How Plum went from an annual pentest to Continuous Hybrid Validation.

Plum needed a way to replace a single annual pentest with continuous security validation it could rely on for audits, due diligence, and AI-driven attacks. Find out how Strike helped make its security validation continuous, audit-ready, and AI-powered.

Client
Plum
Date
September 14, 2026
Industry
Finance
Country
Europe

Security that drives business forward.

[01]

0 findings held against them in audits and due diligence processes.

[02]

From 1 mandatory annual test to continuous testing all year round.

[03]

Direct communication channel with a dedicated account manager.

Context and challenges

Before working with Strike, Plum had no pentesting service of its own. Certain IT and security requirements meant they had to run at least one test a year, so they went out to the market looking for a solution. At the time, the team only knew the conventional model: hire a company once a year, hand over the full scope (internal, external, DDoS) and wait for a report.

The underlying problem wasn't just finding a vendor: it was that, as a regulated fintech, Plum constantly goes through IT audits and due diligence processes where they're asked for pentesting documentation, reports, and evidence of the process. Every one of those processes is a chance to be exposed if the security validation isn't up to the task.

THE NEED WAS CLEAR:

Plum needed to go from having no pentesting process of its own to being able to prove, in any audit or due diligence process, a continuous and documented security practice.


Working with Strike

Strike introduced Plum to a model they didn't know: configurable, schedulable tests, constant communication through a dedicated Slack channel, and testers ("strikers") assigned based on the expertise needed for the industry and product.

Later, when Plum's team started seeing that their own systems could no longer only be attacked manually but by AI as well, the conversation with Strike moved a step further: adopting AI testing as part of the same continuous model, without losing a human expert's manual review along the way.


[01] A platform that doesn't waste your time

The migration to Strike's new platform was, in the words of Plum's own team, practically frictionless. They were able to add and remove users, and every time there was a specific login issue, Strike's team fixed it right away. What they valued most was the simplicity compared to other security tools they use every day.

"UI is very clean. With some other solutions I see a hundred different things, buttons. I go to Strike, I see two things: the targets, start or configure. Quite easy."
OZAN OZGUR OZYUKSEL
Chief Information Security Officer (CISO) & DPO at Plum

Loading a new target comes down to a few steps. Description, importance, criticality, notes, and then access. No lengthy forms or configurations that leave you lost across screens, something Plum flagged as a recurring problem with other security tools they use.

That simplicity holds up after the target is set up, Strike's Vulnerability Manager consolidates visualization, management, and retesting of every vulnerability in a single platform, so Plum's team doesn't have to jump between tools to see the status of each finding.

[02] Testing the way attackers do it today

For Plum, adding AI to their security validation wasn't an efficiency decision, it was a direct response to how the attacks they face have changed. In Strike's Hybrid Continuous Validation model, AI agents run threat emulations autonomously, but every finding goes through a human expert's validation before it reaches the client, something that gave Plum the confidence to make the jump.

That format also changed how they test small changes, instead of running the full test to validate one specific update, they can now request a test without waiting on a full cycle. This is backed by Strike's AI-powered on-demand retesting, which validates a fix as soon as it's ready instead of waiting for the next full testing cycle.

They also found value in something they didn't expect: the step-by-step trace of what the AI attempts during each run

"When I see the AI trying stuff, giving more focus to a specific endpoint, it kind of reminds me: okay, maybe I need more controls around that endpoint, because the AI thinks it's critical."
OZAN OZGUR OZYUKSEL
Chief Information Security Officer (CISO) & DPO at Plum

That trace doesn't just work as an audit log for Plum's internal security team: it gives them concrete ideas for their own hardening, like strengthening rate limiting where the AI focuses most.

The first time they ran a test with AI, Plum's team had doubts that something could break in production. Strike supported them through that moment with direct communication and the ability to pause or revert the test if something went wrong, which gave them the confidence to move forward.

[03] A dedicated account manager who knows your scope

With dozens of urgent things happening at once, having one assigned person in a direct Slack channel with Strike (and now also visibility into what the AI is doing) was key for Plum to avoid getting stuck waiting on a call or an email.

"You gave me a good example, a good suggestion about periodic testing on my back office, which I hadn't thought about. I was doing it manually."
OZAN OZGUR OZYUKSEL
Chief Information Security Officer (CISO) & DPO at Plum

That level of support, knowing Plum's scope, remembering their testing history, and suggesting improvements before the client even asks, is, in Plum's own words, the biggest strength of working with Strike.

This specific recommendation isn't a one-off, it's part of how Strike's Customer Success team works. Every account has a dedicated account manager, who doesn't just coordinate the logistics of each test, but keeps close track of each client's history and scope in order to propose improvements and respond when something breaks. For Plum, that long-term view is what turned a one-off suggestion ("test the back office periodically") into part of their security routine.

For Plum, moving from an annual pentest to Continuous Hybrid Validation wasn't just a vendor change, it meant no longer auditing themselves once a year and instead validating continuously, all the time, using the same kind of technology attackers use today. The result is a security team that walks into every audit and due diligence process with clear evidence and no surprises, and that also uses this approach as a calling card with partners and auditors.

"The tool itself, or the tech capabilities, are great. You're pioneers in this AI world, in the new developments."

No previous success case
No next success case
Let’s Talk About Your Industry

See what Strike could do for your business

We’ve helped companies in fintech, healthcare, insurance, and beyond build stronger security stacks. Let’s explore how our offensive approach can work for you.

Manufacturing

Energy

Telecom

Technology

Finance

Healthcare