Penetration test for an insurance company
External, cloud and wireless assessment for a Luxembourg-based non-life insurance company.
Colonnade is a Luxembourg-based non-life insurance company fully owned by Fairfax and established for a strategic expansion of the Fairfax insurance business in Central & Eastern Europe. It has over 450 employees, with a premium income exceeding 160 million euros.
Colonnade operates through branches in Ukraine, the Czech Republic, Slovakia, Hungary, Poland, Romania, and Bulgaria.
Financial companies are always subject to regulations from national governments within their operating markets and to international industry standards. Conducting regular penetration tests is a mandatory procedure for Colonnade to confirm that client data is protected.
An External & Cloud Pentest was performed, including Wireless infrastructure assessment.
Additionally, a phishing campaign — as an element of social engineering attacks — was carried out against the customer's employees to test the company's cybersecurity protection.
Our pentesting methodology is based on leading standards — PTES, NIST SP 800-115, OSSTMM, OWASP — and improved by our own 15 years of experience.
During pentesting, a full set of common pentester tools was used — but the main key to success was manual analysis: interconnecting individual vulnerability exploitation results to escalate privileges and demonstrate practical IT-infrastructure compromise.
The cybersecurity assessment focused Colonnade IT staff's attention on the most critical risks and options for compromising the network perimeter, providing a detailed Technical Report with recommendations for handling the identified risks.
The Executive Report — as the main element — contains recommendations for improving the Information Security Management System: namely, processes and procedures whose implementation will prevent the occurrence of such vulnerabilities in the future.
More case studies
View allSt. Paraskeva Medical Center
IT infrastructure, management and cybersecurity audit for a leading Ukrainian healthcare provider.
Read case studyDanone
Multiple penetration testing engagements for a global food & beverage company operating in 120+ markets.
Read case studyEldorado
Complex testing of network, applications and employees for a Ukrainian electronics retailer.
Read case studyHave a similar
challenge in mind?
We'll scope a senior-led penetration test against your specific environment — and deliver Technical, Executive and Action-plan reports that translate findings into business decisions.
- Reply within one business day
- NDA on request — no obligation
- Speak directly with our Head of OffSec
- Tailored scope & clear pricing