Healthcare · 2026

Clearing enterprise security review after eleven failed attempts

Penetration testing, remediation support and SOC 2 readiness that unblocked eleven stalled enterprise deals and closed a critical patient-data exposure.

3 months Engagement length
4 specialists Delivery team
31 Findings remediated
11 Enterprise deals unblocked

The situation

What we walked into.

Every enterprise prospect was asking for a penetration test report and SOC 2 evidence, and the company had neither. Their platform handled patient records across web and mobile with an API that had grown organically for four years. Deals worth a significant share of forecast were sitting in procurement, indefinitely.

Client profile

Client Digital health provider
Industry Healthcare
Duration 3 months
Team 4 specialists

Approach

The decisions that mattered.

Not a chronology — the four calls that determined how the project turned out.

01

Full-surface testing

Web app, REST API, both mobile clients and the AWS estate, tested manually against OWASP ASVS and MASVS rather than handed to a scanner.

02

Same-day critical disclosure

An authorisation flaw allowing cross-tenant access to patient documents was reported and patched within nine hours of discovery, before testing continued.

03

Remediation alongside engineering

We paired with their developers on fixes instead of dropping a PDF, which is why 31 findings closed in six weeks rather than two quarters.

04

Evidence that scales

Semgrep and dependency scanning in CI, IAM least-privilege rework and documented controls, so the next audit is a report rather than a project.

What we shipped

Delivered scope.

  • Manual penetration test across web, API, mobile and cloud
  • Cross-tenant authorisation flaw identified and closed in nine hours
  • Prioritised remediation plan with code-level guidance
  • SAST, dependency and secret scanning in the CI pipeline
  • IAM least-privilege rework across all AWS accounts
  • SOC 2 gap assessment with control documentation and evidence

Technology

Burp Suite ProMobSFSemgrepProwlerAWS IAMGitHub ActionsOWASP ASVS

Results

What changed for the business.

31 / 31 Findings verified fixed at retest
0 Critical or high findings remaining
11 Enterprise deals moved out of procurement
9h Critical disclosure to patch
  • Attestation letter accepted by every enterprise security team it was submitted to.
  • SOC 2 Type I achieved four months after the gap assessment.
  • Security review moved into their definition of done, with quarterly automated scanning.
They found in one afternoon what two scanning vendors missed in a year, then sat with our engineers until every finding was actually closed.
CT Chief Technology Officer
Digital health provider

Your project

Have a comparable problem?

Tell us where you are stuck. You will get a senior response within one business day, including whether we think we are the right team for it.