Case Study

Achmea

The official Achmea logo.

Achmea is one of the largest financial services providers in the Netherlands, delivering insurance and related services to millions of customers through well-known brands including Centraal Beheer, Interpolis, Zilveren Kruis, FBTO and Avero Achmea. With roots stretching back to 1811, Achmea operates as a cooperative insurer, placing the security and privacy of its customers at the heart of everything it does.

Challenge

As an insurer, Achmea's customer-facing websites handle large volumes of highly sensitive personal, health and financial data across quote, application and claims journeys. Like most modern web estates, those journeys rely on a range of third-party JavaScript, from analytics and tag managers to chat and personalisation tools, and every one of those scripts executes directly in the customer's browser. This client-side attack surface is exactly what attackers target with "Magecart" and "formjacking" techniques, injecting malicious code or quietly exfiltrating data without ever touching Achmea's own servers. The challenge was to gain clear, real-time visibility of every script running in customers' browsers and every destination data was being sent to, so that any unauthorised change could be detected immediately, all while supporting Achmea's obligations under GDPR and, on payment flows, PCI DSS v4.0.

Solution

Achmea deployed Report URI to monitor and manage the scripts executing across its customer-facing properties. By collecting and analysing Content Security Policy violation reports, Achmea's security team gains a live inventory of every JavaScript dependency and every location that data is sent to, with alerts the moment anything changes. Because the monitoring leverages the browser-native Content Security Policy, there is no agent to deploy and analysis happens in real time as customers browse, with no gaps around authentication, geo-sensitive content or attackers serving safe content to scanners. CSP reporting also lets Achmea safely build and test policies before enforcing them, turning visibility into active protection.

Protecting our customers' data is fundamental to who we are as a cooperative insurer. Report URI gives our team real-time visibility of everything running in our customers' browsers and alerts us to changes immediately, helping us detect and respond to client-side threats without impacting the customer experience.

- Achmea

Outcome

By integrating Report URI into its security workflow, Achmea gained real-time visibility of client-side script activity across its customer-facing estate. The team can now rapidly detect unauthorised changes to scripts and data flows, reducing the risk of data compromise from attacks like Magecart and strengthening the protection of the sensitive customer information Achmea is trusted to hold. This enhanced monitoring supports Achmea's compliance obligations while delivering actionable alerts with minimal noise, allowing the security team to focus on genuine threats and continue providing customers with secure digital services they can trust.

How we can help

Getting started with Report URI is easy, and we can quickly audit all of your existing JavaScript Dependencies and Data Exfiltration endpoints to see if they are all expected.

Once a baseline is established, our Script Watch and Data Watch features will monitor and alert you to any changes for you to investigate quickly.

In addition to this, we have a selection of features and tools detailed below that will help you get started with CSP and work through to enforcing a policy across your whole site, but please reach out to sales@report-uri.com if you need more information.

Get Started

Set up the same monitoring Achmea relies on.

One header. No code. Reports flowing within minutes.

30-day free trial  ·  One header  ·  No code  ·  Cancel anytime

Script Watch

Script Watch will monitor all JavaScript dependencies across your entire site and immediately notify you of any changes. A new JavaScript dependency could be the start of a Magecart attack.

Because Script Watch leverages the browser native Content Security Policy, there is no code or agent to deploy and running in the browser means we analyse your site in real-time as your users are browsing. We don't have the same limitations as external scanning services such as authentication or pay walls, geo-sensitive content or an attacker potentially serving safe content to the crawler.

Read More

Data Watch

Data Watch will monitor all of the locations that your webpages are sending data to. If your website starts sending data to a new location, it could be the start of a Magecart attack.

With Script Watch and Data Watch combined, you can monitor for clear indicators that your site has been compromised. Attackers will always want to inject their hostile JavaScript, and they'll always want to exfiltrate their stolen data.

Read More

The CSP Wizard

We often find that creating a CSP is the first difficult step that organisations face. Having a complete list of all resource dependencies across your entire site like images, scripts or styles, from both 1st-party and 3rd-party locations, is tough to achieve.

The CSP Wizard was created to solve this problem, and in seven days or less, it can give you a complete list of all resources used across your entire site.

With the list of all resources you use on your site, and our easy-to-use tool, creating a viable Content Security Policy is easier than ever with just a few clicks.

Documentation

The CSP Builder

All Content Security Policies will need to be tweaked at some point. New resources may be added to the site or old resources removed, and the policy needs to be updated to reflect those changes and kept up to date.

You can import your existing policy into the CSP Builder and use our fully featured tool to make any changes that you require right there in the UI. When you're done, hit Generate, and the CSP Builder will provide you with your new, updated policy.

CSP Builder

Content Security Policy

Script Watch and Data Watch will allow you to rapidly detect and respond to a Magecart attack and combined, that capability puts you ahead of the field. If you want to take it a step further, Content Security Policy can mitigate a Magecart attack and stop it from even happening.

Deploying an effective Content Security Policy can be difficult, but our CSP Reporting allows you to gather feedback and safely test a policy before deployment. Once deployed, an effective Content Security Policy will block a Magecart attack and stop the hostile JavaScript from even running.

Read More

Threat Intelligence

We subscribe to various feeds of Threat Intelligence data, along with managing our own internally generated feeds, to keep apprised of the latest threats that exist online.

Using this Threat Intelligence Data, we can better analyse the sources of JavaScript on your website and detect malicious activity sooner.

Read More