Vola turns penetration test results into a prioritised backlog

Vola is one of Romania’s largest online travel agencies, handling search, payments, ticketing and customer support at scale.

By Petru Kovaci Clear priorities

The engineering team was already committed to regular security testing. What they wanted was more structure around it: a clear path from result to action, priorities reflecting actual business risk rather than a raw severity score, and reporting that engineers and leadership could both read without translation.

In short, they wanted penetration testing to work like the rest of their engineering process - defined stages, clear ownership, measurable progress.

From a list of results to an ordered backlog

A short scoping session before each test agrees the surface, the focus areas and the business-critical flows. Results are then delivered with a business-impact rating, a suggested owner and a fix recommendation, grouped by affected system.

Rating on technical severity combined with business context produces an ordered backlog rather than a flat list, so engineering leads assign work in minutes instead of debating severity.

Closure that someone else confirms

Intrudify re-tests each change, confirms closure, and produces a one-page posture summary for leadership showing progress over time rather than a snapshot.

With plain-language impact, exact reproduction steps and a specific recommendation on every result, a developer can pick an item up without a security background and move from report to pull request directly.

Our developers got a clear list of what to fix first. I got a one-pager for the board. That's all I ever wanted from a pentest.

Matei Psatta, COO, Vola

The outcome

Penetration testing at Vola now has defined stages, inputs and outputs, and everyone involved knows what happens next and who is responsible. Reporting a trend rather than a snapshot has also made security work easier to plan and to justify.

Join the Future of
AI-Driven Pentesting