Digital Trust Advisory (DTA)
Client: SFIL Finance PLC. (Demonstration Assessment Report)
Report Type: Cyber Threat Intelligence & Risk Analysis
Assessment Method: Web Tools
Prepared By: Digital Trust Advisory (DTA)
Classification: Internal Demonstration Report
Assessment Date: August 2026
Executive Summary
Digital Trust Advisory (DTA) conducted a Cyber Threat Intelligence (CTI) assessment using threat landscape analysis, cybersecurity risk management principles, cyber hygiene frameworks, and website vulnerability assessment findings. The objective was to identify potential threats, vulnerabilities, and business risks facing the organization and provide actionable recommendations for risk mitigation. The analysis incorporates concepts from MIS532 Cybersecurity and Blockchain Technology, including ransomware, phishing, social engineering, Business Email Compromise (BEC), human vulnerabilities, supply-chain threats, incident response, and AI-driven attacks.
The website security assessment identified an overall High Risk rating, with one High severity finding, one Medium severity finding, multiple Low severity vulnerabilities, and several security misconfiguration.
Threat Exposure Summary
| Threat Category | Likelihood | Impact | Risk Rating |
| Ransomware | High | High | 🔴 Critical |
| Business Email Compromise | High | High | 🔴 Critical |
| AI-Powered Phishing | High | High | 🔴 Critical |
| Website Exploitation | High | High | 🔴 Critical |
| Supply Chain Compromise | Medium | High | 🟠 High |
| Insider Threat | Medium | Medium | 🟠 Medium |
| DDoS Attack | Medium | Medium | 🟡 Medium |
Organization Profile
Business Information
| Component | Description |
| Sector | Financial Services & Investment |
| Organization Size | Medium Enterprise |
| Location | Bangladesh |
| Crown Jewels | Customer Information, Investment Records, Financial Data, Employee Information, Business Systems, Website Platform |
Threat Landscape Overview
Modern cyber criminals increasingly target organizations through a combination of technical exploitation and social engineering. According to current threat intelligence trends, attackers frequently exploit outdated software, weak security configurations, human vulnerabilities, and third-party technologies to gain unauthorized access. The MIS532 course highlights that cybersecurity should be considered a business issue involving people, processes, and technology rather than technology alone.
Current Threat Actors
Financial Cybercrime Groups
Objectives:
- Data theft
- Financial fraud
- Ransom demands
Ransomware Operators
Objectives:
- Encryption of critical data
- Business disruption
- Extortion payments
AI-Assisted Threat Actors
Objectives:
- Automated phishing
- Deepfake fraud
- Credential theft
Technical Security Findings
Finding 1: Vulnerable PHP Version
Observation
The website is operating on PHP 8.2.30, which contains several publicly documented vulnerabilities, including vulnerabilities capable of enabling remote code execution, SQL injection, and cross-site scripting (XSS). The highest identified CVE has a CVSS severity score of 9.5 (Critical).
Business Impact
Potential consequences include:
- Unauthorized system access
- Website compromise
- Customer data exposure
- Business disruption
Risk Rating
🔴 HIGH
Recommendation
- Upgrade PHP to the latest secure version immediately.
- Establish automated patch management procedures.
Finding 2: Outdated jQuery Library
Observation
The scan detected jQuery 1.11.3, which contains multiple known vulnerabilities associated with Cross-Site Scripting (XSS) and Prototype Pollution attacks.
Risk Rating
🟠 HIGH
Recommendation
- Upgrade jQuery to the latest supported version.
- Review third-party plugins and dependencies.
Finding 3: Security Header Misconfiguration
Observation
Multiple critical security headers were missing or improperly configured:
- Strict-Transport-Security (HSTS)
- Referrer-Policy
- X-Content-Type-Options
- Content-Security-Policy weaknesses
These findings align with OWASP Security Misconfiguration risks.
