D Commerce Bank case study: Strengthening mobile app and API security

Aug 20, 2026

8 min read

Share:

D Commerce Bank case study: Strengthening mobile app and API security

D Commerce Bank engaged Cyberware to conduct an independent mobile application penetration test and API security assessment of its digital banking ecosystem, covering the Bank's iOS and Android banking applications and the services behind them. The engagement was structured to deliver deep technical validation, operational stability throughout testing, and clear executive reporting for the Bank's internal risk management and governance teams.

For a modern financial institution, the mobile channel is a tier-1 digital service. It must deliver a seamless customer experience while strictly meeting expectations for data protection, cryptographic resilience, and operational compliance. D Bank approached the project as part of an ongoing commitment to maintaining trust in the digital services its customers use every day, and asked for an assessment that would be as useful to the board as it was to the engineering team.

The problem: Complex mobile threat landscape

Digital banking environments are built from interconnected, high-value components. Client-side mobile applications, biometric authentication flows, backend API endpoints, third-party SDKs, and internal transaction workflows all operate inside the same ecosystem, and a weakness in any one of them is a weakness in the channel as a whole. Verifying the security of that ecosystem requires independent, expert validation mapped to modern threat vectors and regulatory expectations, not a checklist exercise.

D Commerce Bank needed a comprehensive external assessment capable of identifying vulnerabilities without disrupting live banking services, exposing sensitive internal architecture, or overwhelming leadership with uncontextualised technical data. The challenge was to deliver actionable, code-level detail to developers while translating the same findings into clear risk metrics for executive stakeholders and governance committees.

Banking also operates under close regulatory scrutiny. The assessment had to stand up as evidence for auditors, supervisors and internal governance committees, which meant a defined methodology, an agreed scope and documentation that could be presented without further translation. That expectation shaped the engagement from the first planning session onward.

The solution: Threat-modelled, framework-driven assessment

Cyberware executed a controlled, independent Mobile Application Security Test (MAST) and architectural review of the in-scope ecosystem across both iOS and Android. The methodology followed the OWASP Mobile Application Security (MAS) framework and international financial-industry benchmarks, with every phase agreed in advance: project alignment, controlled assessment activity, documentation, executive reporting, technical reporting for internal use, and a final presentation of the outcomes.

The assessment scope covered:

  • Client-side code resilience: the integrity of the shipped applications and their resistance to inspection, tampering, and instrumentation on untrusted devices.

  • Authentication and session integrity: login, biometric enrolment, and session lifecycle handling across the mobile and token applications.

  • API security testing: the backend endpoints serving the mobile channel, including authorisation boundaries, object-level access control, and input handling.

  • Configuration management: platform, transport, and build configuration across environments and release variants.

  • Payment and transaction flows: the business logic behind customer-initiated operations and the controls that protect it.

The delivery model focused heavily on data synthesis. Rather than handing over a raw vulnerability dump, the team contextualised every finding against the Bank's own business logic to show what it would actually mean if exploited. Findings were then prioritised by risk severity, producing a clear remediation roadmap for technical teams and a structured risk overview for compliance officers, drawn from the same underlying evidence.

Strategic alignment: Merging technology and governance

In financial services, security testing is not only a technical activity. It is a pillar of operational resilience, and a successful assessment has to bridge the gap between individual technical flaws and enterprise risk management. If the two never meet, engineering fixes bugs that leadership cannot see the value of, and leadership sets priorities that engineering cannot act on.

Cyberware's approach made the engagement a shared foundation for leadership, technology, and governance and compliance teams. By combining threat modelling and business-logic analysis with traditional penetration testing, the work let D Commerce Bank see its mobile applications through the eyes of a sophisticated adversary while keeping every piece of communication anchored in corporate risk standards.

"In banking, our mobile application is our primary customer relationship hub. Ensuring its absolute security without disrupting daily operations requires a partner who understands both elite offensive security and strict corporate governance. Cyberware delivered a high-quality, independent mobile application penetration test and API security assessment across our iOS and Android platforms. Mapped against the rigorous OWASP framework and ISO standards, their team thoroughly validated our security. What set Cyberware apart was their delivery: they provided our engineering teams with a prioritised, code-level technical remediation blueprint, while giving me and our board a clear executive risk analysis."

Chief Information Security Officer

D Commerce Bank

D Commerce Bank

The result: Validated posture and actionable assurance

D Commerce Bank received a professionally documented, comprehensive view of its security posture across its core mobile applications and the supporting API infrastructure. The engagement delivered independent validation of a critical customer-facing channel and improved internal visibility across mobile application assurance, backend services, and operational planning.

Management received a concise view of the project, its purpose, and its relevance to the Bank's wider digital assurance programme. Internal teams received structured documentation they could use immediately to plan and sequence follow-up work. Both audiences were reading the same engagement from the perspective that mattered to them, which is what allowed the results to move quickly from report to roadmap.

The ultimate value came from the depth of the technical work and the speed with which it could be acted on. D Commerce Bank used the outcomes to optimize its internal engineering roadmap, evidence its assurance activity to internal governance, and enter its next release cycle with an independently validated view of a critical customer-facing channel.

Recommendations for the financial sector

Cyberware recommends that financial institutions treat independent mobile application and API testing as a recurring milestone in their digital governance lifecycle rather than a one-off project. In practice, that means the following.

  1. Test before major releases and architectural migrations

    Schedule assessment ahead of significant application releases or core architectural changes, while there is still time to act on the results. Testing after a release turns findings into emergency work; testing before it turns them into ordinary backlog items.

  2. Reassess when customer-facing functionality changes

    New capability changes the attack surface. Biometric updates, open banking APIs, new payment rails, and new third-party SDKs each warrant a fresh look, even when the surrounding application is unchanged.

  3. Assess the app and its APIs as one system

    A mobile application is a client for a set of backend services, and most of the real risk lives at that boundary. Testing the app in isolation, or the APIs in isolation, misses exactly the authorisation and business-logic flaws that matter most in banking.

  4. Pair technical depth with executive reporting

    The highest return on security investment comes when deep technical validation is delivered alongside a clear executive risk analysis, a practical remediation playbook, and explicit alignment to business risk. One report, two audiences, no translation lost in between.

  5. Extend validation into the code and the wider programme

    Complement assessment with a security code review of the components handling authentication, cryptography, and transaction logic, and fold the results into your governance, risk, and compliance programme so that each engagement builds on the last instead of starting from zero.

Pressing questions

  • Why does this case study not name specific vulnerabilities?

    Technical findings belong in the report delivered to the client's engineering and risk teams, which is standard practice for assessments of this kind. What is useful to share publicly is the approach, the structure of the engagement, and the outcome, which is exactly what this case study covers.

  • Is a mobile application test the same as an API test?

    No, and running only one of them leaves a gap. Mobile testing examines the shipped client: storage, cryptography, tamper-resistance, and platform configuration. API testing examines the services behind it: authorisation boundaries, object-level access control, and business logic. D Commerce Bank's engagement covered both, because attackers do not respect the boundary between them.

  • Does an assessment like this disrupt live banking services?

    It should not, and this one did not. Scope, timing, test data, and escalation paths are agreed before any activity begins, and assessment is conducted under controlled conditions with defined limits. Operational stability is a requirement of the engagement, not a hoped-for side effect.

  • How often should a bank test its mobile banking applications?

    At minimum, on a recurring annual cycle, plus before major releases, after architectural changes, and when new customer-facing functionality is introduced. Mobile release cadence is fast, and an assessment describes the application as it was on the day it was tested, not as it ships six months later.

Key takeaways

D Commerce Bank set out to validate the security and cryptographic resilience of its iOS and Android mobile banking applications and the APIs behind them. Cyberware delivered threat-modelled penetration testing mapped against OWASP and ISO standards, run as a controlled, professionally structured engagement that did not interrupt live banking services.

The impact was felt on both sides of the organisation. Technical teams received a prioritised, code-level remediation blueprint they could act on immediately; executives received independent assurance in the language of corporate governance, operational resilience, and customer trust. That combination is what turns a security assessment from a compliance artefact into a decision-making tool.

If your institution is planning a mobile release, integrating new customer-facing functionality, or building out a continuous assurance programme, talk to our team about an independent penetration test of your mobile applications and APIs.