Case Studies

Selected engagements, anonymised. Each case represents real work delivered under NDA.

Financial Services · 2026

Critical Infrastructure Penetration Test

A multinational financial institution engaged Kryvasis to conduct a full-scope penetration test across their trading infrastructure, internal networks, and customer-facing platforms. The engagement uncovered 14 findings including a critical chain exploiting legacy federation protocols.

Remediation guidance was delivered as prioritised roadmap with proof-of-concept patches for the three highest-severity items.

14
Findings
3
Critical
4 wk
Engagement
Methodology

Threat modelling (STRIDE · PASTA) → surface mapping → exploitation → lateral movement → persistence testing → reporting with executive summary and technical annex.

All findings were reproduced in sandboxed environments. No production systems were disrupted.

Telecommunications · 2025

Firmware Patch Development for Legacy Edge Equipment

A tier-1 telecom provider identified a remote code execution vector in field-deployed edge routing equipment where the original vendor had ceased support. Kryvasis engineered a custom firmware patch at the kernel module level.

The patch was validated across 12 hardware revisions and deployed via signed OTA update with zero downtime.

12
HW Revisions
0
Downtime
6 wk
Engagement
Approach

Binary analysis of proprietary firmware → vulnerability reproduction → kernel module patch development → hardware validation → signed deployment pipeline.

↑