A comprehensive security audit of the public cloud environment verified the resilience of both the infrastructure and applications against cyberattacks.

Geetoo Technology s. r. o. is one of the pioneers of cloud services in the Czech Republic. With more than twenty years of experience, it designs, operates, and manages cloud infrastructure for customers across Europe.

As the importance of cloud services grows, so does the emphasis on their security. That is why Geetoo decided to verify the resilience of its public cloud environment through independent penetration testing.

Project Brief

The goal was to independently verify the security of the Geetoo public cloud environment, focusing on the segmentation of customer environments and the possibility of obtaining privileged administrator privileges on the vCloud platform.

Requirements

The client requested penetration testing of the public cloud environment, focusing primarily on:

  • verifying the segmentation of customer environments,
  • simulating the acquisition of privileged vCloud platform administrator privileges,
  • identifying potential security vulnerabilities across the network, system, and application layers,
  • and preparing a technical report, including recommendations for further security enhancements.

Solution

As the prime contractor, Principal arranged for penetration testing to be conducted by its specialized partner, Noibit s.r.o.
The testing was performed in accordance with the OWASP Web Security Testing Guide (WSTG) methodology and included a comprehensive assessment of the cloud infrastructure across the network, system, and application layers.

The testing included verification of network isolation between individual tenants, the possibility of escalating privileges to the administrator level, the security of authentication mechanisms and JWT tokens, and the environment’s resilience to both common and advanced cyberattack scenarios.

During the assessment, an associated storage infrastructure with an outdated software stack was identified beyond the original scope and was also included in the security evaluation.

Assessment of the Partnership

We greatly value our partnership with Principal because we share a commitment to quality, effective communication, and professionalism. Thanks in part to this, the project was implemented smoothly and as expected.

Kristýna Krestová
CDO & Project Manager
Noibit s.r.o.

Result

The project resulted in the testing of the Geetoo public cloud environment according to defined requirements and the preparation of a comprehensive report on vulnerabilities and related findings. The project was carried out from May 18 to June 5, 2026, within the planned timeframe and budget. Since no critical flaws were found, it was not necessary to conduct retests or a follow-up workshop.

Technologies Used

  • OWASP WSTG
  • Nmap

Would you like to verify how resilient your IT environment is against cyber threats? Contact Jiří Kvasnička, who will be happy to introduce you to penetration testing options and other cybersecurity services.

jiri kvasnicka

Jiří Kvasnička

Delivery Manager

This email address is being protected from spambots. You need JavaScript enabled to view it. 

+420 724 717 792

News from PRINCIPAL and IT

Get tips and inspiration to accelerate your digital transformation

logo Contractors

We are looking for enthusiastic people who want to join our team and help us create great IT solutions.

Click below to see what positions we are currently looking for at PRINCIPAL headquarters in the Czech Republic.

Find out more at contractors.cz

Later