How Generali Secured Two Key Digital Applications for the Insurance Onboarding Process?

The Challenge
Digital insurance processes today carry the same weight as paper documentation did twenty years ago, but now they’re far more exposed. For Generali, one of the leading insurers, two web applications supporting the insurance process represented the point where customer trust, regulatory requirements, and operational risk all meet.
The question wasn’t whether the applications worked, it was whether they were secure enough to withstand a real attack attempt, with everything that implies: access to customer data, the business logic behind policy processing, and the integrity of communication with connected services.
The Process
Saga carried out a security assessment of both applications as a gray-box penetration test, following the OWASP Web Security Testing Guide (WSTG) methodology — the same standard used by security teams at leading financial institutions.
Each test ran for one week and used standard-privilege user accounts, simulating a realistic scenario: an attacker who already has some level of access, not just an external actor with no credentials at all.
Testing combined manual and automated techniques, focusing on:
Once the report was delivered, Generali implemented the recommended fixes, and Saga carried out a retest to confirm that the identified weaknesses were genuinely resolved, not just marked as fixed.
The Result
The retest confirmed that all identified vulnerabilities were successfully remediated, and the measures applied effectively strengthened the security of both applications. This is the key difference from a standard “test-and-done” approach: the process doesn’t end with a report — it ends with proof that the risk has actually been removed.
Client Voice

“We want to express our great satisfaction with the collaboration during the penetration testing engagement. The team demonstrated a high level of expertise, professionalism, and commitment, with clear and timely communication. The testing conducted was thorough and systematic, and the delivered report was exceptionally high-quality, well-organized, and practically oriented, with clearly described vulnerabilities, risk assessment, and concrete recommendations for remediation.
We would especially highlight the support provided during the remediation process, as well as the effectiveness of the retest, which confirmed the success of the corrective measures applied. Thanks to the professional approach and expert guidance, we improved the security level of our systems and gained additional confidence in their reliability.”
Dragan Živojinović, Cyber Security Analyst, Generali
From the Perspective of the Team That Conducted the Test
“The testing was conducted as a gray-box security assessment, using standard-privilege user accounts and in line with OWASP WSTG guidelines. Special focus was placed on analyzing application functionality, communication between the application and connected services, as well as reviewing authentication, authorization, session management, and business logic mechanisms.”
Vanja Topalović, Saga
What's Next
For Generali, this engagement wasn’t a one-time check but part of a long-term approach to securing digital insurance processes — with a retest cycle that ensures every corrective measure is not only applied, but confirmed.
Schedule a security assessment of your IT environment.
Topic: Penetration Test
Portfolio: Cyber Security
Reading time: 3 min