NBFC / SECP penetration testing
NBFC cybersecurity testing (SECP, Pakistan)
Vulnerability assessment and penetration testing for SECP regulated entities, including digital lending app audits.
Engagement at a glance
Drives testing
SECP cybersecurity advisories and digital lending circulars: Security testing for regulated entities
Cadence
At least annually, before a digital lending app launch, and after significant change
Typical duration
2 to 4 weeks of testing, plus retest
Region
Pakistan
Issued by
Regulated by the Securities and Exchange Commission of Pakistan
SECP
Regulator
Circular 15
Digital lending requirement
PK
Team based in Pakistan
Annual
Testing cadence
The requirement
What NBFC / SECP asks for
SECP cybersecurity advisories and digital lending circulars · Security testing for regulated entities
SECP expects regulated entities to maintain and test cybersecurity controls, reinforced through advisories including Cyber Security Advisory Circular 10 of 2025. Digital lending apps require a cybersecurity compliance certificate from a PTA approved Cyber Security Audit Firm before SECP whitelisting under Circular 15.
Non-bank finance companies in Pakistan, including lending, leasing, investment and asset management firms, are regulated by the SECP. Alongside conduct and licensing rules, the regulator expects regulated entities to protect customer and financial data and to test that those protections work.
Digital lending is where this bites hardest. Under Circular 15, a digital lending app needs a cybersecurity compliance certificate from a PTA approved Cyber Security Audit Firm before SECP will add it to the approved whitelist. The regulator is specific about protecting borrower data, including phone contacts and photo galleries that predatory apps have historically abused.
XHack is based in Pakistan and tests against these expectations directly. We assess your customer-facing platforms, core systems and lending apps, report findings the regulator will understand, support remediation, retest to closure and sign an attestation letter. Licensing, conduct and regulatory filings remain your responsibility.
What your auditor checks
The report has to clear every one of these
These are the questions a NBFC / SECP auditor asks of a penetration test before accepting it as evidence. Every engagement we run is built to answer all of them.
Independent testing by a qualified firm
Scope covering customer-facing and core financial systems
Mobile application testing where a lending app is in scope
Recognised methodology documented in the report
Findings rated consistently with CVSS v4.0
Explicit coverage of borrower data and device permissions
Evidence of remediation with dates
Independent retest confirming closure
Report suitable for regulatory submission and inspection
Signed attestation letter from the testing firm
What we test
Where the testing effort concentrates
The surfaces this engagement covers, weighted by how much of the work they typically represent. Scope is confirmed with you before anything starts.
Customer-facing platforms and portals
Web and mobile applications
95%
Digital lending application
Android and iOS, static and dynamic
90%
Borrower data and device permissions
Contacts, gallery, location, storage
90%
Core APIs and backend systems
Authorization and financial transaction flows
85%
Infrastructure and perimeter
Internet-facing services and hosts
70%
Weights are indicative of typical effort. Your exact scope is agreed and signed before testing begins.
How the engagement runs
Scope, test, close, attest
Typically 2 to 4 weeks of testing, plus retest. The retest is included, because a report full of open findings is not evidence of anything.
Scope against regulatory expectations
We map which systems matter to the regulator, including any digital lending app and the borrower data it touches, and agree the rules of engagement.
Test platforms, APIs and apps
Web, API, infrastructure and mobile testing, with static and dynamic analysis of Android and iOS builds where a lending app is in scope.
Report for the regulator
Findings written so a regulator or inspector can follow them, with explicit treatment of borrower data handling and device permissions.
Remediation support
Your team fixes. Anything exposing customer or financial data is escalated the day we find it rather than held for the report.
Retest and attestation
Every finding retested and closed, with a signed attestation letter suitable for regulatory submission.
Where the effort goes
Share of a typical engagement, by phase
Scoping & rules of engagement
15%
Testing & exploitation
45%
Reporting & mapping
20%
Retest & attestation
20%
What we bring
Built for the NBFC / SECP auditor specifically
The parts of this engagement that are shaped by the framework rather than copied from a generic testing template.
Local, and in the room
We are based in Pakistan and work with SECP expectations directly, including how findings are best presented for inspection.
Mobile testing included
Static and dynamic testing of Android and iOS lending apps, covering hardcoded secrets, insecure storage and runtime weaknesses.
Borrower data scrutinised
Explicit testing of device permissions and data handling, the area the regulator has been most vocal about.
Written for submission
A report and attestation letter formatted so it can go to the regulator without rewriting.
The deliverable
What lands on your auditor's desk
A report structured so the evidence sits where the auditor is already looking, with every finding mapped to the control it touches.
In the report
Signed letter of attestation with testing dates
Scope covering platforms, APIs, infrastructure and mobile apps
Methodology, qualifications and independence statement
Findings with CVSS v4.0, evidence and reproduction steps
Borrower data handling and device permission analysis
Remediation implemented and independent retest result
Summary formatted for regulatory submission
Control mapping
How the report evidences each control
SECP cybersecurity advisories
Independent testing evidence of the controls the advisories expect.
Circular 15 digital lending
Security assessment of the lending app ahead of the required audit certificate.
Borrower data protection
Explicit testing of device permissions and personal data handling.
Financial transaction integrity
Authorization and transaction flow testing across core APIs.
Incident readiness
Evidence of whether monitoring detected the test activity.
Where our work stops, and who takes it from there
XHack provides the penetration testing evidence for SECP cybersecurity advisories and digital lending circulars. We do not issue certificates, attestation opinions or regulatory approvals, and we do not run your wider compliance programme. For NBFC / SECP, that sits with: Regulated by the Securities and Exchange Commission of Pakistan. Staying independent of them is exactly what makes our evidence worth something when they review it.
Questions
NBFC / SECP testing, answered
The cybersecurity compliance certificate for SECP whitelisting comes from a PTA approved Cyber Security Audit Firm. What we do is test the app and its backend the way that audit will, and report the findings, so nothing in the certificate review is a surprise to you.
Borrower data. SECP has been explicit about apps that harvest phone contacts and photo galleries. We test device permissions, what the app actually collects, how it stores and transmits it, and whether the backend leaks it.
No. Licensing, conduct requirements and regulatory filings are your responsibility, usually with legal and compliance advisers. We provide the security testing evidence that supports them.
Under signed rules of engagement and a Data Processing Agreement. No live customer or financial data is exfiltrated, and anything captured to prove a finding is redacted in the report.
Get the NBFC / SECP evidence sorted
Tell us who is auditing you and when your review period closes. We will scope the test, tell you what it costs, and make sure there is room to remediate and retest before the deadline.