Skip to main content
ITSIGNSolutions
Confidential client

A municipal pentest that became a closed ticket list, not a PDF

Council had asked for a pentest. The last one sat unread. We scoped the systems residents actually use, ranked the paths, and retested the highs before the next council packet.

Public Sector and EducationPenetration Testing

0 open

High findings at retest

11

Weeks from kickoff to retest

None

Resident-facing outage

The challenge

A public-facing portal, an internal file estate and a VPN that still allowed password-only access. A prior report from two years earlier listed 90 findings with no owners. Staff were nervous that a test would take the website down during tax season.

What we did

We wrote rules of engagement that excluded denial of service and set a maintenance window for anything invasive. External testing ran first, then an assumed-breach internal test. Findings were ranked by path to resident data or payment, not by raw CVSS. Each high had an owner and a date. The retest was booked in the same quarter.

The outcome

Nine high findings, all closed or accepted in writing before the retest. VPN moved to MFA. The portal's privileged function was no longer reachable from a low-privilege account. Council received a two-page brief, not a 90-page appendix.

Let's talk about what you are running

A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.