Skip to content

Home Expertise / Penetration testing

PEN / PEN-05

Mobile application security testing

Assessment of an Android or iOS application and its communications to identify exposed data and inadequate security controls.

WHEN IT HELPS

A focused response
to a defined need.

Mobile software vendor or CTO; store release, field application or personal-data processing.

AT A GLANCE

Family
Penetration testing

Engagement
Testing

Reference
PEN-05

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Local storage and secrets
  • authentication and communications
  • permissions, release settings and interaction with in-scope APIs

Deliverables

  • Platform-specific report
  • minimised evidence
  • separate application-side and server-side remediation

Acceptance evidence

Findings reference a specific version and test scenario; server-side dependencies are identified.

DELIVERY

How the work is structured.

Approach

Obtain authorisation and rules of engagement; prepare accounts and backups; perform controlled tests; debrief, clean up and arrange retesting.

Prerequisites & responsibilities

Customer: written authorisation, asset ownership, third-party permission, stop contacts and scope. Provider: bounded testing, minimal evidence and critical-finding notification.

Scope factors

Applications, roles, APIs, networks, business complexity, supplied access, depth and authorised windows. Black/grey/white box and retesting affect effort; price after scoping.

Questions to clarify

Which platforms and versions? Is a test build available? Is the API included in the engagement?

IMPORTANT BOUNDARIES

Device protections do not replace API controls; specify devices, versions and permitted testing techniques.

No denial of service, destruction, real exfiltration or social engineering without explicit authorisation. Third parties are not tested merely at a customer’s request. Untested scope remains unassessed.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A field-service app stores customer documents on phones. Project: examine storage and logout behaviour. Target outcome: stronger local protection and cleanup rules, verified on test devices.

Scenario 02

A loyalty app embeds a shared secret in its binary. Project: assess its use and server controls. Target outcome: remove the distributed secret and implement appropriate access controls; obfuscation alone is not presented as a sufficient fix.

Technology and reference context

OWASP MASVS/MASTG; dedicated devices and synthetic data.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.