Skip to content
TheoSec

Offensive security for fintech

There's always a way to the money.

Rarely a missing patch. Usually an approval that trusts the wrong field, or a ledger that believes two requests were one.

90 minutes · No cost · Mutual NDA before anything is discussed

A worked example

Three findings nobody would fix.

Two Lows and a Medium. Each survives a scan, a triage meeting and a quarter of backlog grooming. Read together, they move money out of an account that is not yours.

  1. Partner APILow

    An error message leaks the account ID format

  2. Password resetLow

    Old sessions stay valid after a reset

  3. Payment approvalMedium

    Approval checks the role, not the tenant

Critical

An approver in one tenant releases another tenant’s payment

Funds leave with a valid approval recorded against them.

No scanner rates this chain. Nothing in the code says approval is supposed to be bounded by tenant — that only comes out of a working session with your engineers.

Where we work

Financial services only.

One sector, tested properly. We turn down everything else, which is why we start already knowing what a settlement file is for.

Payments & cards
PSPs · Acquirers · Issuers · Gateways
Authorisation → Settlement
Banking & BaaS
Core banking · Open Banking · Sponsor banks
Deposit → Transfer
Lending & credit
Underwriting · Bureau data · Disbursement
Decision → Disbursement
Digital assets & trading
Exchanges · Custody · Brokerage
Custody → Withdrawal

Capabilities

Five ways to find out where you stand.

Every engagement runs the same methodology. What changes is the surface, the duration, and how much of your organisation is in scope.

00By invitation · 90 minutes · No cost

Executive Adversary Briefing

A private session with your leadership on how someone would actually come after your money: the groups working financial services right now, what your public footprint already gives away, and the three routes in we would try first. We give away the thinking, not a scan.

  • Threat actors currently working financial services
  • What your public footprint already discloses
  • The three routes in we would try first
  • Straight answers, in the room, no report to chase
Explore Executive Adversary Briefing
01Six-month engagement · Continuous

Managed Red Team

A standing adversary for a business that ships weekly. Continuous offensive testing across your platform and your people, with reporting your board and your regulator can both read.

  • Baseline assessment in month one
  • Weekly external testing & OSINT monitoring
  • Three social engineering campaigns monthly
  • Evidence that satisfies an annual testing obligation
Explore Managed Red Team
02Objective-based · Full-scope

Red Team Assessment

Not a list of vulnerabilities — a single question, answered honestly. Can a capable adversary move money, reach the ledger, or approve something they should not? Technology, people and process are all in scope, because they are all in scope for the people who mean it.

  • A money-movement objective, not a coverage checklist
  • Technology, people and process in one engagement
  • Detection and response measured as you go
  • Full attack narrative, first contact to objective
Explore Red Team Assessment
03Point-in-time · Scoped to you

Penetration Testing

Manual testing of the systems that move and account for money — payment flows, Open Banking APIs, ledgers and the cloud they run on. Reported in plain language, prioritised by what it would actually cost you.

  • Payment, transfer and approval flows
  • Open Banking, partner and internal APIs
  • Cloud estate and identity (AWS, Azure, GCP)
  • Mobile banking and trading applications
Explore Penetration Testing
04Ongoing · Human-crafted

Phishing & Social Engineering

The pretexts that actually work against financial firms — a payment query from a known merchant, an urgent request from a sponsor bank, a support call about a frozen account. Written by an operator, never from a template library.

  • Email, SMS, voice and social channels
  • Pretexts built from your real payment relationships
  • Support-desk and approval-process testing
  • Teachable-moment training at the point of failure
Explore Phishing & Social Engineering
Daniel Scragg, Founder and Principal Consultant at Theosec

The practitioner

Daniel Scragg

Founder & Principal Consultant

I started Theosec because I kept watching skilled engineers — myself included — spend the first three days of an engagement doing work a machine does better, then run out of time exactly when the interesting questions appeared.

Inverting that is the whole business. Automation takes the breadth. The people take the part that requires knowing what your organisation actually does.

A larger firm will sell you more people. It will not sell you more attention.

OSCPOSEPCRTOeWPTXCREST CRTBSc (Hons) Computer Science

Next step

Find out what an attacker already knows.

Every engagement starts with a conversation and a mutual NDA — not a sales pipeline. Tell me what you are worried about and I will tell you honestly whether I can help.

daniel@theosec.com · +27 63 484 1051