Research Library / Case Studies /

Device Security & Mobile Financing Technology

Expanding Partnership, A New Model for Continuous Security

A device security company asked one question: could its device-locking app be bypassed? It could. Seven security domains later, Payatu runs as an extension of their internal security function.
Mobile Application Security Testing, Web Application Penetration Testing, Cloud Security Assessment, Network Penetration Testing, Architecture Review, Threat Modelling, OSINT

At a glance

INDUSTRY

Device Security & Mobile Financing Technology

CLIENT PROFILE

A device security technology provider working with global OEMs and financial institutions

SERVICES

Mobile Application Security Testing, Web Application Penetration Testing, Cloud Security Assessment, Network Penetration Testing, Architecture Review, Threat Modelling, OSINT

ENGAGEMENT

Stream-based retainer · ongoing

Key Takeaways

  • Client: A device security technology provider whose platform enforces EMI payments on financed devices, embedded in hundreds of millions of devices worldwide through OEM and financial institution partnerships.

  • Problem: Project-based testing could not keep pace. Every assessment meant fresh scoping, estimation, negotiation and signing, and context was lost between engagements.

  • What Payatu did: Replaced the project model with a stream-based engagement: a fixed monthly fee, a dedicated consultant rotated by skill, and a permanent project manager holding context.

  • Outcome: Coverage across seven security domains under one agreement, and a partnership that now shapes architecture decisions before code ships.

the challenge

Why the client called us in

The relationship started with one focused assessment and a direct question: could the device-locking application be bypassed? It could. That finding led to more engagements, and the project model started to strain. Priorities shifted month to month, but every new assessment restarted the commercial cycle before any testing began.

  • Remove the procurement cycle that preceded every assessment
  • Cover mobile, cloud, network and architecture without changing vendor
  • Retain context so architecture is not relearned each engagement

scope of engagement

What was in scope

  1. Mobile application security testing
  2. Web application penetration testing
  3. Cloud infrastructure assessment
  4. Network penetration testing
  5. Architecture review
  6. Threat modelling
  7. OSINT

Our Approach

How Payatu ran the engagement

01

Fixed Monthly Fee
A predictable monthly cost removes repeated commercial negotiation and enables straightforward budget planning across the year.

02

One Dedicated Consultant
A skilled security consultant is deployed full time, aligned to the client's priorities and project requirements throughout the engagement.

03

Skill-Based Rotation
Consultants with application, cloud or network expertise are deployed and rotated as project needs evolve, so the right skill is always available.

04

Dedicated Project Manager
A single point of contact holds context across every initiative, ensuring continuity and smooth coordination between security workstreams.

05

Rolling Engagement
The model runs continuously through the year, focusing on one initiative at a time and transitioning between projects without a new agreement.

Key findings

What we found

CRITICAL
Device lock bypass
Payatu's team bypassed the device-locking application and uninstalled the device lock without payment, directly threatening the client's core revenue model.
CRITICAL
Additional platform vulnerabilities
Multiple additional high and critical severity vulnerabilities were identified across the platform, APIs, and mobile application.

the outcome

Results and Impact

What started as a single question has become a standing engagement. Coverage expanded from mobile application testing alone to web, cloud, network, architecture review and threat modelling. The client now brings Payatu in during design rather than after deployment, and treats the team as an extension of its internal security function.

‍

  • Seven security domains covered under a single agreement

  • Zero procurement cycles between security initiatives

  • Context retained across engagements by a dedicated project manager

  • Security moved from post-deployment testing into design

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment