Tier-2 European bank found a critical IDOR before its annual audit.
// challenge
A scheduled Argus validation run picked up an IDOR in the customer transfer endpoint introduced in a feature release the bank shipped two weeks prior.
// solution
Single argus engagement against the transfer surface (authenticated, scope-locked to the affected endpoints). Senior engineer review on the finding within 4 hours of detection. Fix proposed alongside the finding, customer remediation deployed within 48 hours, free retest within 30 days confirmed closure.
// results
- Critical IDOR detected 4h after release, closed in 48h
- 73% reduction in exploitable findings over 90 days of quarterly coverage
- DORA Article 25 (ICT-related operational resilience testing) evidence captured automatically
“We had a clean external pentest in March. argus found a critical that shipped in May. That's what continuous means.”
