Once a year wasn’t going to cut it
At OSec it’s not unusual to work with financial-services companies to determine the risk posed by adversaries. A recent engagement with FNZ — a global wealth-management platform managing around $1.4 trillion in assets — proved the value of continuous penetration testing. Traditionally, pen testing happens once a year, or as a point-in-time exercise. FNZ opted instead for the ongoing assessment its Incenter platform provides, which is considered a game-changer in the industry.
A client’s gate, cleared in a day
FNZ runs Incenter continuously against its own platform, and the always-on setup also proved its worth outward. One of FNZ’s clients had made an independent security attestation a contractual condition of taking an application live: the application couldn’t ship until it passed a clean test. FNZ had to produce that attestation on a tight deadline, and a traditional pen test would take weeks. Because Incenter was already running, OSec added the application to the platform within 24 hours, with remediation guidance almost immediately; everything was in scope within a couple of days, and the final findings were delivered.
“Incenter is a total game changer in the market. There are only a handful of companies doing continuous pen testing, but OSec’s model is completely different from anything I’ve seen.”
A $2M penalty that never landed
The exposure sat with FNZ. Miss the deadline and it couldn’t clear the client’s security gate, the application wouldn’t go live as agreed, and FNZ’s contract carried a $2 million penalty if that happened. Instead the attestation cleared on time, the required level of security was confirmed, and the penalty never landed. Any firm whose customers make a security sign-off a condition of doing business faces the same clock, and the same exposure when testing can’t keep up.
It’s evidence of a shift in the industry: organizations need an ongoing view of threats and vulnerabilities. OSec noted that paradigm shift and built Incenter for it — transitioning from traditional point-in-time pen tests to continuous security assessment, averting crises before they can even arise.