Cybersecurity • • 9 min read

Inside a regulated fintech's Agentic SecOps penetration test

How we combined machine-speed coverage with human judgment to assess live payment infrastructure, expose material risk quickly, and give a regulated fintech a practical path to remediation.

Edwin Kairu

Edwin Kairu

Co-Founder and CEO, Tabiri Analytics

Secure digital payment infrastructure under assessment

A penetration test on a live payment platform has no room for theater. The environment moves money, connects third parties, and sits under regulatory scrutiny. Coverage matters, but so do restraint, evidence and the ability to turn a finding into a verified fix before it becomes an incident.

I led Tabiri's technical work for a regulated fintech with that reality in mind. The engagement covered external and internal vulnerability assessment and penetration testing across a hybrid environment, authenticated payment workflows and the operational controls required by applicable cyber security guidance. We had a compressed regulatory timeline, a production system to protect and a broad attack surface to understand. That combination made it an ideal real-world deployment of our Agentic SecOps methodology.

We began with boundaries, not scanners

Good testing starts with disciplined scoping. Before we touched the environment, our teams aligned on the asset inventory, public endpoints, internal systems, partner-managed integrations, exclusions, network and data-flow diagrams, access methods and escalation paths. We also agreed on low-traffic testing windows and a notification process for any action that could affect availability.

Those controls were especially important because this was not a lab. The client's services were live. Every source address was coordinated, internal access was provisioned through an approved testing host and potentially disruptive activity remained under engineer control. Agentic does not mean unconstrained.

The operating principle

Let agents handle repeatable discovery, correlation and evidence structure. Keep scope, judgment, exploitation decisions, escalation and final validation in the hands of experienced security engineers.

External first, then authenticated internal depth

We started with the externally accessible attack surface while internal access was being finalized. That allowed reconnaissance and vulnerability detection to move in parallel with environment staging. Once approved access was ready, we deployed the orchestrator inside the client's network on a controlled Kali Linux testing VM and moved into authenticated internal assessment.

The combined view mattered. Public exposure alone rarely explains the full risk of a payment system. We correlated evidence across 31 service hostnames, every TCP port on the in-scope internal network and authenticated payment workflows. We examined service relationships and privilege boundaries rather than treating each scan result as an isolated alert.

travel_explore

Coverage

Agents sustained broad discovery across external, internal and authenticated surfaces without losing the relationship between assets.

history

Traceability

The testing agent maintained action history and structured evidence as work progressed, reducing reporting gaps and making review faster.

verified_user

Judgment

Our engineers directed every action, challenged machine-generated hypotheses and manually validated material findings before escalation.

The finding that changed the tempo

Within the first two hours, the assessment exposed a critical cross-merchant authorization flaw. We will not publish the reproduction path or affected implementation details. What matters is the response loop: the evidence was reviewed by our engineers, communicated through the agreed escalation path, patched by the customer and retested by Tabiri the same day.

That is the practical value of speed in security. A faster test is only useful when it shortens the time between exposure, understanding, remediation and proof. In this case, machine-assisted discovery and evidence handling gave the human teams more time to focus on impact and corrective action.

Broader coverage, earlier warning of critical risk, same-day validation of a fix, a complete audit trail and more time to meet compliance obligations.

How this differed from a traditional manual test

In a traditional engagement, skilled testers spend a significant share of the schedule launching tools, normalizing output, deduplicating observations, rebuilding context across systems and formatting evidence. Those tasks are necessary, but they compete with the work that most needs expertise: forming attack hypotheses, understanding business logic, deciding what is safe to test and determining whether a result is genuinely exploitable.

Our configured agent continuously executed approved assessment tooling, tracked what had been attempted, correlated results and organized findings as they emerged. The engineers remained in the loop for direction and review. This division of labor allowed us to deliver a prioritized resilience roadmap in 24 hours, up to 14 times faster than the comparable manual process, while assessing 100% of internal TCP ports in scope.

The customer benefit was not simply a shorter invoiceable timeline. The client received broader coverage, earlier notice of critical risk, same-day validation of a fix, a complete audit trail and more runway to address compliance obligations before its deadline.

Technical evidence was only half the assessment

Infrastructure testing can tell us where a control failed technically. It cannot, by itself, establish whether governance, authorization, staff processes or incident-response practices are mature. We therefore paired the VA/PT with an operational assessment covering governance, risk management, data protection, access management, security architecture and incident response.

We brought both streams into one report. Validated technical findings, operational responses, remediation guidance and control evidence were mapped to applicable cyber security guidance and relevant PCI DSS requirements. The result was not a scanner export. It was a decision document for engineers, executives and compliance stakeholders.

What I took away from the engagement

Agentic SecOps is already useful in production but only when it is engineered around accountability. The strongest part of this engagement was not autonomous execution in isolation. It was the collaboration between the client's technology team, Tabiri's security engineers and a system that could maintain coverage and context at machine speed.

That model changes what a penetration test can deliver. It makes comprehensive testing practical under tight deadlines, surfaces material risk earlier and preserves the human judgment required for live, regulated systems. For the client, it meant moving from uncertainty to a verified fix and a prioritized resilience roadmap in a day. For our team, it was further proof that the future of security operations is not human or agent. It is expert-led, agent-accelerated defense.

Test at Machine Speed. Decide with Human Judgment.

Put Agentic SecOps to work on your attack surface

Combine broad technical coverage, validated findings, and compliance-ready evidence in one engineer-led assessment.