Finance Road Town, Tortola, British Virgin Islands 40 employees, 1 office Test and remediation over 8 weeks

BVI trust company closes 14 vulnerabilities found in a penetration test

A 40-staff BVI trust company closed all 14 penetration test findings, including two critical findings within 10 days, with every finding verified closed at retest eight weeks after kick-off.

An institutional client's due diligence process required an independent penetration test of the systems holding client records. The provider had never been tested externally and needed both the test and a credible remediation record.

Client: 40-staff trust and corporate services provider. Name withheld under our confidentiality terms.

At a glance

Client
40-staff trust and corporate services provider
Sector
Finance
Location
Road Town, Tortola, British Virgin Islands
Size
40 employees, 1 office
Services
Penetration Testing, Vulnerability Management, Cyber Security Assessment
Timeline
Test and remediation over 8 weeks
Headline result
14 — Findings identified across the tested scope

Measured results

Findings identified across the tested scope
14Findings identified across the tested scope
Critical findings, both closed within 10 days
2Critical findings, both closed within 10 days
Findings verified closed at retest
100%Findings verified closed at retest
Test to clean retest report
8 weeksTest to clean retest report

The challenge

  • An institutional client required an independent penetration test report before onboarding.
  • The client portal and remote access infrastructure had never been externally tested.
  • Regulatory expectations in the BVI financial services sector were tightening.
  • Any findings would need remediating and re-verifying within the client's onboarding window.

What we did

  1. 1

    Scoped a test covering the external perimeter, the client-facing portal and remote access.

  2. 2

    Ran CREST-aligned testing combining automated discovery with manual exploitation.

  3. 3

    Delivered findings rated by real-world exploitability rather than raw CVSS score alone.

  4. 4

    Produced a prioritised remediation plan with owners and target dates, not a raw scanner dump.

  5. 5

    Supported remediation of the two critical and five high findings first, then the remainder.

  6. 6

    Performed a free retest to verify closure, and moved the estate onto continuous vulnerability scanning.

The outcome

  • The institutional client completed onboarding on schedule.
  • A clean retest report is now reusable evidence for other client due-diligence requests.
  • Continuous vulnerability scanning replaced point-in-time checks between annual tests.
  • Remote access was rebuilt behind MFA and conditional access.
We expected a list of problems. What we got that was actually useful was the order to fix them in and someone to check the fixes worked.
Compliance Director, trust company, Tortola

The concepts behind this engagement

Plain-English reference pages explaining the certifications, threats and controls involved in this piece of work.

FAQ

Questions about this engagement

The questions businesses in a similar position ask most often before starting.

What is the difference between a penetration test and a vulnerability scan?

+

A vulnerability scan is automated and continuous: it compares your systems against a database of known issues and reports what it finds, including a proportion of false positives. A penetration test adds a human tester who chains findings together, attempts real exploitation, and establishes what an attacker could actually reach. In this engagement the scanner flagged individual issues on the portal; the tester demonstrated that two of them combined into a path to client records, which changed the priority entirely. Most SMEs need both — continuous scanning for coverage between tests, and an annual test for depth and for client-facing assurance.

How often should a financial services firm be penetration tested?

+

Annually is the standard baseline, with an additional test after any material change: a new client-facing portal, a migration to new infrastructure, a significant application release, or a change of remote access technology. Between tests, continuous vulnerability scanning provides coverage, because a system that was clean in March can become exploitable in June when a new vulnerability is published. Client due diligence in the BVI and UK financial sectors increasingly asks for a test dated within the last twelve months, so annual cadence is often driven by commercial requirement as much as by risk.

Is a retest included, and why does it matter?

+

A retest of the original findings is included at no extra cost after remediation. It matters because an unverified fix is an assumption. Roughly one in five remediations we retest is incomplete — a patch applied to one server but not its pair, a configuration change reverted by a later deployment, or a fix that addresses the symptom rather than the underlying issue. The retest produces a clean, dated report showing findings closed, which is the document clients and insurers actually want to see. A test report full of open findings is worth considerably less in a due-diligence pack.

Related case studies

Two ways to get started

Not sure what you need? Speak to us. Want ongoing protection? Try it free.

Book a free 30-minute Cyber Security Review with our UK team, or start a 14-day free trial of Cyber Shield and see the difference for yourself.

Not sure what you need?

Book a Cyber Security Review Takes 30 minutes. No obligation.

Want ongoing protection?

Start Cyber Shield Free Trial14-day free trial. Cancel anytime.
Reply within 1 working hour UK-based specialists No obligation either way