This test found a problem before it became one.
Why they tested
A growing share of their client base sits in finance and banking, and those clients raised what they demanded of a supplier holding candidate data. An ISM certification became the requirement, and for a bank’s third-party risk team to accept it, it had to rest on independent testing. Data privacy rules were being sharpened at the same time, locally and globally.
The finding that mattered
The platform was running on a PHP version approaching the end of its supported life. There was no live vulnerability to report on the day. The risk was dated: once a runtime stops receiving security patches, the next CVE published against it has nowhere to be fixed.
What changed
They upgraded before that date rather than after an advisory forced it. The certification went through with independent testing behind it, and People Dynamics retained Red Team Partners for an annual re-test, because an expiry date only surfaces when somebody looks on a schedule.
Operationally, I would recommend Red Team. Their reporting was easy to interpret and the steps, the procedures and the whole process was very straightforward.
This was a vulnerability assessment and penetration test. The assessment half is what surfaced the runtime date; the test half is what proved nothing else was reachable.