logo
hamburger-menu-icon
Back to Projects

Community Bank

Financial Services Code Inspection

A bank's customer facing application, running on outdated frameworks for 15 years with no original developer left, raised security concerns. Ollon ran a security focused code inspection, prioritized the vulnerabilities found, and identified fixes to keep it running safely. The bank decided to replace the application, running it safely for a year and a half while building that replacement.

A bank's application, essential for managing customer facing systems, was developed 15 years ago using a hybrid of outdated frameworks. This setup raised concerns about security and maintainability, especially with the original developer no longer available.

Ollon conducted a thorough code inspection focusing on security, identifying multiple vulnerabilities and maintenance issues. Based on those findings, a prioritized list of security enhancements and a detailed roadmap to improve the application's overall security and stability were created

From the findings, the bank was able to figure out the application needed to be replaced. It was too much effort to fix given the significance of some of the structural issues. At the same time they had the information needed to make minimal security fixes in the most crucial parts of the application more secure as needed to keep it going for the next year and half with minimal costs while they work on its replacement.

Php, WordPress, MySQL

Our Expertise in Action

Cybersecurity assessment and incident response

A bank's customer facing application had been running for 15 years on a hybrid of outdated frameworks, and the developer who originally built it was long gone by the time anyone needed to know how it actually worked. Ollon conducted a security focused code inspection of the application, working through the codebase to identify specific vulnerabilities and maintenance problems the bank had no internal visibility into. Those findings were organized into a prioritized list, ranking each issue by how much risk it actually carried instead of treating every finding as equally urgent. That prioritization gave the bank a concrete starting point for deciding what needed fixing immediately versus what could wait.

End of life application strategy

After 15 years of accumulated changes with no original developer left to explain the reasoning behind them, a bank's application had reached the point where some of its structural problems were too extensive to fix without effectively rebuilding it. Ollon's findings let the bank make that call directly, deciding to replace the application instead of continuing to patch a system whose problems had outgrown minor fixes. At the same time, the assessment identified the specific, minimal security fixes needed to keep the most crucial parts of the application safe enough to run for another year and a half. That combination gave the bank a low cost bridge to operate on while building a replacement, instead of an all or nothing choice.