24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesIn the PressDSET in the national pressSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI
//Banking & Finance · 2026
Banking & Finance · Case 2026

Top 5 bank mobile banking · OWASP MASVS L2 pentest · 7 critical findings · BDDK compliance

One of Turkey's top 5 banks requested an authorized mobile banking pentest from DSET. Target: iOS+Android jailbreak/root detection bypass, MitM, cert pinning, secure storage. With the full MASVS L2 procedure DSET identified 7 critical findings, the bank fixed them, the BDDK audit was passed, and a 3-year strategic partnership began.

Duration
21 business days of pentest · 30 days of remediation
Scope
iOS+Android · 8M active users · BDDK scope
Customer Satisfaction
★★★★★

01 The Challenge

A top 5 bank mobile banking application, 8M active users. A proactive pentest before the BDDK "mobile banking security" audit. The full MASVS L2 procedure was requested from DSET: 27 control categories, jailbreak detection bypass, cert pinning, secure storage, screen recording protection. The bank's internal team's previous test had been "insufficient."

02 DSET's Approach

01

T+0 · Lab setup

iOS 17 jailbreak (palera1n) + Android 14 root (Magisk + Zygisk). Frida server, Objection, r2frida, mitmproxy + cert pinning bypass scripts were prepared.

02

T+1-10 days · MASVS L2 27 categories

The 27 control categories were tested in order: V1 (Architecture), V2 (Data Storage), V3 (Crypto), V4 (Auth), V5 (Network), V6 (Platform), V7 (Code), V8 (Resilience). 7 critical + 12 high + 18 medium findings.

03

T+10 days · PoC + impact

Bypass #1: jailbreak detection passed with a 4-line Frida hook. #2: cert pinning fixed-key MitM. #3: the SQLite local DB AES key hardcoded in the app. A detailed PoC video + impact demo were prepared.

04

T+15 days · Management presentation

The bank CTO + management presentation was excellent. Approved as a "very detailed analysis," a 3-year contract with DSET was signed.

05

T+30 days · Bank remediation

7 critical findings were fixed: cert pinning Trust Store, jailbreak detection hardening, secure storage Keychain/Keystore + biometric authentication.

06

T+37 days · Re-test

The DSET re-test was free, included in the contract. 7 critical findings clean, 2 high findings remaining (accepted by the bank).

07

T+60 days · BDDK + certificate

The BDDK "mobile banking security" audit was successful. A MASVS L2 certificate (DSET-signed). The App Store / Play Store annual security report was updated.

03 Results in Numbers

7 critical + 12 high
Findings
Approved
MASVS L2 certificate
Successful
BDDK audit
3 years
DSET contract
Clean
Re-test
0
User impact

04 Customer Testimonial

"

7 critical findings our internal team missed were proven with PoCs by DSET. The MASVS L2 certificate formed the backbone of our BDDK audit; we became a strategic partner for 3 years.

Mobile Banking CTO
Top 5 Bank · 8M users
★★★★★

05 Key Takeaways

A full test of the 27 MASVS L2 control categories must be done; only pinning/MitM is insufficient
A detailed PoC video + impact demo is critical for management approval; a technical report alone is insufficient
The re-test should be free (included in the contract); the bank does not want to pay again
In a BDDK "mobile banking security" audit, a MASVS L2 certificate is critical evidence

06 Services Used in This Case

Cyber Security

Cognitive solutions.

Incident Simulator & Threat Heatmap

Not hours of deliberation · but minutes of interactive simulation.

Your case can end just as well.

Free assessment · detailed response within 48 hours.

Call Now Contact form

Other Cases

Automotive Manufacturing

Ransomware on 800 endpoints at an automotive supplier · full recovery in 9 days

View
Public Administration

Detection and cleanup of a 14-month APT intrusion at a metropolitan municipality

View
Finance

A 9-day Red Team engagement at one of Turkey's top 5 banks

View
DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Press Room
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
Home
References
Privacy
KVKK
GDPR
Cookies
Terms