Traditional Penetration Testing
The approach retained conventional penetration testing of the platform and its externally observable behaviour.
Deeper security assurance through an expanded testing methodology.
As a platform entrusted with sensitive employee and organisational data, security has been an important part of Crewmojo’s approach from the beginning. Since 2018, Crewmojo has commissioned annual penetration testing from independent cybersecurity specialists as part of its ongoing security program.
Year after year, those independent assessments produced strong results, with only informational observations and low-risk findings. Rather than simply accepting those results as confirmation that there was nothing more to investigate, Crewmojo wanted to challenge whether conventional penetration testing alone was providing the deepest level of assurance possible.
What else might be uncovered if security testers could examine not only how the application behaves from the outside, but how it is built?
For a multi-tenant HR platform, continually validating important controls such as authentication, identity management and secure data segregation is fundamental. Crewmojo therefore asked StickmanCyber to go beyond the conventional testing approach and conduct a deeper assessment with visibility into the platform’s underlying source code.
The approach retained conventional penetration testing of the platform and its externally observable behaviour.
StickmanCyber’s testers examined implementation details alongside the behaviour of the application itself.
The code-assisted approach added investigative pathways that are difficult to achieve through interface-based testing alone.
The value of the engagement was therefore broader than the individual findings. It demonstrated how combining different testing methodologies can provide additional layers of assurance, even for an organisation with an established security program and a long history of independent penetration testing.
With source-code visibility providing additional context and investigative pathways, StickmanCyber surfaced findings that had not been identified through previous penetration testing engagements. Crewmojo reviewed and remediated the identified findings, further strengthening the platform’s security controls.
The engagement was a natural next step in Crewmojo’s long-standing commitment to rigorous security testing. Code-assisted penetration testing has now become another layer in Crewmojo’s established security assurance approach.
We’ve independently tested Crewmojo’s security every year since 2018, but we’ve never been interested in simply getting a clean report. We asked StickmanCyber to go deeper because our approach has always been to keep challenging and strengthening our security.
Crewmojo continues to work with StickmanCyber annually, with the objective not simply of validating existing controls, but of continually challenging and strengthening the security of the platform.
Please complete the form below and schedule a meeting to discuss your cybersecurity challenge...