Offensive security for fintech
There's always a way to the money.
Rarely a missing patch. Usually an approval that trusts the wrong field, or a ledger that believes two requests were one.
90 minutes · No cost · Mutual NDA before anything is discussed
A worked example
Three findings nobody would fix.
Two Lows and a Medium. Each survives a scan, a triage meeting and a quarter of backlog grooming. Read together, they move money out of an account that is not yours.
- Partner APILow
An error message leaks the account ID format
- Password resetLow
Old sessions stay valid after a reset
- Payment approvalMedium
Approval checks the role, not the tenant
An approver in one tenant releases another tenant’s payment
Funds leave with a valid approval recorded against them.
No scanner rates this chain. Nothing in the code says approval is supposed to be bounded by tenant — that only comes out of a working session with your engineers.
Where we work
Financial services only.
One sector, tested properly. We turn down everything else, which is why we start already knowing what a settlement file is for.
- Payments & cards
- PSPs · Acquirers · Issuers · Gateways
- Authorisation → Settlement
- Banking & BaaS
- Core banking · Open Banking · Sponsor banks
- Deposit → Transfer
- Lending & credit
- Underwriting · Bureau data · Disbursement
- Decision → Disbursement
- Digital assets & trading
- Exchanges · Custody · Brokerage
- Custody → Withdrawal
Capabilities
Five ways to find out where you stand.
Every engagement runs the same methodology. What changes is the surface, the duration, and how much of your organisation is in scope.
Executive Adversary Briefing
A private session with your leadership on how someone would actually come after your money: the groups working financial services right now, what your public footprint already gives away, and the three routes in we would try first. We give away the thinking, not a scan.
- Threat actors currently working financial services
- What your public footprint already discloses
- The three routes in we would try first
- Straight answers, in the room, no report to chase
Managed Red Team
A standing adversary for a business that ships weekly. Continuous offensive testing across your platform and your people, with reporting your board and your regulator can both read.
- Baseline assessment in month one
- Weekly external testing & OSINT monitoring
- Three social engineering campaigns monthly
- Evidence that satisfies an annual testing obligation
Red Team Assessment
Not a list of vulnerabilities — a single question, answered honestly. Can a capable adversary move money, reach the ledger, or approve something they should not? Technology, people and process are all in scope, because they are all in scope for the people who mean it.
- A money-movement objective, not a coverage checklist
- Technology, people and process in one engagement
- Detection and response measured as you go
- Full attack narrative, first contact to objective
Penetration Testing
Manual testing of the systems that move and account for money — payment flows, Open Banking APIs, ledgers and the cloud they run on. Reported in plain language, prioritised by what it would actually cost you.
- Payment, transfer and approval flows
- Open Banking, partner and internal APIs
- Cloud estate and identity (AWS, Azure, GCP)
- Mobile banking and trading applications

The practitioner
Daniel Scragg
Founder & Principal Consultant
I started Theosec because I kept watching skilled engineers — myself included — spend the first three days of an engagement doing work a machine does better, then run out of time exactly when the interesting questions appeared.
Inverting that is the whole business. Automation takes the breadth. The people take the part that requires knowing what your organisation actually does.
A larger firm will sell you more people. It will not sell you more attention.
→Next step
Find out what an attacker already knows.
Every engagement starts with a conversation and a mutual NDA — not a sales pipeline. Tell me what you are worried about and I will tell you honestly whether I can help.
daniel@theosec.com · +27 63 484 1051