Home / Work / Cybersecurity Audit
CASE STUDY · FINANCE · SECURITY

Pass the bank’s review,
or lose the client.

A high-profile event management company handling VIP data for financial institution clients. First Arab Bank required ICC compliance before the relationship could continue. The audit had to find and close every gap — with a fixed deadline and absolute reputational stakes.

Client
BLS Events
End-client
First Arab Bank
Standard
ICC compliance
Scope
Web, network, storage, physical
Data class
VIP personal data
Result
Full compliance achieved
ICC
Compliance achieved
0
Critical findings left open
4
Attack surfaces assessed
1
Fixed, non-negotiable deadline
/ 01
The Problem

BLS Events managed guest lists, personal details and sensitive information for high-profile banking events hosted by First Arab Bank. When the bank’s security team reviewed the arrangement, they flagged gaps in how VIP data was stored, transmitted and accessed by event staff.

ICC compliance was the threshold — without it, the contract would not continue. The deadline was fixed, and a surface-level audit report would not survive the bank’s internal review.

The uncomfortable part of this class of engagement is that the client is paying you to find things that are expensive for them to fix, on a deadline, while a third party grades the result.

/ 02
The Approach

We conducted a full penetration test and vulnerability assessment across web applications, internal network, data storage practices and access control systems — going well beyond automated scanning to manually verify privilege escalation paths, encryption in transit and at rest, API authentication, and physical access controls at event venues.

Every point where VIP personal data touched an external system or third-party integration was mapped, because that boundary is where this kind of data actually leaks.

Findings were delivered as a severity-tiered remediation roadmap with named owners and verification checkpoints — structured so the bank’s security team could audit the remediation, not just read a claim of it.

/ 03
The Hard Parts
  1. Auditing physical process, not just systems VIP guest data at an event exists on printed lists, on staff devices and in conversations at a registration desk. An assessment limited to the network would have passed a system that leaked at the door.
  2. Third-party integration boundaries The riskiest data movements were into tools the client considered ordinary — mail, sharing links, ad-hoc exports. Mapping them surfaced exposure nobody had characterised as a security decision.
  3. Producing a report that survives external review The deliverable was graded by a bank’s security function. Findings needed evidence, reproducible steps and verifiable closure — the standard of proof is materially higher than an internal audit.
  4. Remediating inside a fixed window Severity tiering mattered because not everything could be fixed at once. Sequencing had to guarantee that every critical and high finding closed before the deadline.
/ 04
The Outcome

All critical and high-severity findings were remediated within the compliance timeline. ICC certification was achieved, the bank’s security team signed off on the audit report, and the client relationship continued.

Beyond compliance, the engagement produced architectural improvements the client kept: unified access logging, encrypted event data export workflows, and a formal data retention and destruction schedule that had not previously existed.

Stack Penetration testing OWASP Top 10 Network analysis API security Access control review Encryption audit ICC compliance ISO 9001 Physical security assessment

Compliance isn’t paperwork when
the contract depends on it.

BEFORE SOMEONE ELSE FINDS IT

Your largest client’s security team
will audit you eventually.

Contact Us →