Consumer Internet / Diversified Conglomerate
Security Posture Assessment for the Digital Platform of a Leading Multinational Conglomerate
At a glance
INDUSTRY
Consumer Internet / Diversified Conglomerate
CLIENT PROFILE
An Indian multinational conglomerate present in 100+ countries across 6 continents, launching a large-scale digital platform
SERVICES
Network VAPT, Web Application VAPT, Mobile Application VAPT, Secure Code Review
ENGAGEMENT
360-degree pre-launch security posture assessment run in parallel against a fixed deadline

key Numbers
145
35%+
10/10
Key Takeaways
Client – An Indian multinational conglomerate present in over 100 countries across 6 continents, about to launch a large-scale digital platform folding in its full portfolio of consumer and business services.
Problem – With a fixed launch date, the client needed a 360° security assessment covering network, web, mobile VAPT and secure code review, then expanded the scope mid-engagement to include the web app’s source code.
What Payatu did – We ran the modules in parallel to hit the deadline, doubling our team, and assessed the network and application layers thoroughly, uncovering a wide range of vulnerabilities, a significant share of them critical or high severity.
Outcome – The client fixed the highest-risk issues before launch and rated Payatu 10 out of 10 for technical excellence and delivery.
the challenge
Why the client called us in
Our client, an Indian multinational conglomerate with operations in over 100 countries across 6 continents, was weeks from launching a single large-scale digital platform meant to bring its full range of services to Indian consumers and businesses. The platform had a fixed launch date, so any security gaps needed to be found and fixed fast, across the network, the web application, and the mobile application. Partway through, the client's management also asked us to add a review of the web application's source code, without moving the deadline.
- Get a 360-degree view of the platform's security posture before launch
- Cover network, web, and mobile layers, including secure code review
- Deliver everything, including a late scope addition, inside the original deadline
scope of engagement
What was in scope
- Access control implementation across teams, application and network
- Authorization and authentication mechanisms, application and network
- Securing API keys during error handling
- Escaped user input handling
- Business logic flaw testing
- Sensitive internal page exposure over the internet
- Data at rest and in transit security
- Unnecessary exposed services on the network
- Vulnerable service versions on the network
- Network traffic encryption
- SSL/TLS certificate review
- Mobile application secure code assessment
- Web application secure code review (added mid-engagement)
Our Approach
How Payatu ran the engagement
01
02
03
04
Key findings
What we found
the outcome
Results and Impact
The assessment gave the client's leadership and developers a full, quantified view of their platform's risk, 145 vulnerabilities in total, with 23 rated critical and 28 rated high severity, before the product reached the public. Delivered on time despite a mid-project scope increase, the findings gave the company's top management the runway to fix the highest-risk issues ahead of launch.
145 vulnerabilities identified across network and application layers
23 critical and 28 high severity issues flagged for immediate remediation
Web application source code review absorbed into scope without slipping the deadline
Engagement rated 10 out of 10 by the client for technical excellence and delivery
Get the full case study
Download the complete PDF - full methodology, findings and remediation detail.

.png)







