Bank Pentest: Penetration Testing That Follows the Money, Not the Checklist.
A bank does not fail through its website. It fails through a service account, a trust nobody owns, or a workstation one hop from the wire room.
Our bank pentest is scoped around the six trust boundaries that actually move money: digital banking channels, payment and wire workflows, core-banking integrations, Active Directory privileged paths, vendor and MSP access, and cloud identity. Every finding is a proven attack path with its business consequence, mapped to the FFIEC, NYDFS Part 500, PCI DSS or DORA requirement your examiner will cite. Fixed price, report in 14 days, free retest.
- Attack paths chained end to end, not a scanner export with a cover page
- Findings mapped to the regulatory section an examiner would cite
- Written rules of engagement: no funds moved, no downtime, a stop condition

Senior-led testing scoped to the way a bank is actually put together: hosted core, branch network, payment operations and the suppliers between them.

Leads every bank pentest personally and signs the attestation letter your examiner reads.
Connect on LinkedInWhat a Bank Pentest Actually Tests
A generic penetration test scopes by technology: one web app, one IP range. A bank pentest scopes by trust boundary, because that is how the money is protected and how it is stolen. Six boundaries cover almost every bank we have assessed.
Digital banking channels
Customer web and mobile banking: session and step-up logic, beneficiary management, payment initiation limits, and whether one customer can ever see or act on another’s account.
Payment and wire workflows
The path from an operator’s desk to a released wire or ACH file: approval separation, the jump hosts and shared drives in between, and what a compromised workstation can reach.
Core-banking integrations
The service accounts, interfaces and file transfers that connect you to your hosted core. These carry the platform’s own permissions and are where the findings that matter most tend to sit.
Internal network and Active Directory
Privileged paths from a standard workstation to domain administration, the trusts left behind by acquisitions, and the credentials cached where they should not be.
Vendor and MSP access
Remote management agents, support accounts and partner VPNs that arrive with standing privilege. A supplier compromise is a bank compromise if that access reaches the core.
Cloud and Microsoft 365
Identity, conditional access, mail rules and the storage that holds statements, loan files and board packs. Increasingly where the customer data actually lives.
The Attack Paths That Repeat in Banks
These are not hypotheticals. They are the findings that recur across the financial-institution environments we assess, from single-charter community banks to a six-country group with 8,000 staff. Most of them are invisible to a vulnerability scanner because nothing is unpatched; the weakness is in who can reach what.
Core-platform service accounts with the original password
Accounts wired into the core-banking connection at deployment and never rotated since. Kerberoastable, and once cracked they carry the permissions of the platform itself.
A teller workstation to the wire room in one hop
A single Active Directory path from a standard branch workstation to the jump host that releases wires. It exists in most banks we assess and it is the finding boards remember.
Domain trusts from a prior acquisition
The merged institution’s domain is still trusted, still has Domain Admin-equivalent paths, and nobody currently owns it.
MSP remote-management agents under a standing Domain Admin
The vendor’s convenience becomes your largest single exposure. One compromised support session reaches everything the agent can.
Authorisation gaps in open-banking APIs
Object-level authorisation that trusts the account identifier in the request, mass assignment on beneficiaries, and payment limits enforced only in the mobile app.
Account takeover through recovery and step-up
Password reset, device re-enrolment and support-assisted recovery that lead straight to a new payee and an outbound transfer, with no cooling-off.
What the Report Has to Prove, and to Whom
A bank pentest report has two readers who want different things. The engineer wants reproduction steps and a fix. The examiner wants to see that the institution tested independently, understood the risk, and closed it. Most pentest reports serve the first reader and leave the second one to reconstruct the evidence.
Ours carries both. Every finding is mapped to the regulatory section it bears on, the executive summary states the headline numbers a board can read in two minutes, and the retest and attestation letter close the loop for the exam file.
For institutions designated under DORA there is a separate, heavier regime, TLPT for DORA, which we also deliver. For card environments the pentest is scoped to PCI DSS requirement 11.4 as well.

