CASE STUDY
How BPM’s Penetration Test Helped a Community Bank Hold a Vendor Accountable
September 11, 2026
Services: Penetration Testing Services Industries: Banks & Credit Unions
An Oregon based community bank has spent more than nine decades building trust across its nine Oregon locations, a reputation the institution takes seriously when it comes to protecting customer data. That commitment extends beyond the systems the bank controls directly and into the technology supplied by its outside vendors, an area that increasingly shapes a financial institution’s overall risk profile.
Problem
The bank engaged BPM’s Cybersecurity IT Advisory team to evaluate the security of its network, systems, and third-party technology. The assessment identified a vendor-managed device that was using insecure communication protocols and contained unpatched vulnerabilities, either of which could expose the institution to unauthorized access or data compromise. Because the device was controlled and supported by a third party rather than the bank itself, the bank faced a common but frustrating obstacle in financial services: it could see the risk clearly, but it needed objective, third-party evidence to convince the vendor to take the finding seriously and commit to remediation.
This is a familiar dynamic for community banks. Regulators expect financial institutions to manage third-party technology risk with the same rigor applied to internal systems, yet banks rarely have direct control over how a vendor configures or patches its own equipment. When a vendor is slow to act, or disputes the severity of a finding, the institution is often left negotiating from a position with little independent leverage of its own.
Solution
BPM’s Cyber team conducted an external penetration test designed to probe the bank’s network perimeter, systems, and connected third-party technology the way a real attacker would. The engagement surfaced the vendor-managed device’s insecure protocols and outstanding vulnerabilities, and from there, BPM’s focus shifted to building a record the bank could act on. Rather than a generic vulnerability list, the team produced validated technical findings, supporting evidence, and clear, prioritized remediation recommendations written specifically so that the bank could hand them directly to the vendor and make the case for immediate action.
That distinction mattered. Vendors often resist remediation requests that arrive without independent verification, especially when a fix requires reconfiguring a device or disrupting an existing service arrangement. By grounding the findings in a credible, third-party assessment, BPM gave the bank the leverage it needed to move past resistance and treat the issue as a contractual and risk-management priority rather than an open-ended conversation.
Outcome
Armed with BPM’s findings, the bank applied appropriate contractual and risk-management pressure to require its vendor to disable the insecure configuration and resolve the outstanding vulnerabilities. The engagement reduced the bank’s third-party technology risk and reinforced a broader principle that applies well beyond this single vendor: outside relationships need the same scrutiny as internal systems, and accountability has to be enforceable, not assumed.
The project also illustrated a role penetration testing can play that goes beyond checking a compliance box. The engagement became a catalyst as much as a diagnostic tool, giving the bank a way to convert a known but unresolved risk into a resolved one on a timeline the institution controlled rather than one dictated by the vendor. For financial institutions managing an expanding web of vendor relationships, from core processors to specialized edge devices, that combination of technical validation and negotiating leverage is often the difference between an identified risk and a remediated one.
Linsey Gallo
Cybersecurity Compliance Manager, Advisory
Linsey helps organizations bridge the gap between business objectives, technology decisions, and cybersecurity risk through virtual Chief Information Security Officer …
Josh Schmidt
Partner, Advisory
Josh started his career building IT systems in 2009 and has nearly a decade of experience working directly with clients …