Skip to content
Sentinel Black
Mandates on authorised scope only. Sentinel Black accepts only authorised, written mandates, and it also retains nothing afterwards.

Briefing

Penetration testing for banks: a briefing for the board and the CISO

Penetration testing for banks is judged twice: once by your security team, and again by the examiner who reads the report. So the mandate has to produce evidence that survives both readings.

  • Principal-led mandates
  • Fixed fee agreed in writing
  • Nothing retained afterwards
Penetration testing for banks: agree the mandate, test the estate and brief the board

Why penetration testing for banks is different

Banks hold money, identity and trust at the same time. Therefore an attacker's objective is clearer, and the cost of a gap is higher. Also, examiners usually expect independent testing as part of the information security programme, as the FFIEC Information Security booklet describes.

What penetration testing for banks usually covers

The scope is set by the mandate, and the system owner signs it before any work begins.

  • Online and mobile banking channels
  • The internal estate around core banking systems
  • Payment and transfer approval workflows
  • Third-party connections and remote access
AudienceWhat they needSection of the report
BoardRisk in business terms.Executive summary.
CISORoutes and priorities.Findings and remediation.
ExaminerIndependence and method.Scope and methodology.

Prepare for penetration testing for banks

Tick what is ready. Open items are settled in the engagement letter.

Your result appears here as you tick, so you can see what is still open.

Regulator-led schemes are separate

Some regulators run their own testing schemes. For example, CBEST in the United Kingdom uses its own approved providers and process. So a Sentinel Black mandate is an independent test, not a regulator-led exercise, and we say so in writing.

How a bank mandate is run

A senior professional hacker leads every mandate personally, from scoping to the board debrief. In addition, nothing is subcontracted, and evidence moves only over encrypted channels. Then everything is destroyed when the engagement closes. The method follows the Penetration Testing Execution Standard and NIST SP 800-115.

Fees for penetration testing for banks

Full mandates run from $35,000 to $120,000, while the floor is $25,000. Also, the bounded Exposure Assessment starts at $4,500. Moreover, its fee is credited in full against a full engagement commissioned within ninety days. One fixed fee is agreed after the written scoping brief, then invoiced against milestones.

Questions on penetration testing for banks

How often should penetration testing for banks happen?

At least yearly, and after significant change. Your examiner's expectations set the floor.

Is penetration testing for banks a CBEST test?

No. CBEST is a separate regulator-led scheme with its own approved providers.

Will the report satisfy an examiner?

The report documents scope, method and independence. However, the examiner reaches their own view.

Who reads the findings?

Only the people named in the engagement letter, under a mutual non-disclosure agreement.

Related guides

Request an introduction

Describe the systems the board is most concerned about. A senior professional hacker replies within one business day when the mandate is a fit.

Request an introduction