Research Library / Case Studies /

Health Insurance

Securing Over 1,600 Assets Across Web, Mobile, and Infrastructure for a Digital Health Insurance Leader

One of India's largest health insurers, covering over 17 crore lives, asked Payatu to test everything at once: 10 mobile apps, 35 web applications, and more than 1,600 network assets.
Mobile Application Penetration Testing, Web Application Security Assessment, Infrastructure Penetration Test

At a glance

INDUSTRY

Health Insurance

CLIENT PROFILE

One of India's leading private health insurance companies, insuring over 17 crore lives

SERVICES

Mobile Application Penetration Testing, Web Application Security Assessment, Infrastructure Penetration Test

ENGAGEMENT

Multi-domain assessment · 1,600+ assets

key Numbers

1,600+

Assets Tested

17 Cr+

Lives Insured by the Client

90%+

Reduction in Attack Surface After Remediation

Key Takeaways

  • Client – one of India's leading private health insurance companies, insuring over 17 crore lives since inception.

  • Problem – a rapidly scaling digital footprint across mobile, web, and infrastructure had outpaced the organization's security controls.

  • What Payatu did – ran a multi-faceted assessment covering 10 mobile applications, 35 web applications, external and internal network penetration testing, and wireless network testing across more than 1,600 assets.

  • Outcome – found missing authentication and access controls, unpatched critical vulnerabilities, and inadequate network segmentation, then reduced the client's attack surface by over 90% through remediation.

the challenge

Why the client called us in

As the client scaled its digital footprint across mobile apps, web platforms, and infrastructure, a seamless digital experience was no longer enough on its own, security needed to be embedded at every layer. Leadership engaged Payatu to assess the full stack before a gap in any one layer put customer data or service continuity at risk.

  • Identify vulnerabilities across mobile, web, and infrastructure at scale
  • Validate network segmentation and patch hygiene across internal and external assets
  • Build a resilient environment that supports uninterrupted healthcare access

scope of engagement

What was in scope

  1. Penetration testing of 10 mobile applications
  2. Security assessment of 35 web applications
  3. Infrastructure Penetration Test

Our Approach

How Payatu ran the engagement

01

Mobile Application Testing
Static and dynamic analysis, reverse engineering, and local file analysis across 10 applications, followed by controlled exploitation to validate real-world impact.

02

Web Application Testing
Manual business-logic testing combined with automated scanning across 35 applications to surface access-control flaws, injection points, and configuration issues.

03

External Network Assessment
Reconnaissance and service enumeration across 40+ subdomains to identify exposed services and perimeter weaknesses.

04

Internal Network Assessment
Authenticated and unauthenticated testing across 1,570 internal IPs to evaluate segmentation, lateral movement, and privilege escalation paths.

05

Wireless Assessment
Unauthenticated and authenticated testing of wireless protocols, encryption, and access controls.

Key findings

What we found

Access & Authentication
Missing access and authentication controls exposed sensitive operations.
Encryption & Data Handling
Client-side encryption and weak upload validation exposed data-handling gaps.
Patch & Infrastructure Hygiene
EternalBlue and Zero Logon sat unpatched for years, alongside unrestricted subnet access.
Legacy Systems
SMBv1 and outdated SSH pointed to infrastructure that had fallen behind.

the outcome

Results and Impact

Payatu's assessment gave the client a prioritised view of risk across its entire digital estate, reducing attack surface by over 90% and closing the gaps most likely to affect customer trust and regulatory standing.

‍

  • Attack surface reduced by over 90% through network segmentation and patch management

  • Access controls and session handling hardened against privilege escalation and account takeover

  • Business-critical logic secured against fraud and revenue leakage

  • Strengthened compliance posture against IRDAI, HIPAA, and GDPR requirements

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment