The Bank of Lithuania monitors financial institutions to ensure banking system safety, protect depositors and investors, and promote financial stability. It requires annual ICT risk and security assessments, including penetration testing, to support continuous security improvement.
This case study highlights the collaboration between General Financing Bankas and Baltic Amadeus in delivering penetration testing to identifysecurity gaps and strengthen cyber security.
General Financing Bankas is a Lithuanian bank offering a range of financial products and services, including savings accounts, consumer loans, and term deposits. The bank operates a network of branches across Lithuania and is committed to delivering fast, efficient, and secure services to its customers.
To maintain a high level of digital security and meet regulatory requirements, the client conducts regular security assessments. For this purpose, the bank sought an IT partner with certified cyber security specialists and proven expertise in penetration testing.
Baltic Amadeus proposed IT consulting and penetration testing services to evaluate the client's ICT infrastructure and information systems, as well as to provide clear recommendations for strengthening security controls.


During the project, Baltic Amadeus conducted multiple authorised and unauthorised penetration tests across the client's information systems and infrastructure. These included internal server subnet testing, external penetration testing, and cloud security assessments.
The scope also covered frontend and backend vulnerability assessments, API penetration testing with authorised user access, evaluation of cloud environment configurations, security checks of internal equipment, and vulnerability assessments of externally exposed assets.
At the final stage, Baltic Amadeus delivered a comprehensive report to the client’s team. The report outlined all identified areas for improvement, including technical misconfigurations, vulnerabilities, associated risks, and detailed vulnerability exploitation scenarios. The assessment also supported the bank's adherence to regulatory and security standards.
The penetration testing provided the General Financing Bankas with a clear view of potential risks to its systems and data from an attacker's perspective, strengthening its ability to prevent security incidents and financial losses.
The final report enabled the internal team to clearly understand the bank's current cyber security state and take informed steps to improve its overall security posture.
The assessment was conducted by certified, highly skilled ethical hackers holding CEH, CISA, CISSP, CDPSE, OSCP, CREST CRT, and ITIL certifications. In addition, Baltic Amadeus continues to support General Financing Bankas as a trusted technology partner in maintaining strong cyber security practices.
