Skip to content

Case Study / Continuous VAPT program

A three-year continuous testing partnership

Three years of quarterly VAPT: candidate-data exposure, CSRF, rate-limit abuse, and privilege escalation, found and managed down cycle over cycle.

Developer assessment platform · US

The problem and the risk

A developer assessment and hiring platform used by enterprises worldwide holds two things attackers want: sensitive candidate data and proprietary assessment content. A clean annual pentest would say little about the eleven months that follow it, so the client committed to a continuous VAPT program instead: quarterly cycles, the same senior testers each time, now running for three years.

How the engagement ran
  1. 01Quarterly assessment cycles
  2. 02Hybrid coverage
  3. 03Business-impact triage
  4. 04Developer enablement

Approach

Quarterly assessment cycles

Recurring testing synchronized with development milestones, so new features get assessed when they ship, not a year later.

Hybrid coverage

Automated scanning for breadth, targeted manual testing for depth, and realistic internal/external attack simulations.

Business-impact triage

Regular risk-triage reviews translate technical findings into business-impact scores the client prioritizes against.

Developer enablement

Threat-modeling and secure-coding sessions run alongside testing: the same testers, teaching from the same findings.

Technology & methods

  • Web, network, cloud, and native-application surfaces
  • Automated scanning paired with targeted manual testing
  • Internal and external attack simulation
  • Business-impact risk triage
  • Threat-modeling and secure-coding sessions

Findings

Candidate-record exposure

A directory-level file listing made sensitive candidate information potentially reachable without authorization.

CSRF on critical transactions

Several transaction endpoints operated without anti-forgery safeguards, permitting state-changing requests a victim never intended.

Cross-site scripting (XSS)

User inputs allowed arbitrary markup on key application pages, an XSS-class flaw and the classic path to session and content compromise.

Missing rate controls

Core functionality lacked request-volume controls, exposing it to automated abuse and enumeration.

Privilege escalation

Session-token validation and role mappings were misaligned, producing inconsistent privileges an attacker could exploit.

Remediation, validation & outcome

  • A repeatable VAPT framework that scales with platform growth and each release.
  • Continuous visibility into emerging threats, shortening exposure windows.
  • Three years on: the same senior testers, deepening platform context, and findings trending down cycle over cycle.

Client identity is confidential by agreement. The engagement is published anonymized; we never publish metrics we didn't measure.

What this engagement taught us

Continuity compounds. Testers who carry years of platform context stop re-learning old ground and start anticipating where new features will break, something a point-in-time engagement can never buy. Findings trending down over that span is what the program was designed to produce.

Ready to scope the work?

A 30-minute call with the engineers who will do the testing, not a sales gate.