Security guides
ILLUSTRATIVE GUIDEPenetration testing

What an attacker could reach. And how to stop them.

Inside a web application penetration test: from understanding your attack surface to giving your team the evidence and direction to fix what matters.

Web applicationAuthenticated APIUser roles & permissions
THE QUESTION BEHIND THE REVIEW

Can one account reach another account’s data?

A web application preparing for its next release.

Illustrative assessment

An example of the assessment process and report content. This is not a published client engagement.

01 / THE CHALLENGE

Start with the right question.

Consider a growing SaaS application with multiple customer accounts, shared infrastructure, and an API used by both its web interface and integrations. New features are ready to ship, but the team needs to understand whether the boundaries between customers hold up.

The assessment focuses on how the application behaves when someone moves beyond its intended workflows. It examines authorization, authentication, session handling, and the business logic behind sensitive actions within an agreed scope.

02 / THE APPROACH

From context to clarity.

Each engagement starts with an agreed scope. Here is how a review of this kind can take shape.

  1. 01

    Define the boundaries

    Agree on the applications, endpoints, test accounts, permitted techniques, and testing window. Establish a contact and an escalation path before testing begins.

  2. 02

    Test the real workflows

    Map the application and examine how different roles interact with protected resources. Combine targeted tooling with manual investigation of the application’s logic.

  3. 03

    Validate and document

    Confirm findings with the minimum evidence needed to demonstrate impact. Record the affected components, reproduction steps, and the conditions required.

  4. 04

    Prioritize the next action

    Explain the business impact, recommend a practical fix, and agree how remediation can be verified. Any retesting is defined in the engagement scope.

03 / AN EXAMPLE FINDING

The detail behind the headline.

A useful report connects the observation to its impact, explains what to change, and makes the next step clear.

PT-001 / ILLUSTRATIVE FINDINGHigh priority

A missing account boundary

Authorization
What we observed
In this example, a signed-in user changes a resource identifier and receives a record belonging to a different customer account. The endpoint checks that the user is authenticated, but does not verify ownership of the requested record.
Why it matters
Customer information could be exposed across account boundaries. The final severity depends on the sensitivity of the data, the access required, and the extent of the affected functionality.
Recommended action
Enforce authorization on the server for every protected resource. Derive the permitted account scope from the authenticated identity and apply it consistently to reads and updates.
How to verify
Repeat the original test with separate customer accounts, check adjacent endpoints, and confirm that legitimate same-account workflows still work.
04 / WHAT YOU RECEIVE

A report with a way forward.

The exact deliverables are agreed during scoping. An assessment of this kind can include:

01

An executive view of risk

The assessed scope, key themes, and business implications, written for the people making decisions.

02

Evidence your team can use

Validated technical findings with affected components, reproduction steps, and appropriately redacted evidence.

03

A practical remediation plan

A clear explanation of what to change, which issues deserve attention first, and how fixes can be checked.

LET’S MAKE IT SPECIFIC TO YOU

Your environment.
Your next step.

Share the type of application, its main workflows, and your target timeline. We can then define a testing scope and the deliverables your team needs.

Get a quote