C2C Platform

Web, API and mobile penetration testing for IPO security readiness

Information technology I Japan I Penetration Testing I One-month engagement

C2C challenge I Sunbytes Success Story

C2C Platform required a penetration testing partner that could provide:

End-to-end testing I Sunbytes Success Story

End-to-end testing across web, API, iOS and Android

Assessment I Sunbytes Success Story

Assessment mapped to OWASP Top 10 and API Top 10 risks

Rating I Sunbytes Success Story

Clear severity ratings for every identified finding

Follow rules I Sunbytes Success Story

Reproducible steps that its engineering team could follow

Remediation I Sunbytes Success Story

Practical remediation guidance, prioritized by urgency

IPO audit I Sunbytes Success Story

Reporting structured to support its IPO security audit

Sunbytes conducted penetration testing in a dedicated test environment covering the product’s web, API and mobile layers.

API pentest I Sunbytes Success Story
  • web application I Sunbytes Success Story

    Web application and API security testing

  • IoS I Sunbytes Success Story

    iOS and Android application testing

  • OWASP I Sunbytes Success Story

    Assessment against OWASP Top 10 and API Top 10 risks

  • Report vulnerabilities I Sunbytes Success Story

    A detailed report covering all identified vulnerabilities

  • Rating priorities I Sunbytes Success Story

    Severity ratings and remediation priorities for each finding

  • Delivery timing I Sunbytes Success Story

    Adjustments to the reporting format and delivery timing to support the IPO audit

Want to see if the fit is right for your team?

Why teams choose Sunbytes

A Netherlands-led partner that connects security evidence, delivery capability, and operational follow-through

ISO 27001-certified ISMS

Sunbytes operates an ISO 27001-certified ISMS, so information handling and access control have documented governance behind them.

Evidence-first security work

Security recommendations are mapped to evidence, ownership, and next actions so buyers and auditors can review what changed.

Dutch-led communication

European stakeholders get direct scope alignment, clear escalation paths, and accountable follow-up from a Dutch-led team.

Delivery-aware remediation

Security findings can be translated into software, infrastructure, and process changes through Sunbytes delivery capability.

Continuous security route

Baseline, readiness, specialist services, and CyberCare can connect without restarting context at every new request.

One operating partner

Secure work can align with delivery teams and people operations when access, onboarding, or governance affects the control environment.

The penetration testing engagement covered:

C2C solutions I Sunbytes Success Story
  • Web app security I Sunbytes Success Story

    Web application & API security

  • Mobile Security I Sunbytes Success Story

    iOS & Android application security

  • Risks I Sunbytes Success Story

    OWASP Top 10 and API Top 10 risk assessment

  • Vulnerability I Sunbytes Success Story

    Vulnerability validation and severity classification

  • Instruction I Sunbytes Success Story

    Reproduction instructions for identified findings

  • Guidance I Sunbytes Success Story

    Prioritized remediation guidance

  • Audit support I Sunbytes Success Story

    Audit-oriented reporting and clarification support

  • Findings identified I Sunbytes Success Story

    All findings identified during testing were documented across the web, API and mobile layers

  • KPIs planning I Sunbytes Success Story

    Both project KPIs, vulnerability detection and remediation completion, were fully achieved

  • IPO security audit I Sunbytes Success Story

    The final report supported
    the client’s preparation
    for its IPO
    security audit

C2C testimonials I Sunbytes Success Story

In their words

“They provided practical, prioritized remediation guidance that our team could act on immediately.”

Yoshiyuki Saigusa
CTO, C2C Platform Co., Ltd.

See also

  • DevSecOps and NIS2: what Dutch companies must do before July 2026

    DevSecOps NIS2 readiness means proving that your software development process has working security controls, not just written policies. Before July 2026, Dutch companies in scope for the Cyberbeveiligingswet need evidence for Article 21 controls such as secure development, supply chain security, access management and effectiveness testing. For engineering teams, the practical evidence usually comes from […]

  • NIS2 penetration testing requirements: what Article 21(2) compliance looks like

    NIS2 penetration testing is not a checkbox exercise. Article 21 does not name one single testing tool that every entity must use. It requires organisations to handle vulnerabilities and assess whether their cybersecurity risk-management measures work in practice. That distinction matters. A vulnerability scan can tell you that a known weakness exists. A DAST scan […]

  • NIS2 implementation roadmap: a 12-week plan for EU SMEs

    A NIS2 implementation roadmap should turn the directive into a sequence your management board, IT team, compliance lead, and suppliers can execute. For most EU SMEs, the work does not fail because Article 21 is unknown. It fails because scope, risk assessment, remediation, evidence, and board approval happen in the wrong order. This 12-week plan […]

  • The NIS2 minimum viable evidence pack: what to prepare for Article 21 compliance

    A NIS2 evidence pack is the documentation your organisation uses to prove that Article 21 cybersecurity risk-management measures are not only written down, but implemented. For EU SMEs, the problem is scattered evidence: one access review in a spreadsheet, one supplier check in procurement, one incident procedure in IT, and no single view that connects […]

  • How to run a NIS2 gap analysis: the 5-step assessment framework

    A NIS2 gap analysis turns regulatory pressure into a working plan. It shows which cybersecurity measures already exist, which ones are missing, which gaps create the highest risk, and what evidence the company needs to produce. For EU companies preparing for NIS2, the goal is not to create another policy document. The goal is to […]

  • NIS2 Article 20: management accountability obligations for company leadership

    NIS2 management accountability is no longer a topic only for the CISO or security team. Under Article 20 of the NIS2 Directive, cybersecurity governance becomes a management responsibility. NIS2 management accountability means the management body of an essential or important entity must approve cybersecurity risk-management measures, oversee their implementation, follow cybersecurity training, and keep evidence […]

Download the full case study!

Get the complete story—challenge, delivery setup, scope, outcomes, and the full testimonial.

Contact I Sunbytes Success Story
This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.