Business Risk
Missing security headers increase susceptibility to:
- Cross-Site Scripting (XSS)
- Clickjacking
- Information leakage
- Session hijacking
Risk Rating
🟠 HIGH
Human-Centric Threat Intelligence
Threat 1: Business Email Compromise (BEC)
BEC remains one of the most significant financial threats facing businesses. The course materials emphasize that BEC attacks often bypass traditional email security controls because they contain no malware and rely on manipulation of human trust.
Risk Level
🔴 CRITICAL
Threat 2: Phishing & Social Engineering
Phishing attacks remain a primary entry point for ransomware and credential theft. Cybercriminals exploit trust, curiosity, urgency, and fear to manipulate employees into taking unsafe actions.
Risk Level
🔴 CRITICAL
AI-Driven Cyber Threat Assessment
The rise of Artificial Intelligence has significantly transformed the threat landscape. AI allows attackers to generate highly convincing phishing campaigns, create executive deepfake scams, and automate reconnaissance activities. The MIS532 course identifies AI-driven phishing and deepfake fraud as emerging high-priority threats.
Risk Level
🔴 CRITICAL
Organizational Risk Analysis
Business Impact Assessment
Financial Impact
Potential consequences:
- Fraudulent transactions
- Incident recovery costs
- Legal penalties
- Lost revenue
Operational Impact
Potential consequences:
- Website downtime
- Service disruption
- Business continuity failures
Reputational Impact
Potential consequences:
- Loss of customer confidence
- Brand erosion
- Reduced stakeholder trust
Risk Matrix
| Threat | Likelihood | Impact | Rating |
| Vulnerable PHP Components | High | High | Critical |
| Outdated jQuery Libraries | High | Medium | High |
| Ransomware | High | High | Critical |
| Business Email Compromise | High | High | Critical |
| AI-Driven Phishing | High | High | Critical |
| Supply Chain Threats | Medium | High | High |
| Insider Threats | Medium | Medium | Medium |
Overall Organizational Risk
🔴 HIGH RISK
The organization exhibits multiple technology and process-related vulnerabilities that could be leveraged by attackers to affect confidentiality, integrity, and availability, consistent with the CIA security model discussed in the MIS532 course.
Strategic Recommendations
Immediate Actions (0-30 Days)
✅ Upgrade PHP platform
✅ Upgrade jQuery libraries
✅ Implement security headers
✅ Enable Multi-Factor Authentication (MFA)
✅ Conduct phishing awareness training
✅ Review website configurations
Medium-Term Actions (1-3 Months)
✅ Implement Security Information and Event Management (SIEM)
✅ Conduct vulnerability assessments quarterly
✅ Establish incident response procedures
✅ Review third-party and supply-chain risks
✅ Harden website configurations
Long-Term Actions (3-12 Months)
✅ Establish SETA (Security Education, Training & Awareness) program
✅ Conduct phishing simulations
✅ Develop Zero Trust architecture
✅ Implement Threat Intelligence Monitoring
✅ Conduct annual penetration testing
DTA Executive Conclusion
The cybersecurity threat landscape continues to evolve, with ransomware, phishing, Business Email Compromise, AI-driven attacks, and vulnerable web technologies representing the greatest risks to modern organizations. The website assessment revealed exploitable software versions, security misconfiguration, and inadequate hardening controls that could increase exposure to cyber threats.
Digital Trust Advisory recommends immediate remediation of identified vulnerabilities, adoption of a continuous security awareness program, implementation of modern security controls, and establishment of a proactive threat intelligence capability. Organizations that combine secure technology, strong governance, employee awareness, and continuous monitoring are significantly better positioned to defend against emerging cyber threats and maintain digital trust.
DTA Security Posture Summary
🛡️ Current Security Maturity: Moderate
⚠️ Threat Exposure Level: High
🎯 Priority Action: Patch Vulnerable Systems + Employee Awareness + Security Hardening
Digital Trust Advisory (DTA)
Strengthening Security, Ensuring Trust, Enabling Growth
Download report:
PentestTools-WebsiteScanner-Report