en

Stability and Security for Real-Time Trading

Client:
Financial brokerage company in the online betting sector
 
Industry:
Finance
Focus:
Betting on voting outcomes (primarily political topics)
Main challenge:
Security testing of the web platform after DDoS attacks and implementation of additional protection
Market:
International
Services provided:
Black-box web app pentesting, implementation of Dataguard
Key Takeaways
  • Hardened two web apps and APIs against exploits and DDoS
  • Maintained full service availability
  • Discovered 30 vulnerabilities in two web applications
  • Used manual, automated, and OSINT testing methods
  • Prepared a detailed report with recommendations
  • 30
    vulnerabilities discovered
    4
    tools applied
    2
    web applications tested
    Stability and Security for Real-Time Trading
    Is there a point in pentesting after DDoS attacks? Yes. To prevent future incidents, the client ordered a black-box pentest, during which 30 vulnerabilities were discovered in the web applications. The implementation of DataGuard and additional protection significantly strengthened the platform.

    The brokerage company developed an online platform where users could create polls and place monetary bets on the outcomes. Web service security was critically important for the client, as they operate in a high-risk financial sector and handle sensitive data.

    After a series of DDoS attacks, the company's product required a thorough assessment of its web applications to enhance cybersecurity and prevent future incidents.

    Tasks and challenges
    The client was concerned about the threat of unauthorized access to the platform and requested a pentest of the website, admin panel, and user interface.
    The company expected to receive a report with results and actionable recommendations that could be used to quickly eliminate risks and strengthen protection.
    • Conduct a black-box pentest to identify potential vulnerabilities
    • Assess the platform's resilience to DDoS attacks, bot traffic, and other threats
    • Deliver a report with findings and recommendations for cybersecurity improvements
    icon
    Penetration testing
    Black-box pentest of two web applications to assess resistance to external attacks
    icon
    Dataguard implementation
    DDoS protection and malicious traffic filtering solution
    icon
    Report and recommendations
    Test results summary and recommended actions to eliminate vulnerabilities
    Our approach

    To assess the security of the betting platform, we applied a black-box pentesting strategy along with both automated and manual testing of the web applications. We used OSINT techniques and tools such as Burp Suite, Nessus, and OWASP ZAP to identify both technical and logical vulnerabilities.

    Based on the penetration testing results, the Datami team compiled a report with findings and recommendations. To further enhance protection against DDoS attacks and bots, DataGuard and Cloudflare were implemented.

    Black-box
    Black-box
    Assessment from the perspective of an external attacker - without access to source code or internal information
    Key work stages and solutions

    After thorough preparation, the Datami team conducted full-scale black-box testing: they simulated potential attacks on the web applications and compiled a report on the discovered vulnerabilities.

    A separate stage involved implementing protective solutions, including the integration of DataGuard to defend against DDoS attacks and bots.

    • Preparation
      Analysis of testing objectives, development of attack scenarios, and selection of tools for black-box assessment.
       
    • Security assessment
      Automated and manual testing of two web applications (user/admin), attack simulation without access to source code.
       
    • Results & protection
      Risk evaluation, report preparation with technical details and recommendations. DataGuard implementation.
    How we can help you?

    Every cybersecurity case study we solve involves deep analysis, tailored solutions, and measurable results.
    Datami has already helped over 600 companies strengthen their digital defenses — and we can do the same for your business.
    Ready to take action?

    Let’s start with a free consultation!
    Results and recommendations
    Results and recommendations

    During the testing of the betting platform, the Datami team discovered 30 vulnerabilities: 1 high, 7 medium, 19 low, and 3 informational. These affected both technical configurations and access to functionality in the user and admin areas.

    Based on the pentest results, we prepared a report and provided recommendations to enhance digital security:

    1. configure bot and DDoS protection using DataGuard and Cloudflare;
    2. fix incorrect access configurations;
    3. strengthen control over administrative privileges.

    Most vulnerabilities were addressed immediately, significantly increasing the platform’s overall security level.

    Our certificates
    Key project results

    Thanks to the project, 30 vulnerabilities were identified in the betting service, and protection against DDoS attacks was implemented using Dataguard and Cloudflare. As a result, the client achieved a significantly higher level of cybersecurity and platform stability.

    This case study highlights that even smaller market players can become targets for hackers. If your company handles payment information or processes personal data, security testing is essential.

    Category
    Before the project
    After implementation
    Security level
    Unknown, no independent assessment
    Real threat level identified: 30 vulnerabilities discovered
    Vulnerabilities
    Not identified
    Found: 1 high, 7 medium, 19 low, 3 informational
    DDoS protection
    Absent or unstable
    Dataguard and Cloudflare implemented
    Account compromise
    Risk for administrators
    Risk minimized through privilege restrictions
    Unauthorized access
    Potential threat
    Issues with access rights and configurations resolved
    More success stories with Datami
    Browse other project case studies
    Preparation of the Platform for Regulatory Audit

    Preparation of the Platform for Regulatory Audit

    • The risk of KYC bypass was reduced from high to low.
    • A rate limit and an AI module for deepfake detection were implemented.
    Services:
    API, web, and mobile application pentest (Gray-Box)
    Oct 19, 2025
    Preparing a smart contract for release on Web3

    Preparing a smart contract for release on Web3

    • The code was prepared for certification.
    • The project was secured against 99% of known threats.
    Services:
    Smart contract audit (White-box source code review)
    Sep 16, 2025
    Web3 Project Random Walk: Smart Contract Audit

    Web3 Project Random Walk: Smart Contract Audit

    • Secure launch on Polygon mainnet ensured within 5 days
    • Risk level reduced from medium to minimal
    Services:
    Smart contract audit (White-Box source code analysis)
    Sep 2, 2025
    Security image
    Ready to assess your project's security?
    Contact Datami — we’ll help you identify risks, strengthen your cybersecurity, and confidently pass certification.
    Datami articles
    Datami Took Part in CV Summit 2025 Datami Newsroom
    Datami Newsroom

    Datami Took Part in CV Summit 2025

    CV Summit 2025 brought together leaders in fintech, blockchain, and artificial intelligence in Switzerland. The Datami team participated in the global dialogue on how technology is shaping the new financial landscape.

    Oct 10, 2025 3 min
    Web Applications Penetration Testing: A Pentest Guide Oleksandr Filipov: Security engineer at Datami, author of articles
    Oleksandr Filipov: Security engineer at Datami, author of articles

    Web Applications Penetration Testing: A Pentest Guide

    Web applications are targeted by attacks every day - from simple scanners to deliberate breaches. To understand how vulnerable a web application is and how to protect it from hackers’ actions, a special assessment is conducted - penetration testing (pente

    Oct 1, 2025
    Microsoft enables email bombing protection Datami Newsroom
    Datami Newsroom

    Microsoft enables email bombing protection

    Microsoft announced a new update to Defender for Office 365 that automatically detects and blocks email bombing attacks. The rollout started in June, and most users will receive the feature by mid-July 2025.

    Sep 12, 2025 3 min
    Order a free consultation
    We value your privacy
    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Cookie policy