Telecom · Mobile

Penetration testing for a global mobile operator

End-to-end pentest of a freshly-built corporate IT environment supporting 160 million customers across six countries.

Industry
Telecom
Customers
~160 million
Markets
6 countries
Scenarios
12 exploitation chains

VEON is a mobile operator providing converged connectivity and online services to around 160 million customers across six countries — over 7% of the world's population.

VEON opened a new large office in Lviv to support finance, procurement and HR operations across Ukraine, Armenia, Georgia, Kazakhstan, Kyrgyzstan, Tajikistan and Uzbekistan. Implementing the entire IT infrastructure from scratch accompanied the new office launch.

Therefore, immediately after IT-services implementation, it was necessary to check the security of all components and eliminate vulnerabilities to prevent compromise.

XRAY CyberSecurity conducted a penetration test to assess the IT-infrastructure, eliminate cyber threats and address risks. The scope included external, internal, cloud networks and office wireless.

Several attacker types were modelled: Blackbox — without info or accounts; Greybox — using three user account types within the infrastructure (different department employees).

ExternalInternalCloudWirelessBlackbox · Greybox

Our pentesting methodology is based on leading standards — PTES, NIST SP 800-115, OSSTMM, OWASP.

PTESNIST SP 800-115OSSTMMOWASP

During pentesting, a full set of common pentester tools was used — but the main key to success was manual analysis: interconnecting individual vulnerability exploitation results to escalate privileges and demonstrate practical IT-infrastructure compromise.

Twelve exploitation scenarios were implemented. For each attacker model, the ability to compromise IT infrastructure was demonstrated.

  • Technical recommendationsFocused on eliminating vulnerabilities and architectural improvements for increased security.
  • Executive recommendationsFocused on processes and procedures of the Information Security Management System for maintaining high protection.

An Action plan was developed to help the client prioritise and evaluate resources required to address identified security gaps.

Move forward with confidence

Have a similar
challenge in mind?

We'll scope a senior-led penetration test against your specific environment — and deliver Technical, Executive and Action-plan reports that translate findings into business decisions.

  • Reply within one business day
  • NDA on request — no obligation
  • Speak directly with our Head of OffSec
  • Tailored scope & clear pricing

Tell us about your project

We'll get back within one business day.