Briefing
Penetration testing for banks: a briefing for the board and the CISO
Penetration testing for banks is judged twice: once by your security team, and again by the examiner who reads the report. So the mandate has to produce evidence that survives both readings.
- Principal-led mandates
- Fixed fee agreed in writing
- Nothing retained afterwards
Why penetration testing for banks is different
Banks hold money, identity and trust at the same time. Therefore an attacker's objective is clearer, and the cost of a gap is higher. Also, examiners usually expect independent testing as part of the information security programme, as the FFIEC Information Security booklet describes.
What penetration testing for banks usually covers
The scope is set by the mandate, and the system owner signs it before any work begins.
- Online and mobile banking channels
- The internal estate around core banking systems
- Payment and transfer approval workflows
- Third-party connections and remote access
| Audience | What they need | Section of the report |
|---|---|---|
| Board | Risk in business terms. | Executive summary. |
| CISO | Routes and priorities. | Findings and remediation. |
| Examiner | Independence and method. | Scope and methodology. |
Prepare for penetration testing for banks
Tick what is ready. Open items are settled in the engagement letter.
Your result appears here as you tick, so you can see what is still open.
Regulator-led schemes are separate
Some regulators run their own testing schemes. For example, CBEST in the United Kingdom uses its own approved providers and process. So a Sentinel Black mandate is an independent test, not a regulator-led exercise, and we say so in writing.
How a bank mandate is run
A senior professional hacker leads every mandate personally, from scoping to the board debrief. In addition, nothing is subcontracted, and evidence moves only over encrypted channels. Then everything is destroyed when the engagement closes. The method follows the Penetration Testing Execution Standard and NIST SP 800-115.
Fees for penetration testing for banks
Full mandates run from $35,000 to $120,000, while the floor is $25,000. Also, the bounded Exposure Assessment starts at $4,500. Moreover, its fee is credited in full against a full engagement commissioned within ninety days. One fixed fee is agreed after the written scoping brief, then invoiced against milestones.
Questions on penetration testing for banks
How often should penetration testing for banks happen?
At least yearly, and after significant change. Your examiner's expectations set the floor.
Is penetration testing for banks a CBEST test?
No. CBEST is a separate regulator-led scheme with its own approved providers.
Will the report satisfy an examiner?
The report documents scope, method and independence. However, the examiner reaches their own view.
Who reads the findings?
Only the people named in the engagement letter, under a mutual non-disclosure agreement.
Related guides
Request an introduction
Describe the systems the board is most concerned about. A senior professional hacker replies within one business day when the mandate is a fit.
Request an introduction