Research Library / Case Studies /

Consumer Internet / Diversified Conglomerate

Security Posture Assessment for the Digital Platform of a Leading Multinational Conglomerate

An Indian multinational conglomerate with a presence in 100+ countries needed a 360-degree security assessment of its new digital product before launch. Payatu doubled its team to hit the deadline, uncovered a range of severe vulnerabilities, and left the client thoroughly satisfied.
Network VAPT, Web Application VAPT, Mobile Application VAPT, Secure Code Review

At a glance

INDUSTRY

Consumer Internet / Diversified Conglomerate

CLIENT PROFILE

An Indian multinational conglomerate present in 100+ countries across 6 continents, launching a large-scale digital platform

SERVICES

Network VAPT, Web Application VAPT, Mobile Application VAPT, Secure Code Review

ENGAGEMENT

360-degree pre-launch security posture assessment run in parallel against a fixed deadline

key Numbers

145

Vulnerabilities Identified

35%+

Rated Critical or High Severity

10/10

Client Performance Rating

Key Takeaways

  • Client – An Indian multinational conglomerate present in over 100 countries across 6 continents, about to launch a large-scale digital platform folding in its full portfolio of consumer and business services.

  • Problem – With a fixed launch date, the client needed a 360° security assessment covering network, web, mobile VAPT and secure code review, then expanded the scope mid-engagement to include the web app’s source code.

  • What Payatu did – We ran the modules in parallel to hit the deadline, doubling our team, and assessed the network and application layers thoroughly, uncovering a wide range of vulnerabilities, a significant share of them critical or high severity.

  • Outcome – The client fixed the highest-risk issues before launch and rated Payatu 10 out of 10 for technical excellence and delivery.

the challenge

Why the client called us in

Our client, an Indian multinational conglomerate with operations in over 100 countries across 6 continents, was weeks from launching a single large-scale digital platform meant to bring its full range of services to Indian consumers and businesses. The platform had a fixed launch date, so any security gaps needed to be found and fixed fast, across the network, the web application, and the mobile application. Partway through, the client's management also asked us to add a review of the web application's source code, without moving the deadline.

  • Get a 360-degree view of the platform's security posture before launch
  • Cover network, web, and mobile layers, including secure code review
  • Deliver everything, including a late scope addition, inside the original deadline

‍
‍

‍

scope of engagement

What was in scope

  1. Access control implementation across teams, application and network
  2. Authorization and authentication mechanisms, application and network
  3. Securing API keys during error handling
  4. Escaped user input handling
  5. Business logic flaw testing
  6. Sensitive internal page exposure over the internet
  7. Data at rest and in transit security
  8. Unnecessary exposed services on the network
  9. Vulnerable service versions on the network
  10. Network traffic encryption
  11. SSL/TLS certificate review
  12. Mobile application secure code assessment
  13. Web application secure code review (added mid-engagement)

Our Approach

How Payatu ran the engagement

01

Parallel Module Planning
Split the network, web, mobile, and code review workstreams to run in parallel and doubled the team size, so dependencies between modules would not blow the deadline.

02

Network Security Assessment
Assessed the client's large-scale network infrastructure and found over 100 vulnerabilities, more than a third of them critical or high severity.

03

Application Security Assessment
Assessed the web and mobile application layers and found the application security posture was also compromised, with several modules needing improvement.

04

Scope Expansion and Code Review
Absorbed a mid-engagement request to review the web application's source code as well, without extending the deadline.

Key findings

What we found

Business Logic
Flaws in the platform's business logic could be exploited beyond simple input validation bypass.
Access Control
Authorization checks and access controls were inconsistently enforced across the platform's modules.
Component Security
The platform ran on third-party packages with known vulnerabilities.
Infrastructure Exposure
The Kubernetes API was exposed, alongside an unprotected server and an exposed Alert Manager dashboard on the network.
Authentication
Some services and pages allowed anonymous or unauthenticated access where authentication should have been required.

the outcome

Results and Impact

The assessment gave the client's leadership and developers a full, quantified view of their platform's risk, 145 vulnerabilities in total, with 23 rated critical and 28 rated high severity, before the product reached the public. Delivered on time despite a mid-project scope increase, the findings gave the company's top management the runway to fix the highest-risk issues ahead of launch.

‍

  • 145 vulnerabilities identified across network and application layers

  • 23 critical and 28 high severity issues flagged for immediate remediation

  • Web application source code review absorbed into scope without slipping the deadline

  • Engagement rated 10 out of 10 by the client for technical excellence and delivery

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment