SPK Penetration Testing for Capital Markets
Annual penetration testing for capital markets institutions under the Capital Markets Board (SPK) information systems communiqué VII-128.10.
Order and account manipulation through weak API authorization.
Wallet and custody flows exposed in crypto asset platforms.
Tests performed by teams that are not independent from the systems they test.
Built For
Brokerage firms, portfolio management companies, and other institutions subject to SPK.
Crypto asset service providers now covered by SPK information systems rules.
IT and compliance teams planning the annual test.
Use Cases
Run the annual test with certified testers who hold no information security duty at the institution.
Test trading platforms, mobile apps, and customer APIs for authorization and business logic flaws.
Turn findings into an action plan with retest evidence.
AI Security Starter Training
Request a practical checklist for prompt injection, RAG data leakage, MCP risks, and model-file security before launch.
Frequently Asked Questions
Which SPK rule applies now?
The Communiqué on Principles Regarding Information Systems Management (VII-128.10) was published in the Official Gazette on 13 March 2025 (No. 32840) and repealed the earlier Information Systems Management Communiqué (VII-128.9). It requires information systems to be penetration tested at least once a year by natural or legal persons holding national or international penetration testing certification and having no duty in meeting the institution's information security requirements. The Board may also request additional tests.
Do you cover crypto asset service providers?
Yes. Exchange, custody, wallet, and API flows can be scoped together with the trading and customer applications.
Need help validating this attack surface?
Talk with Eresus Security about scoped testing, threat modeling, and remediation priorities for this workflow.
Talk to Eresus