EresusSecurity
ComplianceSolutions

SPK Penetration Testing for Capital Markets

Annual penetration testing for capital markets institutions under the Capital Markets Board (SPK) information systems communiqué VII-128.10.

Risk & Regulation Signals

Order and account manipulation through weak API authorization.

Wallet and custody flows exposed in crypto asset platforms.

Tests performed by teams that are not independent from the systems they test.

Built For

Brokerage firms, portfolio management companies, and other institutions subject to SPK.

Crypto asset service providers now covered by SPK information systems rules.

IT and compliance teams planning the annual test.

Use Cases

01

Run the annual test with certified testers who hold no information security duty at the institution.

02

Test trading platforms, mobile apps, and customer APIs for authorization and business logic flaws.

03

Turn findings into an action plan with retest evidence.

AI Security Starter Training

Request a practical checklist for prompt injection, RAG data leakage, MCP risks, and model-file security before launch.

Prompt injection and guardrail bypass checks.
RAG data leakage and permission-boundary review.
MCP identity, transport, and command-risk controls.

No spam. Used only to send the resource and related security notes.

Frequently Asked Questions

Which SPK rule applies now?

The Communiqué on Principles Regarding Information Systems Management (VII-128.10) was published in the Official Gazette on 13 March 2025 (No. 32840) and repealed the earlier Information Systems Management Communiqué (VII-128.9). It requires information systems to be penetration tested at least once a year by natural or legal persons holding national or international penetration testing certification and having no duty in meeting the institution's information security requirements. The Board may also request additional tests.

Do you cover crypto asset service providers?

Yes. Exchange, custody, wallet, and API flows can be scoped together with the trading and customer applications.

Need help validating this attack surface?

Talk with Eresus Security about scoped testing, threat modeling, and remediation priorities for this workflow.

Talk to Eresus