ObSignal: Extended Attack Surface Management (XASM)
ObSignal finds the systems, cloud services and domains your organization exposes, watches them for changes, and shows...
Guides, research and case studies from the Snipeyes team in Jakarta, written for the people who make security decisions. Search all 97 articles by keyword, or filter by topic and category.
ObSignal finds the systems, cloud services and domains your organization exposes, watches them for changes, and shows...
Nesgate is a browser extension that masks sensitive data on the device before staff send it to AI tools, and brings u...
Before its biggest sale, an e-commerce platform had us test checkout, vouchers and payments. We found a Rp0 checkout ...
We emulated the ransomware group targeting a commercial bank. A phishing message led to full network control in 26 ho...
A bank's security team got a ready-to-use pack for every finding: evidence, detection queries, blocking rules and fix...
A conglomerate had 400 open security findings and one team to fix them. We ranked them by business risk and gave the ...
A telco group spent more on security each year but could not tell if it was safer. Trend analysis traced most repeat ...
A telco's scanners flagged 540 critical issues. Safe, authorized validation showed 58 were truly exploitable, so the ...
A listed group's board ignored 120-page security reports. We turned the findings into a one-page summary in rupiah an...
A public institution could not secure what it could not see. We mapped every linked domain and host before testing, a...
How we tested a state enterprise's single sign-on end to end. A leaked token, weak one-time codes and a token flaw al...
A fintech lender that deploys many times a week moved security testing into its release pipeline, so every change is ...
A bank moving to AWS had more than 300 insecure settings, including public storage holding e-statements. How we trace...
A retail and logistics firm had 8,400 scanner results that nobody acted on. Expert triage turned them into 132 real f...
An insurer had 90 penetration test findings and 30 days before its audit. Automated retests showed fewer than half th...
A payroll SaaS platform shipped weekly but was tested once a year. Automated penetration testing proved a cross-tenan...
A fintech's inventory listed 180 internet-facing assets. Attackers could see 612, including open storage, debug APIs ...
Six medium-rated weaknesses chained from guest Wi-Fi to a core banking database. How we mapped the attack paths and f...
A digital bank's API documentation listed 84 endpoints. We found 121, including one that let any user read any custom...
How we tested an insurer's AI customer-service assistant, found it could leak internal documents and offer refunds, a...
Cyber resilience is the ability to anticipate, withstand, recover from and adapt to attacks. How it differs from cybe...
Manual API penetration testing found an authorization flaw in a telco billing API that exposed other subscribers' dat...
Before a carrier's 5G standalone launch, testers found an over-privileged service account that allowed container esca...
How manual penetration testing of 42 Open Banking APIs found an authorization flaw that could move funds between acco...
How a digital bank used Snipeyes FD real-time fraud scoring to tackle account takeover and payment fraud while blocki...
How internal penetration testing and code review found a privilege escalation path in a bank's new cloud core banking...
Snipeyes FD scores every login, payment and account opening in real time to stop account takeover and payment fraud, ...
FOCTOS, a Snipeyes company, uses AI to test your web applications and APIs continuously. A human expert confirms ever...
Snipeyes DBM watches the dark web, paste sites, code repositories and Telegram for your leaked passwords, data and ke...
Snipeyes CTD removes phishing sites, fake apps, impersonation and leaked data through legal notices, with every case ...
Safe security testing for power, water and smart city operators: SCADA, substations, smart meters and vendor remote a...
Security testing for airlines, ports and logistics firms: TMS and WMS, fleet telematics, port and airport OT, and par...
Penetration testing and red teaming for mobile and broadband operators: 5G core, OSS/BSS, billing and subscriber data...
Penetration testing for SaaS platforms, cloud and data centers: tenant isolation, APIs, build pipelines and AI featur...
Security testing for retailers and marketplaces: checkout, POS, loyalty points and third-party scripts, mapped to PCI...
Security testing for factories: the link between office IT and plant control systems, SCADA, PLCs and MES, carried ou...
Security testing for insurers, brokers and TPAs: claims portals, partner access and payment data, mapped to OJK rules...
Security testing for hospitals, labs and pharma: medical records, imaging, connected devices and backups, run safely ...
Independent penetration testing and security audits for ministries, agencies and state-owned enterprises, aligned wit...
Penetration testing for e-wallets, payment APIs, lending apps and KYC flows, mapped to Bank Indonesia and OJK rules, ...
Penetration testing and red teaming for banks: mobile banking, open APIs, SWIFT and payment systems, mapped to OJK an...
Safe security testing for energy and mining operators: the link between office IT and control systems, vendor remote ...
Security testing for universities, schools and EdTech: learning platforms, student records, campus login and research...
Security testing for connected cars, over-the-air updates, mobile apps and EV charging, aligned with UNECE R155 and I...
A quick scan looks cheaper until it misses the attack that matters and the audit has to be redone. How testing by a C...
How Snipeyes, a CREST-accredited firm, runs a penetration test from scoping to retest, and what your board, engineers...
A 12-point checklist for CISOs and procurement teams to vet a penetration testing provider, from CREST credentials an...
CREST accredits the firm that tests you; ISO 27001 and SOC 2 assess your own organization. How to choose the evidence...
CREST is an international body that accredits penetration testing companies and certifies testers. What accreditation...
How we tested an energy and manufacturing group's plant control systems without stopping production, and found a path...
A state-owned bank tested the QRIS payments in its mobile app before launch. We found a way to redirect payments made...
