en

GCP security audit for PCI DSS readiness

Client:
International fintech company
Industry:
FinTech
Focus:
Cloud security audit on the GCP platform
Main challenge:
Protection against unauthorized access to administrative resources and personal or financial data leaks
Market:
International
Services provided:
Cloud penetration testing, cloud security assessment
Key Takeaways
  • PCI DSS compliance achieved.
  • Risk of unauthorized access reduced by 90%.
  • 12 vulnerabilities identified and remediated.
  • Project completed ahead of schedule in 4.5 weeks.
  • Robust resource monitoring and event logging implemented.
  • 12
    vulnerabilities identified
    90%
    risk reduction
    4.5
    week audit duration
    GCP security audit for PCI DSS readiness
    Can a fintech’s cloud infrastructure be prepared for regulatory requirements in 4.5 weeks? Yes, it can! The Datami team conducted a White-box pentest and Google Cloud security assessment, identifying 12 vulnerabilities, and resolving these reduced unauthorized access risk by 90%.

    The client is a fast-growing fintech company specializing in real-time transaction analytics and fraud detection for digital payment platforms and neobanks, serving approximately 200,000 users. 

    The company processes millions of financial events daily, leveraging Google Cloud infrastructure for data analysis, regulatory compliance management, and machine learning-driven risk assessment.

     

    Tasks and challenges
    To enhance infrastructure security and prepare for PCI DSS certification, the client engaged Datami for a GCP security audit. 
    The company needed to identify configuration and access vulnerabilities for early remediation and to improve its cybersecurity level. 
     
    • Conduct a comprehensive White-box security audit of the Google Cloud Platform environment. 
    • Identify and prioritize risks that could lead to unauthorized access or data leaks.
    • Assist in preparing the infrastructure for regulatory compliance.
    icon
    Object
    Audit GCP security: console, Organization, Folders, IAM, storage, network, and monitoring
    icon
    Standard
    Assess configuration compliance with PCI DSS requirements
    icon
    Result
    Technical report including vulnerabilities and a remediation plan

    Our approach

    In this project, we conducted White-box penetration testing and cloud security assessment of the Google Cloud Platform environment. Both automated and manual checks were used. 

    For the cybersecurity audit, Datami specialists used Google Cloud Console, IAM & Admin, Security Command Center, Cloud Identity, Policy Analyzer, Cloud NAT, Cloud Armor, Cloud Run, and Artifact Registry.

    White-box

    White-box

    Full-access testing approach for deep system analysis
    Key work stages and solutions

    The project began with a kickoff meeting to align GCP audit priorities and obtain a test account.

    Communication was organized through a real-time chat, where the client received interim progress reports. This ensured rapid data exchange and allowed all testing stages to be completed ahead of schedule.

    • Preparation
      Studying GCP structure and documentation, obtaining access, and setting up tools.
    • Testing and security assessment
      Automated scanning and manual search for vulnerabilities in IAM  configurations and network objects.
    • Result documentation
      Analyzing results and checking PCI DSS compliance. Preparing the final report with recommendations.
    How we can help you?

    Every cybersecurity case study we solve involves deep analysis, tailored solutions, and measurable results.
    Datami has already helped over 600 companies strengthen their digital defenses — and we can do the same for your business.
    Ready to take action?

    Let’s start with a free consultation!
    Results and Recommendations

    Results and Recommendations

    Project tasks were completed in 4.5 weeks. The security audit reduced the risk of unauthorized access by 90%. 

    During the pentest, Datami specialists identified 12 vulnerabilities: 1 high, 5 medium, and 6 low. 

    The client received a clear action plan to strengthen cybersecurity, specifically recommending the following:

    • configure two-factor authentication (2FA) for all accounts, especially privileged ones; 
    • enable resource monitoring and event logging for timely detection of suspicious activity; 
    • update software library versions and remove unnecessary dependencies. 

    The fintech company's Google Cloud infrastructure became a managed, secure environment, and compliance levels, following the implemented measures, align with cloud security best practices.

    Key Project Results

    Default cloud settings can become entry points for attacks. As this cybersecurity case study demonstrates, risks often stem from basic gaps rather than complex attacks. 

    Through the pentest and security assessment, the client avoided confidential data leaks, preventing potential financial and reputational damage, and prepared for regulatory audits.

    Indicator
    Pre-project
    Post-project
    Risk level
    High
    Low / managed
    Compliance with standards
    Low (PCI DSS)
    Aligns with cloud security best practices
    Vulnerabilities
    Unknown / unassessed
    12 vulnerabilities identified and remediated
    Unauthorized access risk
    High
    Reduced by 90%
    More success stories with Datami
    Browse other project case studies
    Cloudflare Zero Trust & SIEM for SaaS
    Cloudflare Zero Trust & SIEM for SaaS
    • MTTD reduced to 1–2 hours
    • False positives reduced by 50–65%
    Services:
    Cloudflare Zero Trust and Wazuh SIEM implementation
    Aug 4, 2026
    WordPress Website Recovery After a Hack
    WordPress Website Recovery After a Hack
    • Backdoor infections and web shells were completely removed.
    • 9 unauthorized admin accounts were removed.
    Services:
    WordPress Security Audit (White-box)
    Aug 4, 2026
    SIEM Wazuh Implementation for a Financial Company
    SIEM Wazuh Implementation for a Financial Company
    • PCI DSS & ISO 27001 audit-ready
    • Reduced false positives by 60–70%
    Services:
    SIEM Implementation (Wazuh)
    Jul 1, 2026
    Security image
    Ready to assess your project's security?
    Contact Datami — we’ll help you identify risks, strengthen your cybersecurity, and confidently pass certification.
    Datami articles
    What Does AI Penetration Testing Include? A Practical Breakdown of 12 Critical Security Checks Oleksandr Filipov
    Oleksandr Filipov
    What Does AI Penetration Testing Include? A Practical Breakdown of 12 Critical Security Checks

    AI Penetration Testing checks not only for prompt injection but also for RAG, memory, agent privileges, and integrations. Find out which 12 tests help identify real risks in AI systems.

    4 min Aug 20, 2026
    Modern LLM Pentesting Goes Far Beyond Prompt Injection Oleksandr Filipov
    Oleksandr Filipov
    Modern LLM Pentesting Goes Far Beyond Prompt Injection

    LLM pentesting goes beyond prompt injection: it audits data leaks, permission bypasses, and harmful actions. Discover what a full AI audit must cover.

    4 min Aug 20, 2026
    Why AI Tokens Introduce a New Class of Smart Contract Risks Oleksandr Filipov
    Oleksandr Filipov
    Why AI Tokens Introduce a New Class of Smart Contract Risks

    A smart contract can pass a Solidity audit without a remark and still be exploitable - if part of the decision-making sits with a model. What a real audit with 40 findings reveals, and what to check before listing.

    4 min Aug 4, 2026
    Order a consultation
    We value your privacy
    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Cookie policy