Whitepapers
Discover our insights into Nearsurance, DevOps, Software Modernization and more
Technology is evolving at such a high pace that as we are witnessing how the future becomes present, we also need to put efforts to keep up with it. This especially concerns industries like high tech, energy, automotive, logistics, industrial automation and manufacturing.
Browse through the whitepapers below to find the topics relevant to you and your business.
Topics
General
Nearshoring + Quality Assurance = Nearsurance
ICT Strypes’ unique Nearsurance model combines our expertise in IT implementations and software development with the benefits of nearshoring. We work with a fixed budget and our clients only pay for the work we deliver. Managing the budget and scaling up or scaling down the teams according to the workload is our responsibility. This allows our clients’ in-house teams to focus on their goals while we take full ownership of the outsourcing organization, execution, and solving the issue.
Mobility and transport software solutions
Up2 is a division within ICT Strypes, specializing in innovative solutions for the transport and mobility industry. These custom solutions are applicable in cases where out-of-the box solutions don’t fit. Thanks to the knowledge and expertise we have acquired in the field, we are in a position to develop sustainable, rational, and intelligent mobility solutions through using smart technologies
DevOps: The big brother of Agile
Regardless of whether you’ve been in the tech business for a while and need to reconsider your product development practices or you’ve just founded а tech start-up and want to do everything the right way – you’ve most likely heard of DevOps.
DevOps is a popular and fancy word nowadays, and it seems to be used without an understanding of what really stands behind it. The intent of this paper is to hopefully try and change that.
Smart applications: an integral part of business operations
If you are in an industry that is moving from traditional operating environments to the cloud, then Smart Applications can become an integral part of your business operations. This is especially true in the instances where it is difficult to determine where the application lifecycle ends.
In this white paper, you can read more about the teams that we bring onboard and their roles, as well as the technical stack, and a case study of how we have successfully applied our expertise.
The ICT Strypes approach to software development as a service (SDaaS)
At ICT Strypes, we use the SDaaS approach to help our clients with the overall project planning, execution, and delivery. We act as an external member of the client’s engineering team.
We developed an approach called Nearsurance. It brings the benefits of outsourcing software development services while ensuring easy communication and quality by having local team members present at the client’s site. The feedback we get from our clients about this model is that it builds a great work relationship with clear communication and quality assurance.
ICT Strypes Software Modernization: Get ready for the future
New systems are deployed daily, computer languages keep growing in numbers and complexity, products are becoming more multi-dimensional. Many businesses still struggle to catch up with these developments.
Old systems don’t have to be broken and non-functional to be modernized. But software modernization is not a quick fix either. It’s a continuous process that ensures old systems don’t put a strain on the business and that enhances the lifecycle of a product.
Cybersecurity resources
Whitepaper: Cybersecurity as a Service - Securing your systems with ICT Strypes in 2025
At ICT Strypes, we recognize the multifaceted nature of safeguarding your organization’s vital infrastructure, which is why we offer tailored cybersecurity services to address the ever-changing threatscape. Our two primary competencies, vulnerability management and penetration testing, form the bedrock of our approach. As we explore the intricacies of these services, we shed light on the critical components of modern enterprise cybersecurity, highlighting key risk points and the foundational importance of network security.
Join us as we navigate the complexities of cybersecurity in the digital age and discover how Strypes can fortify your defenses against emerging threats.
Chain of unrestricted render options: EJS RCE capabilities research
Our Solution Architect, Diyan Apostolov, explores the EJS library and its remote code execution (RCE) potential, uncovering vulnerabilities in versions prior to 3.1.9. Despite attempts to patch these vulnerabilities, a chain of unrestricted render options enabling RCE persists. By manipulating the client option and leveraging prototype pollution vulnerabilities, attackers can inject malicious payloads into EJS rendering, leading to RCE. The research includes a proof of concept and outlines steps for setting up a lab environment to demonstrate exploitation, while discussing ongoing challenges in securing EJS-rendered applications.
404: The Invisible Script with Visible Damage
A single overlooked line of code can open the door to major breaches. In this Cybersecurity in Practice story, our experts reveal how a subtle Cross-Site Scripting (XSS) flaw can turn everyday functionality into a serious security risk — and what steps teams can take to stay one move ahead of attackers.
Less is mighty - Cybersecurity Research
Our Alteryx security research (by Diyan Apostolov, Solution Architect) reveals a critical authentication bypass in Alteryx Server that can expose active session tokens and user identities — potentially allowing privilege escalation to administrator level — together with client-side issues in Alteryx Designer (reflected XSS and a Zip-Slip vulnerability) that enable local file access and weaponised package installs. The full technical report (PDF) explains the discovery, proof-of-concepts, timeline, and mitigation steps; vendors have since released patches — we strongly recommend immediate version checks and updates.