What 345 Days of Untested Exposure Looks Like at a Bank
… They are not the bank's application, the bank does not have source code, the bank does not control releases, and the vendor maintains its own security program. Institutions reasonably decide the platform vendor is responsible for testing its own code and exclude the hostname from the engagement. …