Skip to content

Financial institutions

Penetration Testing for Banks and Credit Unions

Banks and credit unions answer to examiners who read the FFIEC handbooks, to card networks, and in New York to the Department of Financial Services, all of whom expect independent penetration testing. Invadel tests online banking, internal networks, and staff at a fixed price, with an attestation letter written for the exam file.

OSCP & OSCE3 certified testers150+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology
DTCCCity National BankBrewDogLuluEmeriaIP Telecom

The stakes

Why banks and credit unions get tested differently

Attackers target financial institutions for the money and for the trust. Account takeover of online and mobile banking through weak reset flows and session handling, business email compromise that ends in a fraudulent wire, ransomware that walks from a branch workstation to the core connection, and abuse of the file-transfer and VPN links to core and payment vendors are the patterns that recur in incident reports year after year.

The examiners arrive with expectations already written. The FFIEC Information Technology Examination Handbook treats penetration testing and vulnerability assessment as standard components of an institution’s assurance program. The FTC’s Safeguards Rule, which covers non-bank financial institutions, requires annual penetration testing and vulnerability assessments every six months, and bank and credit union examiners apply the same logic through their own guidance. New York-chartered and licensed institutions owe annual testing under NYDFS 23 NYCRR 500.5, and any card program brings PCI DSS.

A generic test misses the shape of a financial institution. Online banking is usually hosted by a digital banking vendor and can only be tested with that vendor’s authorization and within its rules. The internal network mixes branch workstations, teller systems, and back-office servers with vendor connections that must be handled with care. The report has to tie findings to the institution’s risk assessment and read the way an examiner expects. We scope, coordinate, and write for that audience.

What we test

The systems attackers go after first

01

Online and mobile banking

The customer and business banking portals and apps, often vendor-hosted, tested for account takeover, authorization flaws between customers, and weaknesses in enrollment, reset, and transaction flows.

02

Payment origination and vendor connections

Wire and ACH origination portals, file transfers to the core and card processors, and the VPN and API links to vendors, tested for the trust an attacker could borrow.

03

Branch and back-office network

Active Directory, teller and loan workstations, back-office servers, and the segmentation between them, tested from an assumed foothold for the path to the core connection.

04

Employee identity and email

The Microsoft 365 or on-premises identity that authorizes wires and approvals, tested for multi-factor gaps, mail-rule abuse, and the business email compromise paths that produce fraudulent payments.

05

Public website and loan applications

The marketing site and the online account and loan application forms that collect Social Security numbers and income data, tested for injection, exposure, and abuse.

06

Cloud and imaging systems

Document imaging, loan origination, and the cloud services that hold customer records, tested for identity and configuration paths that expose nonpublic personal information.

How it runs

Typical engagements

Illustrative scopes for this industry, written to show what a test covers and what you walk away with. They are not client stories; our anonymized engagements are on the case studies page.

Typical engagement

Community bank ahead of its information technology examination

A community bank with a handful of branches wants independent testing evidence before its next examination. We run an external test of the perimeter and remote access, an internal test from a branch workstation toward the core connection and the domain, and a phishing campaign across staff. The report ties each finding to the bank’s risk assessment, and the attestation letter goes into the exam file alongside the retest results.

Typical engagement

Credit union after a digital banking platform migration

A credit union has moved members to a new vendor-hosted online and mobile banking platform and wants its own assurance rather than the vendor’s. We obtain the vendor’s testing authorization, test the member portal and mobile apps with accounts in every role, and focus on enrollment, reset, and transfer flows. The credit union receives findings the vendor is obliged to fix and evidence for its examiners.

Typical engagement

New York trust company completing its annual NYDFS certification

A New York-chartered trust company needs the section 500.5 testing done before its annual certification of compliance. We scope external and internal testing to the systems that hold nonpublic information, coordinate windows with the operations team, and deliver a report structured around the regulation’s requirements with an attestation letter the compliance officer can reference in the certification.

FAQ

What banks and credit unions ask

01Do examiners require a penetration test?

The FFIEC handbooks treat penetration testing and vulnerability assessment as expected components of an information security program, and examiners ask for the results. The FTC Safeguards Rule makes annual penetration testing explicit for the non-bank financial institutions it covers, and NYDFS 23 NYCRR 500.5 makes it explicit for New York-regulated entities. In practice every institution we work with is asked for a recent independent test.

02Can you test our vendor-hosted online banking platform?

Yes, with the vendor’s authorization, which most digital banking providers grant through a standard testing policy. We handle the request with you, test within the vendor’s rules using accounts you control, and report findings in a form you can hand to the vendor for remediation. Testing your own instance is the only way to know how your configuration and your members’ data actually hold up.

03How much does penetration testing cost for a bank or credit union?

External network testing starts at $4,200, internal network testing at $6,000, web application testing at $5,200, and phishing campaigns at $3,600, each fixed in writing before work starts and each including a free retest. A typical annual program for a community institution combines external, internal, and phishing testing and is quoted as one number.

04How do you avoid disrupting operations?

Rules of engagement are agreed with your operations and IT teams before testing begins: windows, systems to handle with care, vendor connections that are off limits, and an emergency contact. We never use denial-of-service techniques, we coordinate any testing that touches payment systems, and internal testing is delivered remotely through a device we ship so no branch has to host a tester.

05How often should a financial institution test?

Annually at a minimum, which is what NYDFS 500.5, the FTC Safeguards Rule, and examiner expectations line up on, and again after a core conversion, a digital banking migration, a merger, or a significant change to remote access. Vulnerability assessments run more often, and phishing is best measured on a recurring schedule rather than once.

06Do you test staff for business email compromise and wire fraud?

Yes. Phishing, voice, and text campaigns are scoped to the roles that approve payments and change account details, with pretexts that mirror real fraud attempts. The report shows who clicked, who submitted credentials, who reported, and how fast, and a red team assessment can extend the exercise to an objective such as originating a test wire.

Get a fixed price for your institution's scope

Tell us what needs testing. You get a written fixed price within one business day, with the compliance mapping your auditors and customers expect.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.