Efficient and Collaborative: How Origin Turned Pentesting From Admin Burden to Routine Confidence

How a fintech bond-market platform replaced a high-turnover pentest vendor with a consistent, streamlined partner, cutting the end-to-end testing process from six to eight weeks down to around four.

About Origin

Origin is a fintech company, leading a digital, front-end-back issuance platform for debt capital markets. Founded 11 years ago, they connect market participants in the bond market. The platform supports legal contract generation, collaboration between counterparties, and analytics, helping banks and their borrowing clients manage bond issuance more efficiently.

The Challenge: A High Bar for Information Security, Undermined by Vendor Turnover

Origin’s clients are investment banks, and with banking brings a very high bar for information security. Origin has held ISO 27001 certification since 2022, and had aligned its policies with the standard for a number of years before that. As the business has grown, so has the scope of its security programme.

Penetration testing has been part of that programme for years, with nine tests carried out to date. For a stretch of those years, Origin worked with a single, larger vendor. But staff turnover at that vendor, followed by the business being sold, meant Origin found itself re-explaining its platform to new personnel every year.

“It felt less streamlined. It was always someone different, and while they were good pentesters, they had no context on our business. Every year felt like starting from scratch because there was no continuity.” – Robert Taylor, Co-founder & CTO

This lack of continuity, more than any single test result, is what pushed Origin to look for a different provider. They have since completed two penetration tests with OnSecurity.

Why Origin Chose OnSecurity

Robert compared the two vendors directly: with the previous provider, Origin was a smaller client of a much larger business. OnSecurity, by contrast, offered a more personal relationship from the outset.

“The previous vendor was a much bigger, established business, so we were just another line item. With OnSecurity, being a startup, it felt like a much more personal, customer-care interaction.” — Robert Taylor

Robert was candid that the OnSecurity platform was still early in its development when Origin first started using it, and that its value wasn’t immediately obvious. Two years on, he sees the benefit clearly, particularly in how it lets Origin plan testing engagements well ahead of time.

“The platform has come a long way since we onboarded. We can now book test dates a year in advance, which lets us streamline the whole process as much as possible and save hours of manual work.” — Robert Taylor

The Solution: Testing Focused on Authentication, Permission, and Data Separation

Origin’s architecture has stayed broadly consistent for at least three years: fully hosted on AWS, with no on-premises infrastructure, and a client base of banks rather than mass-market consumers, so scaling isn’t the main challenge. Testing with OnSecurity now covers:

  • Scanning and checks of Origin’s AWS accounts, alongside automated testing used as an ongoing sanity check
  • Testing of Origin’s public-facing, API-key-protected endpoints
  • In-depth testing of authentication and permission controls, and of data separation between the different banks using the platform

“The most important thing on our platform is authentication, particularly around permissioning and data leakage. Different banks use the platform, and their data is extremely confidential. If, by accident, data from one bank ended up with another, that would be disastrous for us.”

To date, Origin has never received a critical finding from a penetration test. Robert is clear that this doesn’t make testing any less valuable; it’s part of why the process now feels routine rather than high-stakes.

“In the history of our pentesting, we’ve never had a critical finding. Even though our architecture has matured over the years, we still believe in the critical importance of pentesting, because we can always get something wrong.”

Team Workflow: A Lean Team, a Clear Owner

Origin runs with a team of eight. Origin’s Head of Infrastructure owns the day-to-day relationship with OnSecurity’s testers, ensuring they have the credentials and access they need. As Co-founder and CTO, Robert oversees the wider technology and product function but stays largely hands-off during test execution itself.

Origin’s policy is to remediate everything above a low-severity finding, and to fix low or informational findings where possible. Once findings are in, the wider team reviews them together to prioritise and, occasionally, to discuss severity.

The Impact: Less Admin, Faster Turnaround

Origin can’t put a precise cost figure on the switch, but the time savings are clear. Under the previous vendor, ad hoc scheduling meant a roughly three-week lead time to book a test, which in practice cost Origin close to a month of testing time each year.

“We used to leave scheduling until the last minute, which meant a three-week lead time and effectively losing a month of testing every year. Now we book a year ahead, so it just happens without needing to be actively managed.”

Robert also estimates that the overall process, from scoping through to final report, now takes around four weeks with OnSecurity, compared with six to eight weeks previously.

“My gut feel is that with OnSecurity, the whole process was done in about four weeks, compared to six to eight weeks with our previous provider.” – Robert Taylor

Results

  • Reduced end-to-end testing process from six to eight weeks down to around four weeks
  • Removed the admin overhead of ad hoc scheduling by booking test dates up to a year in advance
  • A single, consistent point of contact in place of a rotating cast of testers
  • Continued confidence in authentication, permissioning, and data-separation controls that protect confidential bank data

Would Origin Recommend OnSecurity?

“Our security posture has definitely improved. It’s valuable having a reliable, experienced partner. Working with OnSecurity has been seamless.” Robert Taylor

“I’d describe the relationship as efficient and collaborative. I’d highly recommend it. If people ask me, I’m very open about how positive our experience has been.”

Robert Taylor, Co-founder & CTO, Origin

Start your security partnership with OnSecurity today. Get an instant quote now.

Related Case Studies