
ACA Asuransi
Vulnerability Assessment, Penetration Testing & Patching System
A comprehensive security test of ACA Asuransi’s main site and partner portal, followed by hands-on remediation support until every finding was closed.
- Year
- 2025
- Duration
- 5 months
- Project value
- Rp 950 million
- Sector
- Insurance
Challenge
As an insurer, ACA handles sensitive customer and agent-partner data across several connected web applications. It needed an honest, attacker’s-eye view of its risk and a team that would make sure fixes were actually applied, not just reported.
Scope of work
- Asset and attack-surface mapping for the main site and partner portal
- Automated and manual vulnerability assessment based on the OWASP Top 10
- Controlled penetration testing on an agreed schedule without disrupting production
- Findings report with risk ratings, evidence, and technical recommendations per finding
- Patching support alongside the internal team, followed by retesting for verification
Outcome
- Findings prioritised by business risk so critical fixes went first
- Every fix re-verified through retesting before closure
- ACA’s internal team received secure-development guidance for future work
Security findings are confidential and reported to the client only.
Have a similar project?
Tell us what you need. We’ll help you define the scope, timeline, and cost estimate.
