Blueprint

Penetration testing for a mid-sized financial services firm

How we scope, run and report a penetration test for a 250-person broker or insurer, and turn the findings into a 90-day remediation plan.

The scenario

This blueprint describes how FOXMINDS plans and runs a penetration test for a typical mid-sized financial services firm in Lebanon or the Gulf: a broker, insurer or microfinance company with about 250 employees, a head office and four branches.

  • Microsoft 365 for email and Teams, with on-premises Active Directory synchronized to Entra ID
  • Core systems on a VMware cluster: core financial application, SQL Server, file shares
  • A client web portal and a mobile app backed by REST APIs
  • Site-to-site VPN to the branches, remote-access VPN for staff, guest Wi-Fi

Management wants to know one thing: could an attacker reach client data or move money, and what should we fix first? Regulators and auditors increasingly expect an independent answer every year. For example, PCI DSS (requirement 11.4) requires regular penetration tests wherever card data is processed.

Scope: what gets tested

#AreaWhat we testApproach
1External perimeterPublic IPs, firewall, VPN gateways, exposed services, email security (SPF, DKIM, DMARC)Black box
2Client portal & APIsAuthentication, authorization between clients, injection, business-logic flawsGrey box with two test accounts
3Internal network & Active DirectoryWhat a compromised employee laptop could reach and escalate toAssumed breach
4Microsoft 365 & Entra IDMFA coverage, Conditional Access, admin roles, external sharing, mailbox rulesConfiguration review
5Wi-Fi & branchesGuest/corporate separation, rogue access points, branch-to-HQ pathsOn-site
6Phishing resilienceSimulated phishing campaign (optional, approved by management and HR)Social engineering

Rules of engagement

A penetration test is only legal and safe with clear, written permission. Before any testing starts we agree and sign:

  • Authorization letter from an officer who owns the systems, listing every IP range, domain and application in scope, and confirming permission from any hosting or cloud provider involved.
  • Test windows, for example evenings and weekends for production systems, and blackout periods such as month-end closing.
  • Prohibited actions: no denial-of-service, no changes to production data, no access to real client records beyond proving it is possible.
  • Emergency contacts on both sides and a stop procedure if anything behaves unexpectedly.
  • Data handling: evidence encrypted, kept only for the engagement, and securely deleted after the retest.

Methodology and timeline

We follow recognized frameworks: the Penetration Testing Execution Standard (PTES), the OWASP Web Security Testing Guide for applications and APIs, and NIST SP 800-115 for technical security testing. A typical engagement of this size takes three to four weeks end to end.

PhaseStepWhat happensDuration
0Pre-engagementScope, rules of engagement, written authorization, test windows, emergency contacts3–5 days
1ReconnaissanceMap public IPs, domains, subdomains, exposed services and leaked credentials2–3 days
2Vulnerability analysisAutomated scanning plus manual verification to remove false positives3–4 days
3Controlled exploitationProve real impact on agreed targets, with no data exfiltration or service disruption4–6 days
4Post-exploitationTest lateral movement and privilege escalation toward agreed crown jewels2–3 days
5Reporting & debriefExecutive summary, technical findings with evidence and CVSS ratings, remediation plan3–4 days
6RetestVerify fixes for critical and high findings and issue an updated report1–2 days

Tooling includes Nmap, Tenable Nessus, Burp Suite Professional, Metasploit, BloodHound and Microsoft 365 configuration analysers. Tools find candidates; experienced testers decide what is real and what matters.

Weaknesses we look for

These are the weaknesses most often found in environments like this one across the industry. They are what an attacker tries first, so they are where we start.

#WeaknessAreaTypical fix
1VPN or firewall firmware behind on security updatesExternalPatch within days of vendor advisories; restrict management interfaces
2Legacy authentication that bypasses MFA in Microsoft 365Cloud / identityBlock legacy protocols with Conditional Access; enforce MFA for all users
3Service accounts with weak passwords and Kerberos tickets that can be cracked offline (Kerberoasting)Active DirectoryLong random passwords or managed service accounts; monitor ticket requests
4Same local administrator password on many PCsInternalDeploy Windows LAPS so every device has a unique, rotated password
5LLMNR/NBT-NS enabled and SMB signing not requiredInternal networkDisable legacy name resolution; require SMB signing
6Client portal issues from the OWASP Top 10 (access control, injection, outdated components)Web applicationFix code, add server-side authorization checks, update libraries, add a WAF
7Backups reachable from the main domainResilienceSeparate backup credentials, immutable or offline copies (3-2-1-1)
8Flat network between branches, servers and guest Wi-FiNetworkVLAN segmentation and firewall rules between zones

Why chains matter: attackers rarely need one critical flaw. A phished password, a reused local admin password and one crackable service account can be enough to go from a single laptop to full domain control. Our report shows these attack paths step by step, so you fix the links that break the whole chain.

What you receive

  • Executive summary for management and the board: overall risk, the attack paths found, and the top five actions.
  • Technical report: every finding with evidence, CVSS severity rating, affected systems and step-by-step remediation.
  • Remediation roadmap grouped into 30, 60 and 90 days.
  • Debrief workshop with your IT team.
  • Retest and letter of attestation once critical and high findings are fixed, useful for auditors, regulators and partners.

A 90-day remediation plan

  1. First 30 days: patch exposed systems, enforce MFA everywhere and block legacy authentication, fix critical portal vulnerabilities, rotate exposed credentials.
  2. Days 31–60: deploy Windows LAPS, harden Active Directory and service accounts, disable legacy protocols, separate backup credentials.
  3. Days 61–90: network segmentation, EDR on every device with 24/7 monitoring, security awareness training, then the retest.

FOXMINDS can carry out the remediation as well as the test, and provide ongoing monitoring with Microsoft Defender and Sentinel. Testing then becomes a yearly cycle of continuous improvement rather than a one-off report.

Explore FOXMINDS cybersecurity services

FAQ

Frequently asked questions

How often should a financial services firm run a penetration test?

At least once a year, and after any significant change such as a new client portal, a cloud migration or a network redesign. Many firms add quarterly vulnerability scans between full tests.

Will a penetration test disrupt our operations?

It shouldn’t. Testing follows agreed windows and rules of engagement, avoids denial-of-service and data changes, and any risky step is coordinated with your IT team first.

What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan is automated and lists potential weaknesses. A penetration test adds expert manual work to confirm which weaknesses are real, chain them together the way an attacker would, and prove their business impact.

Next steps

Let's unlock the intelligence in your business

Start with a conversation. We will map your systems, identify the quickest wins and give you a clear, costed plan with no obligation.

  1. 1Discovery callA 30–60 minute session to understand your goals, systems and constraints.
  2. 2Assessment & roadmapWe map your data sources and infrastructure and prioritize use cases by value.
  3. 3Proof of valueA fixed-scope pilot that shows measurable results before you scale.