An automated scan of a bank's SNAP open API found nothing critical. Manual testing found a way to redirect transfers....
A digital bank preparing to join BI-FAST asked us to test its payment module. We found a way to hijack phone-number a...
How we tested a private bank's AS/400 core banking system from inside its network, found a route to change balances, ...
A 12-week plan for PDP Law compliance: data inventory, ROPA, DPIAs, a DPO, technical controls, vendor checks, breach ...
VAPT pairs a broad automated check for known weaknesses with hands-on expert attacks, showing which problems are trul...
When Indonesia's PDP Law requires a data protection officer, what the role involves, how the PDP authority fits in, a...
A one-off security review of your application's source code, combining automated scanning with expert line-by-line ch...
A realistic attack exercise that tests whether your security team can detect and stop a determined adversary before t...
Administrative fines of up to 2% of revenue, prison terms of up to 6 years and personal liability for management: wha...
Article 46 of Indonesia's PDP Law requires written breach notice within 72 hours. Who to notify, what to say, and a s...
A plain test for when Indonesia's PDP Law requires a data protection impact assessment, what the assessment should co...
When you may send personal data outside Indonesia under Article 56 of the PDP Law, which safeguards count, and a chec...
What valid consent means under Indonesia's PDP Law, the consent designs that fail the test, and practical fixes for y...
Simple security habits for staff and small offices: strong passwords, two-factor login, regular updates, secure Wi-Fi...
SOCRadar shows your organization as attackers see it, combining attack surface monitoring, digital risk protection an...
Security specialists review risky code changes inside your development cycle, catching flaws before they are merged a...
What data controllers and processors must do under Indonesia's PDP Law: lawful basis, records, DPIAs, a DPO, security...
The rights people hold over their data under Indonesia's PDP Law, which requests carry a 72-hour deadline, and how to...
What Indonesia's PDP Law requires, who it applies to, what counts as personal data, the lawful bases for using it, an...
RidgeBot, from Ridge Security, automates much of a penetration test. Snipeyes resells it and helps you run it alongsi...
Kawanlabs is an Indonesian digital company and Snipeyes partner that builds digital products and services for busines...
An independent security check before a new system goes live, testing it against agreed requirements so the owner can ...
Find out how your application behaves under peak demand before your customers do, with load, stress and endurance tes...
A regular, largely automated check of your servers, cloud and applications for known weaknesses, ranked by risk so yo...
What continuous cybersecurity monitoring involves, from alerting and log analysis to patching and threat intelligence...
System hardening switches off unused services, applies a secure configuration baseline such as the CIS Benchmarks and...
Security automation turns your incident response steps into consistent, repeatable workflows, so teams contain routin...
An independent review of whether your security settings, access rules and procedures actually work, with risk-rated f...
After a breach, fraud or data leak, we preserve the digital evidence, work out what happened and report the facts cle...
Security testing for your web, mobile and API applications, combining automated scanning with expert manual checks so...
An independent check against ISO/IEC 27001, PCI DSS, SOC 2, GDPR or Indonesia's PDP Law, with a gap report and a plan...
Experienced security engineers, SOC and NOC analysts, DevOps engineers and developers placed in your team, on-site or...
What a cybersecurity risk assessment covers, how it differs from a security audit, and how directors can use both to ...
Practical steps to lower your data breach risk and recover faster: staff awareness, backups you have tested, regular ...
How to build a data leakage prevention strategy: classify sensitive data, control access, watch where data goes and c...
How to build security into a CI/CD pipeline: team awareness, the right guidelines, automated code and dependency chec...
The six building blocks we use to set up DevOps for clients, from developer tools and source control to build pipelin...
We build automated security checks into your software delivery pipeline, so flaws are caught early, releases keep mov...
Round-the-clock monitoring of your systems by our analysts, who investigate alerts, contain attacks and report clearl...
Snipeyes is a CREST-accredited, ISO/IEC 27001:2022 certified cybersecurity firm in Jakarta offering penetration testi...
Security built into how your software is designed, written and released, with threat modeling, automated pipeline che...
We run your 24/7 security monitoring, cloud operations, backup and service desk under one contract, with agreed servi...
Independent testing that shows whether your defenses would hold against a real attack, where your audit gaps are, and...
Security experts try to break into your networks, applications and cloud the way a real attacker would, then show you...
Nothing matches that search. Try another keyword, such as fintech or SOC.
By default we only use the cookies this site needs to work. Analytics (Google Analytics) and support tools (HubSpot, Typeform) stay off until you agree, in line with GDPR Art. 6(1)(a), ePrivacy rules and ISO 27001 controls A.5.34 and A.8.23. You can accept, reject or choose for yourself. No boxes are pre-ticked. We keep your choice for 6 months (ISO 27701 retention). Privacy Policy · Controller: Snipeyes, legal@snipeyes.com
You can change this anytime via “Cookie Preferences” in the footer.
Switch each purpose on or off. We follow ISO/IEC 27001:2022 and GDPR principles: use data only for its stated purpose, collect as little as possible, and be open about it. Learn more.
Jekyll session, CSRF, consent storage. No tracking. Retention: session to 6 months. Lawful basis: Legitimate interest (security).
Aggregated page views to improve content. Anonymized IP, 14-month retention. Only if you opt-in.
Chat, scheduling (Calendly), forms. Loads only with consent. Data transfers under SCCs.
Off by default. No marketing cookies currently set. Reserved for future, still opt-in.