors and regulators.
Yes. We work in staging environments equivalent to production or in agreed windows, using controlled techniques and no real customer transactions.
Yes. We tailor the scope to your stage: from a first test of your app and APIs to an ongoing security program.
Yes. We perform the penetration tests the standard requires, help define the cardholder data environment scope and support your assessment readiness.
Yes. We test object- and function-level authorization, data exposure and logic abuse, following the OWASP API Security Top 10.
Other industries
Digital citizen services, personal data and legacy systems. We help public entities protect them.
Remote operations, critical OT assets and extended supply chains. We protect production continuity.
Tell us about your objectives and constraints. We will send you a proposal with scope, rules of engagement, timeline and deliverables.