<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=9291417&amp;fmt=gif">
Customer story

See how Crewmojo raised the bar on security testing

Deeper security assurance through an expanded testing methodology.

Going beyond a clean report

Crewmojo is a Sydney-based HR Tech SaaS company providing customisable workflows for performance management, employee engagement, feedback and goal setting.

As a platform entrusted with sensitive employee and organisational data, security has been an important part of Crewmojo’s approach from the beginning. Since 2018, Crewmojo has commissioned annual penetration testing from independent cybersecurity specialists as part of its ongoing security program.

Year after year, those independent assessments produced strong results, with only informational observations and low-risk findings. Rather than simply accepting those results as confirmation that there was nothing more to investigate, Crewmojo wanted to challenge whether conventional penetration testing alone was providing the deepest level of assurance possible.

  • Annual independent penetration testing since 2018
  • Sensitive employee and organisational data at stake
  • Multi-tenant controls requiring continuous validation
  • A desire to test implementation, not only behaviour

The question

What else might be uncovered if security testers could examine not only how the application behaves from the outside, but how it is built?

For a multi-tenant HR platform, continually validating important controls such as authentication, identity management and secure data segregation is fundamental. Crewmojo therefore asked StickmanCyber to go beyond the conventional testing approach and conduct a deeper assessment with visibility into the platform’s underlying source code.

The engagement

Crewmojo engaged StickmanCyber to complement its established security testing program with a 14-day code-assisted penetration test.

Traditional Penetration Testing

The approach retained conventional penetration testing of the platform and its externally observable behaviour.

Controlled Source Code Access

StickmanCyber’s testers examined implementation details alongside the behaviour of the application itself.

Another Layer of Scrutiny

The code-assisted approach added investigative pathways that are difficult to achieve through interface-based testing alone.

The outcome

The deeper methodology validated Crewmojo’s decision to challenge the conventional approach.
  • 14 Days
    Focused engagement
  • 4 Control Areas
    Examined in depth
  • 2018 Since
    Annual testing relationship
  • + Additional Findings
    Not identified in previous engagements
Importantly, the engagement reinforced a principle that has underpinned Crewmojo’s approach to security for many years: a clean security assessment should provide assurance, but it should never be a reason to stop challenging assumptions or looking for ways to test more deeply.

The value of the engagement was therefore broader than the individual findings. It demonstrated how combining different testing methodologies can provide additional layers of assurance, even for an organisation with an established security program and a long history of independent penetration testing.

Critical areas of the security architecture

With source-code visibility providing additional context and investigative pathways, StickmanCyber surfaced findings that had not been identified through previous penetration testing engagements. Crewmojo reviewed and remediated the identified findings, further strengthening the platform’s security controls.

01

Authentication

02

Password management

03

Microsoft Single Sign-On

04

Secure tenant data segregation

Raising the standard

The engagement was a natural next step in Crewmojo’s long-standing commitment to rigorous security testing. Code-assisted penetration testing has now become another layer in Crewmojo’s established security assurance approach.

5.0 on G2 Trusted Cybersecurity Partner
We’ve independently tested Crewmojo’s security every year since 2018, but we’ve never been interested in simply getting a clean report. We asked StickmanCyber to go deeper because our approach has always been to keep challenging and strengthening our security.
Crewmojo Sydney-based HR Tech SaaS company

Keep challenging and strengthening security

Crewmojo continues to work with StickmanCyber annually, with the objective not simply of validating existing controls, but of continually challenging and strengthening the security of the platform.

 

Book a free consultation today

  Please complete the form below and schedule a meeting to discuss your cybersecurity challenge...