4 min read · Security Testing · Banking & Financial Services

DAST and VAPT for a US bank’s campaign management web application

Cybersecurity Engineering · Application VAPT

  • Burp Suite
  • Acunetix
  • Nessus
  • OWASP
  • DAST

Engagement

How the work ran.

Client names and implementation details are withheld where they are not approved for publication.

Case study

Challenge

A US bank needed Dynamic Application Security Testing on an ASP.NET MVC campaign management portal with four user roles — without leaving technical or design flaws that would undermine a secure online banking experience.

Approach

VST ran automated and manual VAPT, mapped every URL and parameter, produced video proof-of-concepts for each threat, reviewed findings with developers, and governed remediation through a central vulnerability tracker aligned to OWASP guidance.

Engagement model

Cybersecurity Engineering · Application VAPT

Technology

Burp Suite, Acunetix, Netsparker, Nessus, Nikto, IronWASP

Outcome

Full VAPT completed with verified findings, reduced false positives, and a managed remediation backlog for the asset owner.

Industry

Banking & Financial Services

Practice

Cybersecurity Engineering

Value delivered

  • Manual verification cut false positives while keeping exploitation evidence attached to every finding.
  • Centralised Excel tracker and dashboard gave IT ownership of status, risk rating and actions.
  • Code review with the development team closed the loop from detection to remediation.
  • Assessment followed OWASP web-application security practices and the bank’s risk-rating SOPs.

Share

LinkedInXEmail

Related practice

Security engineered into how software is built and run.

Cybersecurity Engineering — Assessment, secure development, cloud and identity security, and response — integrated with engineering rather than bolted on.

This engagement sits inside our Cybersecurity Engineering practice. Explore the full scope, outcomes and how we usually start.

Explore Cybersecurity Engineering →

Next step

Have a similar problem — or need more clarity?

If this challenge looks like yours, book a short discovery call. If the problem is still fuzzy, we will help you name the constraint before anyone builds a large plan.

Start a conversation

Tell us whether you need software built, a release assured, or operations taken on.

Start with a 2–8 week advisory if the problem is still a choice — then a project, a named engineering team, or managed operations.