Skip to main content
All case studies
SaaSPenetration TestingDelivered in days

Certified penetration testing under compliance pressure

UK SaaS provider

Compliance obligations closing in, a report needed for their own clients, and no time for a slow procurement process. Tested personally by a named, CREST certified practitioner.

Outcomes

  • Completed in days, against a live compliance deadline
  • Tested personally by a named CREST certified practitioner
  • Report written for leadership and engineering separately
  • Presented directly to the client's own customers
  • Ongoing relationship, including ISO 27001 readiness

A UK SaaS provider came to Tarian Labs under pressure. They had compliance obligations closing in, a report they needed to put in front of their own clients, and no time for a slow procurement process. They needed a certified penetration test carried out by a named, qualified practitioner, and they needed it done properly within days.

The challenge

The client needed a security assessment that would hold up under scrutiny from their own clients and stakeholders. That meant a proper test carried out by a named, credentialed practitioner, not a scan report with a logo on it. And they needed it done within days, not weeks.

What we did

We started with a conversation about what the client was actually trying to achieve, not just what systems needed testing. The compliance deadline was real, but so was the longer term goal of having security evidence that would hold up as the business grew.

We scoped the engagement around both. Testing covered the client's web application and its supporting infrastructure, looking at how the application handled authentication, access controls, and data in transit alongside the security of the environment it sat in. All of it carried out personally by a CREST certified practitioner. No delegation to junior staff. No automated tooling passed off as a manual assessment. The client knew exactly who was testing their systems and what qualifications they held.

When the findings came back, we reported them straight. Where things were solid, we said so. Where there were weaknesses, we explained what they meant in practical terms and what to do about them. No inflated findings to pad the report.

The result

The engagement was completed in days. The report was structured for two audiences: a clear executive summary for leadership and stakeholders, and detailed technical findings for the engineering team. The client was able to present it directly to their own customers with confidence.

What started as a one-off compliance exercise has since turned into an ongoing relationship. We have helped the client think through their broader security posture, including thinking through ISO 27001 readiness, and they know they have someone to call when their requirements grow.

Client name withheld by agreement.

We engaged Tarian Labs for a certified penetration test, but what we found was a long-term security partner.
Technical Director, UK SaaS provider

Want the same on your environment?

Tell us what you are running. We will come back within one business day with how we would scope it.