Summary
Key results
Validated security of new applications
Actionable recommendations for remediating identified vulnerabilities and findings
Parallel application development and growing vulnerability risk
In the insurance sector, web applications support critical business processes, including sales, customer service, and claims handling. The security of new solutions therefore has a direct impact on business continuity and regulatory compliance. Vienna Insurance Group launched an IT modernization program that included developing new applications and upgrading existing tools, some of which processed customer and agent data.
Most projects were delivered by external vendors using their own security standards. Without independent testing, some applications could have entered production with security flaws that had gone undetected during development. This created the risk of post-deployment incidents, costly remediation, and delays in system launches. In addition, new versions of both web and mobile applications were released continuously, requiring regular security validation before each release. Without an ongoing, independent testing process, VIG faced the risk of inconsistent security standards and vulnerabilities being identified only after deployment.
To mitigate these risks and confirm that new applications could withstand attacks, VIG partnered with Sii Poland, which has a team of more than 200 cybersecurity specialists, including penetration testers holding certifications such as OSCP and OSWE, as well as experience delivering projects for major international insurers, including UNIQA and ERGO.
Comprehensive security validation of new and enhanced applications
Sii’s objective was to provide VIG with an independent and reliable assessment of applications developed by multiple vendors. Sii experts conducted vulnerability assessments and penetration testing in line with OWASP (Open Worldwide Application Security Project) best practices, an internationally recognized standard for application security testing, supplementing them with manual attempts to exploit the identified vulnerabilities.
The scope of work included:
- Grey-box penetration testing – simulated attacks from the perspective of a user with limited knowledge of the system
- Vulnerability assessments – identification of vulnerabilities in the application and communication layers
- Manual validation and exploitation of identified vulnerabilities – confirmation of their actual impact on security
- Source code security analysis – identification of issues that could not be detected externally
- Testing based on the OWASP Web Security Testing Guide – comprehensive coverage of threat scenarios
- Reports for each application describing the vulnerabilities, assessing the associated risks, and providing actionable remediation recommendations
As a result, the client received a comprehensive, prioritized list of security threats, along with clear guidance on how to remediate them effectively. The engagement with Sii Poland is ongoing, with testing performed regularly for subsequent applications and their new versions.
Secure releases and greater control over application quality
Through independent testing by Sii Poland, Vienna Insurance Group gained greater assurance that its new and enhanced applications could withstand the most common attack vectors and that the quality of their security controls did not depend solely on the vendors responsible for developing them.
The organization gained a clear view of the identified vulnerabilities and associated risks, along with actionable recommendations that enabled the security flaws to be remediated before the systems entered production. Greater control over application security also delivered long-term benefits, including lower remediation costs, stronger regulatory compliance, and greater resilience of the IT environment to security incidents.
Regular testing enables the organization to maintain a high level of cybersecurity in a rapidly evolving IT environment and ensure compliance with industry regulations with each new application release. Ongoing collaboration with a single experienced partner makes the process more predictable and shortens response times when security threats are identified.
Key results
- Validated security of new and modernized web applications
- Clear identification and prioritization of detected vulnerabilities
- Actionable remediation recommendations for each application
- Greater system resilience to attacks and reduced exposure to potential threats
- Consistent security standards regardless of the application vendor
GET IN TOUCH
Let's start the conversation today