Case study: Web Penetration Test on TSV8 by Add Value S.r.l.

This case study concerns Add Value S.r.l., an IT company based in Verona that develops innovative IT solutions for the small and medium-sized enterprise market. When the team decided to subject their TSV8 web application to a structured security audit, they chose to rely on ISGroup for a Web Application Penetration Test.

The case illustrates how a technical analysis conducted with a methodical approach can turn into a concrete path for improvement: from identifying points of attention to defining a remediation plan, up to the growth of cybersecurity skills within the team. The full case study is available on the ISGroup website: TSV8 Web Penetration Test for Add Value S.r.l.

🔴 Web Application Penetration Testing: identify hidden risks and strengthen your security with a focused assessment by ISGroup specialists.

The context: a web application to be secured

Add Value S.r.l. develops software solutions for business process management. TSV8 is one of the web applications at the heart of their offering: a tool used by real customers, containing sensitive data and critical operational flows.

Before proceeding with the product’s evolution, the team felt it was necessary to verify the application’s security level systematically. The goal was not just to find potential vulnerabilities, but to acquire a clear vision of the security status and have operational guidelines for improving it.

How ISGroup conducted the Web Penetration Test

ISGroup performed a Web Application Penetration Test on TSV8, simulating real attack scenarios to evaluate the application’s resilience. The approach combined manual analysis and specialized tools, following internationally recognized methodologies such as OWASP.

At the end of the activity, ISGroup delivered a detailed report to Add Value with the identified points of attention and a structured remediation plan, with clear priorities and operational instructions for the development team.

Results: remediation, awareness, and skills

The journey with ISGroup produced three concrete results for Add Value.

The first is the resolution of the points of attention identified during the test: the team was able to intervene with precision, without distractions, following the priorities indicated in the remediation plan.

The second is the growth of internal awareness: facing a penetration test conducted by external specialists allowed the development team to better understand the attack surfaces typical of web applications and to integrate a security perspective into their daily work.

The third is the strengthening of cybersecurity skills within the organization, with an impact that goes beyond the single test and is reflected in future development practices.

The full case study, with all the details of the intervention, is published at: Add Value S.r.l. Case study – ISGroup.

Frequently asked questions about the Web Application Penetration Test

  • What is a Web Application Penetration Test?
  • It is an offensive security activity in which experts simulate real attacks on a web application to identify vulnerabilities before they can be exploited by malicious actors. Unlike an automated scan, the penetration test includes manual analysis and contextual reasoning about application logic.
  • When is it appropriate to perform a WAPT?
  • Before releasing a new application or a significant version, after major architectural changes, following a security incident, or as a scheduled periodic check. For SMEs that handle customer data, it is a concrete and proportionate security measure.
  • What do you get at the end of the test?
  • A technical report with the identified points of attention, their classification by severity, and a remediation plan with operational instructions. The document is designed to be usable by both the technical team and management.
  • Is WAPT also suitable for SMEs?
  • Yes. The case of Add Value S.r.l. proves it: even a small-sized company can derive concrete benefits from a penetration test, both in terms of product security and the growth of internal skills.
  • What is the difference between Vulnerability Assessment and Penetration Test?
  • The Vulnerability Assessment identifies known vulnerabilities through automated tools and structured analysis. The Penetration Test goes further: it simulates a real attack scenario, verifies if the vulnerabilities are actually exploitable, and evaluates the concrete impact. The two services are complementary.

Useful insights

If you are evaluating how to improve the security of your web application or your IT perimeter, these contents can help you get oriented:

Protect your organisation with Web Application Penetration Testing.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert