Securing A Customer Portal Before A Major Platform Expansion
A more secure customer portal with clearer access controls and greater confidence before scaling the platform.
- Client
- Professional services client
- Industry
- Professional Services
- Services
- Customer Portal Security Assessment
- A more secure customer portal
- A more secure customer portal
- Clearer access controls
- Clearer access controls
- Greater confidence before scaling
- Greater confidence before scaling
Where they were starting from.
The client was preparing to expand its customer portal, which allowed users to log in, access account information and submit requests. Before expanding the platform, the business needed confidence that existing security controls could withstand real world attacks. The main concerns were weaknesses in authentication, user permission issues, exposed API endpoints, sensitive customer information and outdated third party dependencies.
Three decisions that shaped the outcome.
- 01
What We Did
OnyxEra performed a full security assessment of the portal and supporting APIs.
- 02
What We Found
The assessment identified several security weaknesses that could have allowed unauthorised access to application functionality and sensitive information. Each finding was documented with severity, business impact, technical evidence, reproduction steps and recommended remediation.
- 03
What We Delivered
Security Assessment, Vulnerability Report, Remediation Plan, Fix Verification. The development team used the findings to address the identified vulnerabilities before the platform expansion.
A more secure customer portal with clearer access controls and greater confidence before scaling the platform.
The numbers behind it.
Screenshots taken from the tools themselves, not a summary of them. Select any one to see it full size.
The portal and its supporting APIs, and the seven areas assessed against them.
Security Assessment, Vulnerability Report, Remediation Plan, Fix Verification, and what each finding was documented with.
Cyber Security
Penetration testing, secure code review, cloud and identity security, compliance readiness and incident response planning.
Tell us where it hurts.
If any of this sounded familiar, the call is free and the advice is honest, even when the honest advice is that you do not need us.