Get a free audit

Case studies · United Kingdom

Engagements, as they ran.

What the client asked us to find, what we actually found, and what changed afterwards. Named where the client allowed it, anonymised where they did not. Nothing here is a composite.

ClientPeople Dynamics Inc
SectorCognitive and psychological assessment for enterprise HR
EngagementVulnerability assessment and penetration test (VAPT)
WhereManila, Philippines

This test found a problem before it became one.

Why they tested

A growing share of their client base sits in finance and banking, and those clients raised what they demanded of a supplier holding candidate data. An ISM certification became the requirement, and for a bank’s third-party risk team to accept it, it had to rest on independent testing. Data privacy rules were being sharpened at the same time, locally and globally.

The finding that mattered

The platform was running on a PHP version approaching the end of its supported life. There was no live vulnerability to report on the day. The risk was dated: once a runtime stops receiving security patches, the next CVE published against it has nowhere to be fixed.

What changed

They upgraded before that date rather than after an advisory forced it. The certification went through with independent testing behind it, and People Dynamics retained Red Team Partners for an annual re-test, because an expiry date only surfaces when somebody looks on a schedule.

Operationally, I would recommend Red Team. Their reporting was easy to interpret and the steps, the procedures and the whole process was very straightforward.
Malvinn Mendoza Quality Assurance and Compliance Director, People Dynamics Inc

This was a vulnerability assessment and penetration test. The assessment half is what surfaced the runtime date; the test half is what proved nothing else was reachable.

More engagements

Anonymised at the client’s request

Sector and city are accurate. Security buyers rarely let their name sit on a page describing how someone got in, which is the correct instinct.

White-label penetration testing

We put our name on the report and the client never knew RTP existed. Same calibre of work we used to buy from a tier-one firm, at a wholesale price that left us a real margin. We kept the account and the relationship.

Founder IT consultancy · London

Red team assessment

They found a path into our payments stack inside the first day and walked us through it in plain language. The report went to our board and our regulator without a rewrite.

Head of Information Security Digital bank · Singapore

Continuous penetration testing

The re-tests are what sold it internally. One engagement, a year of proof, and nothing goes stale between annual reports.

Managing Director Managed security provider · Zürich

A security lead lit in red, looking to camera.

Find out what yours would say.
Start with the free audit.

We map what your organisation exposes to the internet and send back the routes in, ranked by what each one reaches. You keep the list and the fixes, whether or not we do the work.