Skip to content

Energetyka

|

CS.109

CSIRE System API Security Testing

Comprehensive security testing of the Central Energy Market Information System - penetration, configuration, and production verification.

Client

Leading entity in the Polish energy sector

Challenge

CSIRE (Central Energy Market Information System) is an extensive platform comprising user portals, dedicated applications (My IRE, Certification System), and B2B API interfaces. Each component represents a potential attack vector requiring dedicated security analysis.

Approach

01

Penetration testing per OWASP ASVS

Web, API, and WAF testing across 7 areas: authentication, sessions, access control, data validation, cryptography, error handling, and business logic.

02

Configuration review

On-premises and Azure infrastructure audit (up to 200 instances) using Nessus and OpenSCAP. Verification of Firewall, WAF, NSG, IAM, and RBAC.

03

Production verification

Comparison of test and production environment configurations to identify discrepancies.

04

Retesting

Re-verification after implementation of remediation recommendations.

Results

7 OWASP ASVS areas covered by testing
01

Security map per OWASP ASVS Level 2 across 7 areas

02

Configuration review of up to 200 instances (on-premises + Azure)

03

Executive summary, vulnerability descriptions with CVSS scores, and remediation plan

04

Verification of test and production environment consistency

We'll discuss scope, methodology, and timeline.

Book a consultation

Free consultation, no strings attached.