BVI trust company closes 14 vulnerabilities found in a penetration test
A 40-staff BVI trust company closed all 14 penetration test findings, including two critical findings within 10 days, with every finding verified closed at retest eight weeks after kick-off.
An institutional client's due diligence process required an independent penetration test of the systems holding client records. The provider had never been tested externally and needed both the test and a credible remediation record.
Client: 40-staff trust and corporate services provider. Name withheld under our confidentiality terms.
At a glance
- Client
- 40-staff trust and corporate services provider
- Sector
- Finance
- Location
- Road Town, Tortola, British Virgin Islands
- Size
- 40 employees, 1 office
- Services
- Penetration Testing, Vulnerability Management, Cyber Security Assessment
- Timeline
- Test and remediation over 8 weeks
- Headline result
- 14 — Findings identified across the tested scope
Measured results
- Findings identified across the tested scope
- 14Findings identified across the tested scope
- Critical findings, both closed within 10 days
- 2Critical findings, both closed within 10 days
- Findings verified closed at retest
- 100%Findings verified closed at retest
- Test to clean retest report
- 8 weeksTest to clean retest report
The challenge
- An institutional client required an independent penetration test report before onboarding.
- The client portal and remote access infrastructure had never been externally tested.
- Regulatory expectations in the BVI financial services sector were tightening.
- Any findings would need remediating and re-verifying within the client's onboarding window.
What we did
- 1
Scoped a test covering the external perimeter, the client-facing portal and remote access.
- 2
Ran CREST-aligned testing combining automated discovery with manual exploitation.
- 3
Delivered findings rated by real-world exploitability rather than raw CVSS score alone.
- 4
Produced a prioritised remediation plan with owners and target dates, not a raw scanner dump.
- 5
Supported remediation of the two critical and five high findings first, then the remainder.
- 6
Performed a free retest to verify closure, and moved the estate onto continuous vulnerability scanning.
The outcome
- The institutional client completed onboarding on schedule.
- A clean retest report is now reusable evidence for other client due-diligence requests.
- Continuous vulnerability scanning replaced point-in-time checks between annual tests.
- Remote access was rebuilt behind MFA and conditional access.
“We expected a list of problems. What we got that was actually useful was the order to fix them in and someone to check the fixes worked.”
The concepts behind this engagement
Plain-English reference pages explaining the certifications, threats and controls involved in this piece of work.
Where this fits in what Complete Cyber Security does
FAQ
Questions about this engagement
The questions businesses in a similar position ask most often before starting.
What is the difference between a penetration test and a vulnerability scan?
+
A vulnerability scan is automated and continuous: it compares your systems against a database of known issues and reports what it finds, including a proportion of false positives. A penetration test adds a human tester who chains findings together, attempts real exploitation, and establishes what an attacker could actually reach. In this engagement the scanner flagged individual issues on the portal; the tester demonstrated that two of them combined into a path to client records, which changed the priority entirely. Most SMEs need both — continuous scanning for coverage between tests, and an annual test for depth and for client-facing assurance.
How often should a financial services firm be penetration tested?
+
Annually is the standard baseline, with an additional test after any material change: a new client-facing portal, a migration to new infrastructure, a significant application release, or a change of remote access technology. Between tests, continuous vulnerability scanning provides coverage, because a system that was clean in March can become exploitable in June when a new vulnerability is published. Client due diligence in the BVI and UK financial sectors increasingly asks for a test dated within the last twelve months, so annual cadence is often driven by commercial requirement as much as by risk.
Is a retest included, and why does it matter?
+
A retest of the original findings is included at no extra cost after remediation. It matters because an unverified fix is an assumption. Roughly one in five remediations we retest is incomplete — a patch applied to one server but not its pair, a configuration change reverted by a later deployment, or a fix that addresses the symptom rather than the underlying issue. The retest produces a clean, dated report showing findings closed, which is the document clients and insurers actually want to see. A test report full of open findings is worth considerably less in a due-diligence pack.
Related case studies
Manufacturing
Leeds manufacturer passes Cyber Essentials Plus first time to win a supply-chain contract
Read moreConstruction
Northallerton construction firm recovers from a server failure in under four hours
Read moreProfessional Services

