BDDK Penetration Testing for Banks
Independent annual penetration testing for banks under Article 18 of the BDDK regulation on banks' information systems and electronic banking services.
Account takeover and transaction abuse in digital channels.
Annual tests that stay at scanner output and miss business logic flaws.
Findings closed on paper without a retest that proves the fix.
Built For
Banks operating under BDDK supervision.
Information security and IT audit teams planning the annual independent test.
Digital banking teams shipping mobile, API, and open banking features.
Use Cases
Run the annual test with a team that has no role in designing or operating the tested services.
Test internet banking, mobile banking, and API authorization paths end to end.
Chain individual findings into realistic attack paths toward money movement.
AI Security Starter Training
Request a practical checklist for prompt injection, RAG data leakage, MCP risks, and model-file security before launch.
Related Content
Case Study: Chaining BOLA and IDOR in a Fintech API Pentest
How BOLA and IDOR vulnerabilities were chained to reach cross-tenant transaction data in a multi-tenant payment platform — test approach, exploitation evidence, and remediation, anonymized.
API Security in Fintech Applications: Why WAFs Are Never Enough
Today, the digital lifeblood connecting banking software, crypto wallets, open banking integrations, and payment gateways is the API (Application...
Frequently Asked Questions
What does the BDDK regulation require?
Article 18(7) of the Regulation on Banks' Information Systems and Electronic Banking Services (Official Gazette, 15 March 2020, No. 31069) requires a bank to have a penetration test performed at least once a year by independent teams that have no role in the design, development, implementation, or operation of the services it provides through its information systems.
Can the scope include mobile apps and APIs?
Yes. Internet and mobile banking, public and partner APIs, and internal applications can be scoped together so findings are evaluated as combined attack paths.
Need help validating this attack surface?
Talk with Eresus Security about scoped testing, threat modeling, and remediation priorities for this workflow.
Talk to Eresus