Online Banking Penetration Testing
CREST-accredited penetration testing for online banking platforms, digital banks and challenger bank apps. We test account ownership, payees, transfer limits, step-up authentication and the maker/checker approvals that decide who can move money, across the web platform, mobile app, APIs and card issuing. Fixed quote in 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
controls we test on every online banking platform: account ownership, payee changes, transfer limits and step-up authentication.
What FCA, PRA & DORA Mean for Your Online Banking Platform
Operational resilience. FCA and PRA operational resilience requirements call for in-scope firms, including banks, building societies and payment institutions, to identify important business services, set impact tolerances and test severe but plausible disruption scenarios. Penetration testing can identify exploitable weaknesses in the systems supporting online banking, payments and card issuing, and inform remediation and scenario testing. The FCA does not prescribe penetration testing as the method: demonstrating resilience also requires broader scenario testing and evidence of response and recovery. FCA Handbook SYSC 15A; PRA SS1/21.
DORA. The EU Digital Operational Resilience Act requires threat-led penetration testing (TLPT) at least once every three years, for financial entities identified by their competent authority, not for every bank or lender. A UK-only firm sits outside that scope, but many UK banking groups include EU-regulated entities that do not. We scope engagements to the specific entity and system in question and can time testing to fit a TLPT cycle where DORA applies. DORA, Article 26.
Movement of funds. Online banking and challenger bank apps move money and change who can move it. We test account ownership and payee management, transfer limits and step-up authentication, transaction signing, and maker/checker approval on business and joint accounts, because a single missed check on any of these paths can let one customer or approver move another’s money.
Who we test for. Digital banks and challenger bank apps, building societies, credit unions and card issuers moving into digital-first products. See our wider financial services penetration testing and fintech penetration testing pages.
SCOPE
What We Test in an Online Banking Platform
Payees, Transfers & Limits
Account ownership, adding and changing payees, transfer limits, transaction signing and maker/checker approval on business and joint accounts.
Step-Up Authentication
Login, biometric and step-up authentication flows for high-risk actions such as new payees, limit changes and large transfers, and what happens when a step is skipped.
Challenger Bank & Mobile App
The mobile banking client: local storage of tokens and balances, device binding, jailbreak and root detection, and deep links between app and web.
Core Banking & Open Banking APIs
Account information and payment initiation APIs, consent scope and expiry, redirect integrity, and the permissions given to third-party providers.
Card Issuing & Controls
Cardholder roles, spend controls and limits, tokenisation, and card freeze/unfreeze, wherever your platform issues virtual or physical cards.
KYC & Identity Verification
Onboarding and identity verification flows: exposure of identity evidence, reviewer override paths, and the authenticity of callback and recovery steps.
Fraud Controls & Maker-Checker
Maker/checker approval logic, adviser versus customer access, and the fraud controls guarding account and payee changes against social engineering.
OUR PROCESS
From Scope to Attestation in 4-6 Weeks
Scoping Call
30-minute call to map account types, payee and approval roles, and the systems in scope: web, mobile, APIs and card issuing. Fixed-price quote within 24 hours.
Test Accounts
You provide test accounts covering ownership, joint and business access, and any maker/checker approval roles, in a staging environment that mirrors production.
Active Testing
3-15 days of hands-on testing by CREST-certified pen testers, covering payees, transfer limits, step-up authentication and approval workflows. Live findings in your client portal.
Report & Retest
CVSS-scored report with reproduction steps, a walkthrough call, free retest and a letter of attestation for your board, auditors or regulator.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST online banking pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Aligned to Every Framework
Findings map to specific control references in each framework, so your audit team submits the report directly without translation work.
FCA / PRA Operational Resilience
Important business services testing, severe-but-plausible scenarios.
DORA
Evidence aligned to a TLPT cycle, for EU-scope entities identified by their competent authority.
ISO 27001
Annex A 8.8 technical vulnerability management, once you declare that control applicable.
PCI DSS
Requirement 11.4.2/11.4.3 internal and external testing at least every 12 months where card data is in scope.
UK GDPR
Article 32(1)(d) evidence that you regularly test the effectiveness of your security measures.
Cyber Insurance
Findings and remediation documented against the questions on your proposal form. Requirements vary by insurer and policy.
PRICING
Transparent Online Banking Pen Testing Pricing
Pricing depends on the number of account types, payee and approval roles, and integrations in scope. The day count flexes; the included deliverables stay the same across all engagements.
Depends on app complexity
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quoteDepends on app complexity
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quoteDepends on app complexity
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteWHY EJN LABS
What You Get From Online Banking Penetration Testing
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What is online banking penetration testing?
Testing of your online banking platform, mobile banking app and the APIs behind them for the specific ways money and account control can be misused: account ownership, payee management, transfer limits, step-up authentication and maker/checker approvals. We test whether one customer, payee or approver can act outside their intended role.
Do you test loan origination and mortgage application portals?
Yes. For loan origination platforms we test applicant data exposure, underwriting changes, affordability inputs and decision overrides. For mortgage application and broker portals we test broker and borrower access separation, document integrity and unauthorised product or rate changes.
Do you test pension member portals?
Yes, where they sit alongside your banking or lending products. We test member identity and authentication, access to benefit data, and whether a member can change withdrawal instructions or beneficiary details outside the intended approval process.
Does the FCA or DORA require penetration testing for our bank?
The FCA does not prescribe penetration testing. Its operational resilience rules call for in-scope firms to identify important business services, set impact tolerances and test severe but plausible scenarios, and testing is one way to evidence that work. DORA’s threat-led penetration testing (TLPT) requirement under Article 26 applies only to financial entities identified by their competent authority, at least once every three years, not to every UK bank or lender.
Can you test our challenger bank app’s open banking APIs before we launch a new payment feature?
Yes. We test account information and payment initiation APIs, consent scope and expiry, redirect integrity and third-party permissions, alongside the mobile app and web platform the feature ships in. See our open banking API penetration testing page.
How do you handle live customer funds and accounts during testing?
We prefer a staging environment with test accounts, payees and approval roles that mirror production. If production is the only option, we agree strict limits on any action that could move real funds, and use test payees and accounts you create for us.
What’s in the report?
Executive summary (board-ready), technical report with CVSS 3.1 scores, reproduction steps, screenshots, specific remediation guidance, and a 60-minute walkthrough call. Letter of attestation issued after free retest.
Do you sign NDAs?
Yes. We sign client-supplied NDAs as standard. Engagement data is protected under our ISO 27001 (BSI-audited) information security management system.
How quickly can you start?
From signed scope to active testing in 24 hours where required. Standard pipeline is 3-5 business days from initial scoping call to test start.
Are your testers UK-based and what certifications do they hold?
Every engagement is performed by vetted UK-based CREST-certified testers matched to your engagement based on security clearance, compliance scope, and sector specialism. Testers hold CREST certifications relevant to their discipline (CRT, CCT APP, CCT INF, CCSAM).
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get my online banking pen test scope
Tell us about your account types, payee and approval roles, and the platforms in scope. A CREST-certified pen tester will contact you within one business day with a fixed price.



