Fru meets its NIS2 penetration testing requirement in a single day

Headquartered in Warsaw, FRU.PL operates one of Poland’s flight search engines, comparing fares across airlines and travel agents alongside hotel, car rental and travel insurance search.

By Petru Kovaci NIS2 deadline

As an organisation in scope for the NIS2 Directive, Fru treated the requirements as an opportunity to formalise what the team was already doing. One of them stood out for its timeline: an independent penetration test, with documented results and follow-up, that could be presented as evidence of ongoing security testing.

With a tight compliance deadline, Fru needed a partner who could move at their pace without giving up rigour.

A full test, scoped and delivered in a day

Scope was agreed and testing began the same day. Intrudify mapped the external attack surface and the authenticated application flows, then ran a full penetration test covering authentication, authorisation, input handling, session management and business logic.

Every result was validated before it reached the report, and documented with reproduction steps, impact and a recommended fix. The final document included an executive summary written for auditors and non-technical stakeholders.

Evidence that closes rather than opens questions

Fru's team completed the follow-up work over the following days. Intrudify re-tested it and issued a closure confirmation for the compliance file, so the evidence trail ran from finding to fix to independent verification without a gap in the middle.

The report, remediation summary and closure confirmation were accepted as evidence for the NIS2 security testing requirement without follow-up questions.

The pentest was the part of NIS2 I was working on. We kicked it off in the morning and had the report by the afternoon.

Peter Stoica, CTO, Fru

The outcome

With independent testing and a documented vulnerability-handling process in place, Fru meets the directive’s expectations for security testing and vulnerability management, and has a repeatable process for the next cycle rather than a one-off exercise.

Join the Future of
AI-Driven Pentesting