Investor Due Diligence - Application Service Provider
Client
commissum, acting on behalf of a syndicate of investors that included two global banks, was engaged to undertake an Information Security audit as part of the technical due diligence of a potential target for significant investment. A satisfactory outcome was one of the mandated prerequisites to securing the additional funding.
Client Requirement and Business Drivers
The subject of the review was a leading provider of on-line digital document and information management services. Their clients include a number of well know names within the commercial sector and local government.
The main business drivers were:
enabling
- satisfying investors of the fact that appropriate levels of security were inherent in the company’s delivery mechanism and their operations was a prerequisite to securing funding for the target organisation and fundamental to the investors realising a return
- By the nature of the ASP’s business, ensuring a sound Information Security environment is fundamental to protecting the confidentiality of their client's data, and to their ongoing business success
risk reduction
- both the inadvertent and potential intentional, malicious exposure of client information was to be a top priority
- the ASP was continually improving it’s delivery platform through its in-house development team – it was essential that this ongoing development activity followed a rigorous process that would minimise the risk of later changes undermining current security levels
Operating within a carefully defined scope, commissum undertook to provide objective evidence of the security of the investment from an Information Security perspective.
commissumServices Provided
There were four parts to the audit.
- a review was undertaken of the software development lifecycle and management processes, driven by the importance of the unique, core application, which as part of the investment was to be significantly improved by an in-house development team – the investors wanted reassurance that the company environment would support the planned development, particularly with respect to security awareness being an inherent element of the process
- the unique core application was subjected to a detailed application security review and penetration test – this included “black box” security testing as an external unauthorized attacker, and “white-box” security testing from the perspective of both an external and internal authorised user
- internal and external infrastructure penetration testing was conducted
- a security audit of the operations at one of the ASP’s data-centres was carried out against the ISO27001 framework
The assignment provided direct evidence of the security measures taken to date, and that security risks were appropriately identified and acted upon. commissum presented findings to the investor syndicate. As a result of this and the company’s demonstrated positive approach to adopting recommendations made by commissum, the company was successful in securing its funding.
- Case Study 1 - Online Banking Project Assurance
- Case Study 2 - Government Data Handling, BCP & ISO27000 consultancy
- Case Study 3 - Oil & Gas Industry - Asset Tracking System Project Assurance
- Case Study 4 - Professional Institute - Strategic Security Review
- Case Study 5 - Government Agency - Business Continuity Exercise
- Case Study 6 - Government Agency - CLAS Services for Accreditation
- Case Study 7 - National Engineering Group - Security Programme
- Case Study 8 - Application Service Provider - Investor Due Diligence
- Case Study 9 – Global Legal Firm - Annual Test Programme & Security Partnership
- Case Study 10 - Investment Bank - Secure Application Development Training
Get in touch with one of our security consultants today
- No obligation
- Expert advice
- Tailored solutions
"commissum recently provided us with services to assess a web application and supporting infrastructure. I was impressed with the consultants throughout the project, by their technical knowledge, flexibility, open communication and willingness to go that extra mile. Of particular benefit was the sound advice given both during and after the engagement. By identifying vulnerabilities promptly, accompanied with practical recommendations on how to address them. We were able to implement improvements quickly. Good value, a job well done.”
JM, Infosec Analyst, International Investment Bank
"commissum recently provided invaluable advice and support, ensuring the success of our secure remote access project, and has provided us with annual penetration testing and managed service scanning for several years. I would happily recommend commissum to others for their professionalism and quality of service.”
Mr Tim R, IT Director, International Law Firm


