Banking assessments do not change much across borders. The regulator changes, the reporting format changes, and the risk model stays almost identical, because the things that hurt a bank are the same things everywhere: authorisation between accounts, transaction integrity, and the paths into the estate that nobody documented.
What travels and what does not
Our method travelled unchanged. The regulatory mapping did not: findings were framed against the obligations the bank actually answers to rather than against CERT-In or RBI, because a report that cites the wrong regulator is a report the client has to translate before it is useful.
This is worth stating because it is the part firms get wrong when they work outside their home market. The testing is portable. The reporting is not.
Where the work concentrated
Authorisation between customer accounts, which is the finding class with the most direct consequence in a banking application. Transaction handling, including whether state could be manipulated through timing or replay. Session management across channels. And the internet facing infrastructure, which on any bank of scale includes systems that predate the current security team.
Remediation and retesting
Every finding was retested after remediation. On banking engagements we also retest adjacent functionality, because a fix applied to one transfer path frequently leaves an equivalent path untouched.
What was handed over
Findings with reproduction and business impact, an executive summary for the bank's leadership, remediation guidance, and retest evidence.












