The stakes at $2.5B a day
A leading financial brokerage, 5,000 employees processing more than $2.5 billion in daily transactions across multiple asset classes, served thousands of professional traders who needed fast execution they could trust. Leadership asked OSec for a full-scope assessment: test the trading platform and the systems around it, and find what an attacker could reach before one did. At that scale and speed, security is existential.
“In the world of high-frequency trading, security can’t be an afterthought — it must be woven into every microsecond of every transaction.”
What we tested
The work modelled the way real attackers go after a trading firm, from criminal groups to state-backed teams, across three areas:
- Red team. Testers worked the platform end to end the way an intruder would, chaining small weaknesses into real access rather than reporting them one at a time.
- Application security. Deep testing from the API endpoints through the data-validation logic and into the application code, where the logic flaws a scanner skips tend to live.
- Human factor. Phishing simulations against staff, to find the gaps technical controls cannot close.
What the testing found
The test did not stop at a list of bugs. Testers chained weaknesses together into working attack paths, and the worst of them reached the heart of the business.
On the main trading platform and its supporting systems, testers reached full administrator access, and from there demonstrated the ability to modify trades. In total the engagement surfaced 11 high-risk exploit chains and a further 43 high-risk vulnerabilities, each documented with the path that led to it.
What changed
The findings drove a round of hardening:
- Continuous security validation. Automated testing pipelines that keep probing for exposures in production, not just at audit time.
- Multi-factor authentication overhaul. Token-based verification that removed the single points of failure the testers had leaned on.
- Monitoring improvements. Detection tuned to catch the kind of chained attack that walks past default configurations.
The response went past the technical fixes. It prompted a governance-level review of the firm’s security posture, moving the question up from individual bugs to how risk was owned and managed across the business. OSec then ran follow-up purple team exercises alongside the defenders, to confirm the fixes held and to find and close the gaps that only surface once you go looking again.
Where it landed
The next round of assessments told a clear story: the firm’s posture had improved considerably against the earlier baseline, and no incidents had occurred in the interim.