Penetration testing for a global mobile operator
End-to-end pentest of a freshly-built corporate IT environment supporting 160 million customers across six countries.
VEON is a mobile operator providing converged connectivity and online services to around 160 million customers across six countries — over 7% of the world's population.
VEON opened a new large office in Lviv to support finance, procurement and HR operations across Ukraine, Armenia, Georgia, Kazakhstan, Kyrgyzstan, Tajikistan and Uzbekistan. Implementing the entire IT infrastructure from scratch accompanied the new office launch.
Therefore, immediately after IT-services implementation, it was necessary to check the security of all components and eliminate vulnerabilities to prevent compromise.
XRAY CyberSecurity conducted a penetration test to assess the IT-infrastructure, eliminate cyber threats and address risks. The scope included external, internal, cloud networks and office wireless.
Several attacker types were modelled: Blackbox — without info or accounts; Greybox — using three user account types within the infrastructure (different department employees).
Our pentesting methodology is based on leading standards — PTES, NIST SP 800-115, OSSTMM, OWASP.
During pentesting, a full set of common pentester tools was used — but the main key to success was manual analysis: interconnecting individual vulnerability exploitation results to escalate privileges and demonstrate practical IT-infrastructure compromise.
Twelve exploitation scenarios were implemented. For each attacker model, the ability to compromise IT infrastructure was demonstrated.
- Technical recommendationsFocused on eliminating vulnerabilities and architectural improvements for increased security.
- Executive recommendationsFocused on processes and procedures of the Information Security Management System for maintaining high protection.
An Action plan was developed to help the client prioritise and evaluate resources required to address identified security gaps.
More case studies
View allCarlsberg
A decade of pentesting partnership with one of the world's leading brewery groups.
Read case studyDanone
Multiple penetration testing engagements for a global food & beverage company.
Read case studyZeppelin
Long-term recurring Blackbox/Greybox/Whitebox pentesting across external, internal and wireless networks.
Read case studyHave a similar
challenge in mind?
We'll scope a senior-led penetration test against your specific environment — and deliver Technical, Executive and Action-plan reports that translate findings into business decisions.
- Reply within one business day
- NDA on request — no obligation
- Speak directly with our Head of OffSec
- Tailored scope & clear pricing