Cybersecurity Services / SaaS (Pentesting-as-a-Service)
Securing the Digital Realm of a Pentesting-as-a-service Provider with Threat Modeling
At a glance
INDUSTRY
Cybersecurity Services / SaaS (Pentesting-as-a-Service)
CLIENT PROFILE
Well-recognized pentesting-as-a-service platform
SERVICES
Threat Modeling
ENGAGEMENT
STRIDE-based threat modeling across five platform modules

key Numbers
24
14
10
Key Takeaways
Client – A well-recognized platform that offers pentesting-as-a-service to its own customers.
Problem – The client had general security controls in place but no clear, structured picture of the threats and threat agents facing its platform, including client onboarding, scan scheduling and attack surface management modules.
What Payatu did – We ran a STRIDE-based threat modeling exercise, building data flow diagrams and a threat model diagram in the Microsoft Threat Modeling Tool to identify, rank and map threats across the platform's five core modules.
Outcome – We identified 24 threats and vulnerabilities, confirmed that existing controls already mitigated 14 of them, and delivered 10 new control recommendations to close the rest.
the challenge
Why the client called us in
As a platform that sells pentesting-as-a-service to its own customers, the client held itself to a higher bar for its own security. It had general controls in place but no structured, prioritized view of the threats facing modules like client onboarding, reporting automation and attack surface management, and no clear plan for which risks to close first. The client brought in Payatu to proactively identify threats and define countermeasures before those gaps could be exploited.
- Identify all potential threats and vulnerabilities across the platform
- Prioritize threats by risk to guide a mitigation roadmap
- Determine which existing controls already covered identified threats and where new ones were needed
scope of engagement
What was in scope
- To perform threat modeling of modules of the portal
- To identify all potential threats and vulnerabilities to the platform
Our Approach
How Payatu ran the engagement
01
02
03
04
05
06
07
Key findings
What we found
the outcome
Results and Impact
Before the engagement, the client had 14 general controls in place but no clarity on the threats those controls were actually stopping or missing. The threat modeling exercise gave the client a complete, STRIDE-categorized view of its risk, confirming which of its 24 identified threats were already mitigated and which needed new controls.
24 threats and vulnerabilities identified and categorized using STRIDE
14 threats confirmed as already mitigated by existing general controls
10 new control recommendations delivered, including S3 bucket encryption and container hardening
Data flow diagrams and a threat model diagram delivered for ongoing use
Client moved from no threat clarity to a documented, prioritized risk picture
Get the full case study
Download the complete PDF - full methodology, findings and remediation detail.

.png)







