Logo

Penetration Testing and Cybersecurity for a Pharma Company

Black-box penetration testing, social engineering and assistance with ISO 27001 and GxP compliance for a pharmaceutical company.

INDUSTRY

Healthcare

SERVICE

Cybersecurity

SUMMARY

Black-box penetration testing

"Black-box penetration testing, social engineering and assistance with ISO 27001 and GxP compliance for a pharmaceutical company."

A multinational pharmaceutical company with more than 50 branches worldwide needed to demonstrate security maturity ahead of ISO 27001 and GxP compliance requirements, standards where any gap in data integrity is a direct risk to patient safety.

Waverley's cybersecurity team ran a company-wide social engineering assessment alongside external and internal black-box penetration testing, then delivered a two-stage security audit mapped to the client's infrastructure and regulatory obligations.

The client's in-house IT team implemented Waverley's prioritized recommendations, closed the access points the testing exposed, and went on to pass the required security certifications.

ABOUT THE CLIENT

The Client

The client is a multinational pharmaceutical company headquartered in Europe, with more than 50 branches operating worldwide and medicines sold in markets across the globe.

Pharmaceuticals is one of the most heavily regulated industries in the world, and for good reason: a breach of data integrity does not just cost revenue, it can put patient safety at risk. Meeting that bar means proving security maturity to regulators and partners alike, which is what brought the client to Waverley for an independent, evidence-based assessment.

THE CHALLENGE

Project Analysis

Before this engagement, the client had internal security controls in place but no independent validation of how those controls would hold up against a real attacker, human or technical.

Two gaps stood out. First, the client needed to know whether its own employees, spread across more than 50 branches, would recognize and resist a targeted phishing attempt; weak password hygiene and low cybersecurity awareness are common failure points in large, distributed organizations. Second, the client needed a rigorous, standards-aligned audit of its technical infrastructure to support its ISO 27001 and GxP compliance efforts.

Both assessments had to be conducted without disrupting a company whose operations directly affect patient care, which ruled out generic, off-the-shelf testing and called for a program built around the client's specific systems and business needs.

SOLUTION

What We Delivered

Waverley's cybersecurity specialists designed a two-stage program that addressed the human and technical sides of the client's risk exposure together, rather than as separate workstreams.

Social Engineering Assessment

To test whether the human factor had contributed to prior exposure, Waverley's team ran a phishing email campaign across all 50 of the client's branches, aimed at identifying employees with weak password practices or low cybersecurity awareness. Findings were consolidated into a detailed report that also set out concrete guidance for educating staff going forward.

**

External Black-Box Penetration Testing**

Working with no prior insider knowledge of the client's systems, a team of cybersecurity specialists probed the client's external-facing infrastructure to identify potential access points, then helped the client close the highest-risk exposures immediately, ahead of further testing.

Internal Penetration Testing

Waverley's engineers then tested the client's defenses from the inside, using standard office and WiFi access available to any employee or visitor. That access was sufficient to reach the company's core systems, including its ERP software, management team email accounts, and servers. Left unaddressed, the vulnerabilities uncovered at this stage could have let an attacker interfere with budget and logistics controls, disrupt business-critical operations, or access highly sensitive information.

Compliance-Aligned Security Audit

All findings fed into a two-stage security audit built around the client's own infrastructure, industry requirements, and business needs, rather than a generic ISO 27001 checklist. The result was a prioritized set of vulnerabilities and concrete recommendations the client's own IT team could act on directly.

RESULTS

Outcomes & Impact

Waverley handed the client a full picture of its weak spots, ranked by risk, along with recommendations the in-house IT team could implement without external support. Based on Waverley's guidance, the client introduced additional security measures across its infrastructure and strengthened the systems the assessment had flagged.

Conclusion

Conclusion

For a company where a security gap can put patient safety at risk, good enough security isn't good enough. Waverley's combination of human-factor testing and technical penetration testing gave this client an honest, evidence-based picture of its exposure and a clear path to closing it, without slowing down a global operation.

It is the kind of independent scrutiny that regulated industries increasingly need to prove, not just claim, that they take security seriously.

Let's Build Something Great.

Tell us about your project — we'll find the right path forward.