Rules of Engagement for Live Banking Systems
Testing a bank in production is a governance exercise as much as a technical one. Before anything is touched, both sides sign rules that a risk committee can read.
- No funds move. Payment paths are proven to the point of authorisation and documented. We never submit a transaction.
- No availability impact. No denial-of-service techniques, agreed windows for anything that touches the core connection, and rollback steps written before use.
- A named contact and a stop word. One escalation contact on each side, reachable throughout, and a written condition under which testing halts immediately.
- Evidence handling. Any customer data encountered is redacted at capture, held encrypted for the engagement only, and destroyed on a documented date.
- Vendor boundary respected. Hosted core platforms are tested at the integration surface, inside the vendor’s own testing terms.
How the Engagement Runs
Five steps, fixed price agreed at the first one, report inside fourteen days of the third.
Scoping call
Which boundaries matter to your charter, your core vendor and your examiner. Fixed price and timeline in writing.
Rules of engagement
Test windows, escalation contacts on both sides, the no-funds-movement rule for payment rails, and a written stop condition.
Manual testing
Senior-led, attack paths chained end to end against the agreed scope. Tools for breadth, people for the part that finds money.
Report and workshop
Findings register with reproduction steps, executive summary with regulatory mapping, and a live remediation session with your engineers.
Retest and attestation
Free retest after you fix, then an attestation letter signed by a named qualified individual, addressed to the board.
Bank Pentest Pricing
Each scope is a fixed price. Combined scopes go into one proposal with volume pricing, and you approve the total before anything starts.
| Scope | What is covered | Testing | Price |
|---|---|---|---|
| External perimeter | Internet-facing IP ranges, DNS, mail, remote access | 5-7 days | From $4,000 |
| Open-banking and partner APIs | Up to 50 endpoints, authorisation-focused | 5-7 days | From $4,000 |
| Digital banking web application | 1 application, all customer and operator roles | 7-10 days | From $5,000 |
| Internal network and Active Directory | Internal ranges plus privileged-path analysis | 7-10 days | From $5,000 |
| Cloud or Microsoft 365 | Identity, conditional access, storage, mail rules | 7-10 days | From $5,000 |
| Mobile banking application | iOS or Android plus its API | 10-14 days | From $6,000 |
Every scope includes the findings register, the executive summary with regulatory mapping, the remediation workshop, a free retest and the attestation letter. A full Active Directory assessment with examiner-ready evidence is priced separately on the AD security assessment page.
For small projects and ad-hoc work outside our pre-agreed packages or retainers, our standard hourly rate is $460.
Bank Pentest, Vulnerability Scan, or TLPT
Three different controls that get bought as if they were one. Examiners know the difference; the report has to show you do too.
Designated under DORA? The threat-led penetration test is a separate, regulator-validated exercise that runs alongside the annual pentest rather than replacing it.
Who Commissions a Bank Pentest
Find Out What a Teller Workstation Can Reach
One scoping call. Bring your last pentest report, your examiner’s request, or nothing at all. You will leave with a scope written as questions, a fixed price, and a date for the report.
Scope My Bank PentestBook the Scoping Call
Bank Pentest FAQ
What is a bank pentest?
How is a bank pentest different from a vulnerability scan?
Which regulations require penetration testing for banks?
Do you test production banking systems?
Can a pentest touch our core banking platform?
Will the report satisfy an examiner or close an MRA?
How long does a bank pentest take?
What does a bank pentest cost?
Do you test open banking and partner APIs?
We are designated for TLPT under DORA. Is this the same thing?
Do you work with credit unions and community banks?
Related Services
Penetration testing - TLPT for DORA - Active Directory security assessment - PCI DSS compliance - DORA compliance - MAS TRM - Fintech virtual CISO - bankpentest.com