Not Just Banks: Why iGaming, Crypto Platforms and Shipping Companies in Cyprus Now Need Penetration Testing Too

Ask most Cyprus businesses which sectors get real cybersecurity scrutiny from regulators, and the answer is almost always “banks and investment firms.” That stopped being accurate a while ago. Between MiCA, the National Betting Authority’s licensing regime, IMO shipping cyber requirements, and the Central Bank of Cyprus’s oversight of electronic money institutions, several sectors that used to sit outside financial-grade regulation are now squarely inside it, each with its own testing expectations that a generic vulnerability scan does not come close to covering.

This guide covers what each of these sectors actually needs tested, why the risk profile is different from a standard business website, and what “in scope” really means if you operate a crypto platform, an iGaming site, a shipping company, or an EMI out of Cyprus.

Crypto platforms: MiCA made Cyprus a CASP hub

The Markets in Crypto-Assets Regulation (MiCA) has been fully applicable across the EU since 30 December 2024. Cyprus, already home to a large Cyprus Investment Firm (CIF) and forex sector, has become one of the more active jurisdictions in the EU for Crypto-Asset Service Provider (CASP) licensing through CySEC, partly because firms already familiar with CySEC’s supervisory style see a shorter learning curve than in less financially developed jurisdictions.

A CASP inherits much of the ICT risk scrutiny CySEC already applies to CIFs, but layered onto custody and key management, an attack surface a standard financial firm simply does not have. Under MiCA, a CASP has to demonstrate operational resilience and sound ICT risk management as part of both initial licensing and ongoing supervision, and increasingly that overlaps directly with DORA for any CASP that also meets DORA’s financial-entity definition.

What actually needs testing on a crypto platform

  • Hot and cold wallet separation, and the technical controls that enforce it.
  • Private key management practices, including how signing keys are generated, stored, and rotated.
  • The trading or exchange platform itself: order matching, account balances, and withdrawal logic.
  • On/off-ramp integrations and any third-party liquidity providers, since these are common weak points in an otherwise well-secured platform.
  • KYC/AML data handling, given the sensitivity of the identity documents a CASP collects.

A generic web check tests the login page and the marketing site around it. It does not test whether your custody architecture actually enforces the separation it claims to. Our penetration testing service is used by several Cyprus-based crypto platforms specifically because it goes past the login flow and tests the custody and trading layer directly.

iGaming and online casinos: licensed, monetised, and rarely tested to the standard the risk deserves

Cyprus’s online gaming and betting operators are licensed and supervised by the National Betting Authority (NBA). These platforms combine exactly what attackers look for in one place: real-money transactions, sensitive KYC data, and session and balance logic that directly controls payouts. A vulnerability in bet settlement, wallet balance calculation, or bonus abuse logic is not a theoretical risk on an iGaming platform, it converts into direct financial loss the moment the wrong person finds it, and that loss is frequently invisible until a reconciliation report flags it weeks later.

Despite that, iGaming platforms are very often tested with the same generic checklist used for a marketing website: OWASP Top 10 coverage on the login and registration forms, and not much else. Game logic, round-result integrity where it is in scope, session handling under concurrent play, and payment or wallet flows all need testing that understands abuse patterns specific to real-money platforms. Our web application penetration testing engagements are scoped around exactly that kind of business logic testing, on top of standard technical coverage, precisely because a clean OWASP report tells you very little about whether your payout logic can be manipulated.

Shipping and shipmanagement: IMO 2021 made cyber risk a safety requirement, not just an IT one

Cyprus runs one of the largest ship registries and shipmanagement hubs in the world, and since 1 January 2021, IMO Resolution MSC.428(98) has required cyber risk to be addressed within a vessel’s existing Safety Management System under the ISM Code. This is a meaningful shift in how the requirement gets enforced: cyber risk on a vessel or in a fleet management system is no longer just an IT department’s problem, it is a documented safety-management compliance item that flag states and port state control inspectors can actually check during an audit.

Shipmanagement companies typically run a mix of shore-side corporate IT, fleet and crew management platforms, and increasingly networked systems on the vessels themselves, several distinct attack surfaces that rarely get assessed together in a single engagement. Our website penetration testing services cover the shore-side and fleet management platforms with that ISM Code documentation requirement in mind, so what you get back is evidence you can actually present to an auditor or inspector, not a generic scan report with no bearing on the ISM Code.

Electronic Money Institutions: a different regulator, a different risk profile

Electronic Money Institutions (EMIs) in Cyprus are licensed and supervised by the Central Bank of Cyprus, a completely different regulator from CySEC, with its own expectations around payment platform security and, critically, the technical separation between safeguarded client funds and the institution’s own operational accounts. For an EMI, account takeover and payment fraud through weak session or API controls tend to cause far more real financial damage than infrastructure-level attacks, which is exactly the kind of risk a properly scoped penetration test is designed to surface before a regulator, or an attacker, finds it first.

What matters most in an EMI penetration test

  • Session and authentication controls, since account takeover is the highest-impact realistic scenario for most EMIs.
  • Payment API integrations and how thoroughly they validate incoming requests.
  • The technical separation between safeguarded client funds and operational accounts.
  • Open banking or third-party integrations, where present, given how directly these expand an EMI’s attack surface.

Frequently asked questions

Does MiCA require penetration testing?

MiCA does not name penetration testing by that exact term, but its operational resilience and ICT risk management expectations, closely aligned with what CySEC already applies to CIFs and increasingly with DORA, are in practice evidenced through security testing during licensing and ongoing supervision.

Who regulates iGaming companies in Cyprus?

Online gaming and betting operators in Cyprus are licensed and supervised by the National Betting Authority (NBA), which is a separate regulator from CySEC and the Central Bank of Cyprus.

Is online gambling legal in Cyprus?

Yes, online betting and gaming are legal in Cyprus when the operator holds a licence from the National Betting Authority. Operating without that licence is not.

What is an Electronic Money Institution?

An EMI is a company licensed to issue electronic money and provide payment services, without being a full bank. In Cyprus, EMIs are licensed and supervised directly by the Central Bank of Cyprus rather than CySEC.

Do IMO cyber security regulations apply to shore-side offices, or only to vessels?

IMO Resolution MSC.428(98) is framed around a vessel’s Safety Management System, but in practice a ship’s cyber risk cannot be assessed in isolation from the shore-side systems, fleet management platforms, and crewing systems that connect to it, so a serious assessment has to cover both.

The common thread

None of these sectors are edge cases anymore. Crypto platforms, iGaming operators, shipmanagement companies, and EMIs are all licensed, supervised, and increasingly expected to produce real technical evidence, not just policy documents, when a regulator or an auditor asks for it. The testing has to match the sector’s actual risk profile, not a template built for a generic corporate website. If your business sits in one of these categories and has not had a test scoped to what actually matters for it, that is the gap worth closing first, before it closes itself the hard way.