
Martin Hořický
Mobile application penetration testing is an advanced security service focused on identifying vulnerabilities specific to mobile operating systems such as Android and iOS.
This testing simulates real-world attack scenarios to assess whether the application is exposed to risks such as unauthorized access to sensitive data, manipulation of local storage, bypassing authentication mechanisms, or abuse of unprotected API interfaces.
For regulated entities, particularly in the financial sector, this type of testing is an essential component in meeting the requirements of European regulations such as DORA and NIS2, which emphasize regular identification and management of cyber risks throughout the entire application lifecycle.
Static security measures alone are not enough, application resilience must also be validated through controlled attacks in realistic conditions.
| Benefit | Description |
| Simulation of Real-World Attacks | Verification of resilience against vulnerabilities such as Insecure Data Storage, Code Injection and other common weaknesses. |
| Application Security Validation | Testing authentication, data encryption in storage, API access control, and protection against reverse engineering. |
| Configuration Flaw Detection | Analyzing application permissions, misconfigured components, or exposure of sensitive data. |
| Verification of App Logic and Backend Interactions | Identifying weaknesses in input validation, business logic, or client-side enforcement. |
| Human Factor Identification | For example, weak administrative passwords or unsecured test accounts. |
DORA emphasizes that application penetration testing must be conducted by qualified and independent experts with proven experience in application security, specifically:
According to the DORA framework, testing of mobile applications falls under so-called basic testing, mandatory routine security assessments of systems supporting critical or important business functions. The key requirements include:
Regular testing at least once per year, or prior to each deployment of a major application release.
Documentation of identified findings and proposed remediation measures, including their subsequent verification (retest) and approval by the security management.
Inclusion of third parties involved in the development, management, or hosting of the application (e.g., outsourced development, cloud providers).
Identification of the target mobile application, functionality types, access interfaces (e.g., frontend, REST API), and test types (authenticated/unauthenticated, black/grey/white-box approach).
Selection of appropriate tools and techniques based on the technology stack and application type.
Testing from an attacker’s perspective (e.g., reverse engineering, encryption and storage testing, traffic interception, API manipulation).
Evaluation of identified vulnerabilities based on severity, likelihood of exploitation, and alignment with OWASP MASVS/MSTG. Prioritization using CVSS or the OWASP Mobile Risk Rating.
Delivery of a detailed technical report describing the attack vectors, impacts, and remediation suggestions, accompanied by a management summary.
Consultation on findings, recommendations for code or architecture changes, and possible retesting after implementation of corrective measures.
BDO provides mobile application penetration testing as part of a comprehensive security strategy. We help organizations identify and remediate technical vulnerabilities before they can be exploited by real-world attackers. Our approach combines manual testing, scripted automation, and deep knowledge of real attack techniques.
01 Technical expertise and experience
We understand the requirements of DORA and NIS2 and tailor our tests to ensure that the outputs are suitable for both supervisory reviews and audits. We assist in defining the testing strategy and ensure its alignment with other types of testing, such as TLPT and penetration tests.
02 Independence and credibility
As an independent consulting firm, we do not own any technologies and offer truly objective assessments. Cooperation with BDO is a clear signal of quality and trust for both regulators and clients.
03 Certified team with expert experience
Our specialists hold certifications such as OSCP, CRTP, eCPPT, BSCP, CEH, CRT, CPSA, CISSP, CCISO, and others. They have experience testing large banks, insurers, and ICT providers.