Securing the Client Portal of a Global EdTech Intelligence Platform
Market Intelligence | Sector: Education | Location: US, UK, Australia
OVERVIEW
The client is one of the world's leading intelligence platforms, providing research, analytics and AI-powered tools to organisations across education, climate and health.
As a data-driven business handling sensitive client information through a dedicated client portal, the security of that portal is mission critical. A breach would not only expose client data but would directly undermine the trust that sits at the core of their business model.
Before engaging Ancore, the client portal had not been formally stress-tested against external attack. The client wanted an independent, expert-led assessment of where vulnerabilities existed and how exposed they truly were.
RESULTS AT A GLANCE
WHAT WE DID
Ancore was engaged to carry out a full penetration test of the client's portal through our Cybersecurity vertical.
Scoping and Approach - We began by aligning with the client's team on the scope of the engagement - defining the boundaries of the test, the systems in scope, and the methodology we would follow. This ensured the test was thorough, focused and relevant to their specific threat landscape.
Penetration Testing - Our team systematically tested the client portal for vulnerabilities across authentication, access controls, data exposure, session management and other attack vectors. Every potential weakness was documented, categorised by severity, and assessed for real-world exploitability.
Detailed Findings Report - Following the test, the client received a comprehensive written report covering every vulnerability identified - what it was, how it could be exploited, the potential business impact, and a clear remediation roadmap to address each issue.
Live Walkthrough Session - In addition to the written report, we conducted a live session with the client's team walking through each finding in detail. This gave the client the opportunity to ask questions, understand the risk in plain terms, and leave with full clarity on what needed to be done and in what order.
BUSINESS IMPACT
Client name withheld for confidentiality. Metrics verified internally. Available to discuss on request.