Protecting modern on-site digital experiences

Penetration testing for Friendlyway’s cloud-driven kiosk and visitor management ecosystem

Friendlyway

The requirements

Friendlyway’s digital kiosks act as a physical touchpoint for visitors, contractors, and employees – capturing sensitive user data and triggering processes such as check-in, access verification, communication updates, and emergency mustering.

Because these endpoints operate in diverse environments and integrate deeply with corporate systems, Friendlyway’s customers expect robust security controls and evidence of ongoing risk management. To maintain these standards, Friendlyway required an annual penetration test that:

  • evaluates both kiosk hardware and software
  • examines backend infrastructure and cloud services
  • identifies vulnerabilities in authentication, data handling, and API interactions
  • supports compliance with stringent client security requirements across multiple industries

IDS Group was engaged to deliver a comprehensive, security-driven assessment tailored to the realities of modern, connected on-site environments.

The project at-a-glance

 

  • Recurring penetration testing to secure Friendlyway’s integrated kiosk hardware and cloud-based visitor management ecosystem.
  • Specialists conducted end-to-end analysis to neutralize attack paths across both physical endpoints and backend cloud infrastructure.
  • The team tested authentication and API interactions to ensure the total integrity of sensitive visitor and employee data.
  • We fortified security controls for critical workflows including access verification, emergency mustering, and workforce management.
  • Remediation guidance allowed Friendlyway to maintain continuous compliance with stringent global enterprise security standards.

Our solution

IDS Group designed a targeted penetration testing approach aligned with the unique challenges of physical-to-digital systems:

End-to-end ecosystem analysis

We mapped Friendlyway’s kiosk architecture, cloud workflows, and integrated applications, identifying critical assets and potential attack paths across both hardware interfaces and cloud-based services.

Application and infrastructure penetration testing

Simulating real-world cyber threats, IDS Group tested the kiosk software, administrative dashboards, authentication processes, API integrations, and backend infrastructure to surface vulnerabilities that could impact data integrity or system reliability.

Compliance-aligned vulnerability management

The testing framework was shaped around the security expectations of Friendlyway’s enterprise customers – ensuring alignment with industry-standard controls for access, data protection, and system resilience.

Detailed reporting and ongoing advisory

Our findings were delivered with clear remediation steps, risk prioritisation, and technical guidance. Follow-up support ensured Friendlyway could implement fixes and sustain a strong security posture throughout the year.

The results

Through IDS Group’s annual penetration testing programme, Friendlyway strengthened the security of its cloud platform and self-service kiosks, ensuring that its solutions continue to meet the high expectations of enterprise and industrial clients.

Targeted testing significantly reduced high-risk vulnerabilities across kiosk software, backend systems, and integrated workflows, fortifying data protection and operational stability. Enhanced security controls reaffirmed Friendlyway’s commitment to safe, reliable on-site experiences – reinforcing trust with customers who depend on secure visitor registration, access control, workforce management, and communication systems.

With ongoing support from IDS Group, Friendlyway remains aligned with evolving client security requirements and maintains a continuous state of readiness across its global deployments.

Risk reduction
Significant reduction in high-risk vulnerabilities across kiosk and cloud systems
Data protection
Strengthened data protection controls for visitor, employee, and contractor workflows
Compliance
Continuous compliance with evolving enterprise security expectations
Confidence
Increased client confidence in Friendlyway’s secure and scalable platform

IDS Group’s annual penetration testing was essential to meeting the security requirements of our clients. Their thorough approach and actionable insights have given us and our clients peace of mind.

Friendlyway
Anton Dechko
CEO, Friendlyway

Let's talk about your security strategy

Complete the simple form below and a member of the team will be in touch

This field is for validation purposes and should be left unchanged.
Name(Required)
Please let us know what's on your mind. Have a question for us? Ask away.

Related case studies

Technical due diligence to qualify investment decisions

Technical due diligence to qualify investment decisions

Software Consultancy, Software Security, Technical Due Diligence