Information system security is a crucial aspect in supporting digital-based regional financial services. This study offers novelty by implementing penetration testing on the financial service system of Pati Regency, which previously had not been comprehensively evaluated. The black-box testing method is used to simulate external attacks, while the Penetration Testing Execution Standard (PTES) is selected because it provides structured and replicable work stages, thereby improving the accuracy of vulnerability identification. The testing results reveal serious vulnerabilities, such as exposure of the phpinfo() page and the use of default credentials in the login process, which are classified as high risk based on CVSS 3.1. These vulnerabilities had not been detected by the system administrators prior to testing. The implementation of security recommendations, including brute-force protection, removal of sensitive pages, and strengthened authentication mechanisms, is able to significantly reduce the level of risk. The main contribution of this research lies in providing a structured and applicable security evaluation model for local governments to enhance the resilience of digital financial services against cyberattacks.
Copyrights © 2026