Skip to main content
Ensuring a Comprehensive Security Program Through Testing With Local Government

About the Client

The client is a top bank in the Midwest that provides various products and services in consumer finance.

Objectives

RedTeam Security was engaged to perform a comprehensive, offensive security campaign against the client's external facing IPs and web applications, internal network, employees, and physical locations to assess their overall risks and identify areas where they need to focus additional resources. This testing assessed the effectiveness of their employee training and physical and technical protections.

Findings

Several potentially serious technical vulnerabilities were identified, and RedTeam Security worked with the client's management and technical staff to quantify the potential impact to the organization, develop a remediation plan, and later perform retesting of remediated findings. In addition, areas to focus on for additional employee training were identified, and additional physical protections and procedure changes were implemented.

Takeaways

After the engagement, the client used their project reports, which outlined findings, to immediately implement the suggested remediation efforts, resulting in an empowered team with a much more robust physical and technical security perimeter. Every engagement with RedTeam Security provides clients with:

  • A clear understanding of the effectiveness of their existing information security program, training, monitoring, and system updating to keep things current.
  • How well their vendors manage the security posture of networks and web applications (for those with a 3rd party IT vendor).
  • A statement of assurance to provide to their customers that they are doing everything they should to keep their data and systems secure.

All identifying information has been changed to protect our clients and ensure absolute confidentiality.

Hear What Our Clients Are Saying

  • Friendly, Professional, and Knowledgeable
    "Saint Paul College hired Red Team consultants to perform Web Applications vulnerability scanning and assessment. It was one of best group of people I worked with - from beginning to the end. Everyone I worked with was extremely cooperative, friendly, professional, and knowledgeable. They understand IT security very well. They worked around our schedules, were available when we needed them, and always on time. My staff and I thoroughly enjoyed our relationship with them. The consultants were focused/committed, pointed out the vulnerabilities and worked with my team to remediate them. Red Team also gave us detailed report about each web application. In all, it was a great experience working with Red Team and we will not hesitate to hire them again if needed.

    -Najam Saeed, CIO, Saint Paul College, Saint Paul, MN

  • Reliable and Consistent Communication
    "I hired RedTeam to do both a Network Penetration test and a Social Engineering test on my organization. From start to finish in building our relationship and contract plan all the way through the execution of both of our tests they were helpful, insightful, proactive in reaching out to me, and thorough in their follow up. During the tests I was in constant contact with their testers, getting results as they discovered them along with the full and detailed report afterwards. They not only found my issues, but gave me a very helpful and detailed guide to remedy the issues afterwards. I am going to continue my relationship with them. If you are looking for network testing I cannot recommend them enough."

    -Trevor Keller

  • Highly Skilled Team
    "Contacted RedTeam to do a penetration test. I was very impressed with their ability to perform, not only from a vulnerability analysis, but true "Pen" test to identify REAL risks. Was very impressed with their highly skilled people and resources."

    -Donald Schleede