Case Study
May 26, 2021

FinTech and System Vulnerabilities

No items found.
elliott davis accounting resources

Table of Contents

Share with network

Related Insights

Most companies don't need a better budget. They need a planning systemMost companies don't need a better budget. They need a planning system

Most companies don't need a better budget. They need a planning system

Lorem ipsum dolor set

Understanding the Cash vs. Tax Carry Mismatch in Private Equity FundsUnderstanding the Cash vs. Tax Carry Mismatch in Private Equity Funds

Understanding the Cash vs. Tax Carry Mismatch in Private Equity Funds

Lorem ipsum dolor set

Your next CFO probably isn't looking for a jobYour next CFO probably isn't looking for a job

Your next CFO probably isn't looking for a job

Lorem ipsum dolor set

Managing state tax exposure for growing businesses: When to consider a voluntary disclosure agreement (VDA)Managing state tax exposure for growing businesses: When to consider a voluntary disclosure agreement (VDA)

Managing state tax exposure for growing businesses: When to consider a voluntary disclosure agreement (VDA)

Lorem ipsum dolor set

Trends in charitable giving: Tax advantages of partnership interest donationsTrends in charitable giving: Tax advantages of partnership interest donations

Trends in charitable giving: Tax advantages of partnership interest donations

Lorem ipsum dolor set

CEO and executive management asked Elliott Davis to help answer: “Would you help us identify areas of potential vulnerability within our systems?”

Context

  • A fintech company that makes philanthropy as easy as online banking
  • Needed to identify vulnerabilities and ensure on an ongoing basis that their web application and payment system cyber controls were consistently working.
  • Wanted an expert review and analysis of their current Disaster Recovery Plan (DRP)/Business Continuity Plan (BCP)

Our Approach

Penetration Testing:

  • Performed web application penetration test of payment system
  • Analyzed the web frontend infrastructure for any configuration issues
  • Completed detailed testing of application using custom tools, scripts, and methodology
  • Attempted to compromise backend database and systems

DRP/BCP Analysis:

  • Reviewed org charts, recovery plan structure, coordinator list, impact analysis, risk assessment, and training program
  • Reviewed critical DRP/BCP vendor contracts and attestation reports
  • Delivered report of observations and full-scale simulation test

Customer Results

  • Received report of security vulnerabilities and recommendations to improve the overall security
  • Penetration testing identified what an attacker could do in the ‘real world’
  • Developed understanding of current cyber risks associated with cyber-attacks, data breaches,   and other internal and external threats
  • Amended previous DRP/BCP plan to confirm corrective controls are in place to protect business

We Can Help

For more information on this and other topics, contact a member of our team.

The information provided in this communication is of a general nature and should not be considered professional advice. You should not act upon the information provided without obtaining specific professional advice. The information above is subject to change.

contact our team

contact our team

contact our team.