Entersoft, a leading APAC end-to-end cybersecurity solutions provider, is proud to announce its role in supporting Pier Two’s achievement as the first NORS (Node Operator Risk Standard) accredited validator globally. Entersoft conducted a comprehensive Web Application & Web Services (API) Vulnerability Assessment Penetration Testing for Pier Two, a crucial step in preparing them for the rigorous NORS certification process and reinforcing their position as a leader in institutional non-custodial staking.
NORS is a peer-reviewed framework developed to benchmark operational practices, security and performance in staking. Pier Two, an Australian-based global institutional staking provider, has now set a significant precedent for node operators worldwide. Meeting this international standard is important in building trust as well as enabling the wider adoption of ETH staking, particularly among regulated entities such as ETFs and asset managers.
Entersoft’s engagement with Pier Two highlights the importance of robust cybersecurity in the fast-evolving digital asset environment. Its team of certified white-hat hackers conducted in-depth web application and web service penetration testing, simulating real-world attack scenarios to identify and mitigate potential weaknesses across Pier Two’s infrastructure. This approach ensured Pier Two’s systems were not only resilient but also met the stringent security controls mandated by the NORS framework.
“Our core focus at Pier Two is on building and maintaining enterprise-grade infrastructure, which is what underpins our institutional offerings,” said Jack Deeb, Co-Founder and COO of Pier Two. “Achieving NORS is a significant milestone that validates our security-first approach and our dedication to robust, secure, and performant infrastructure. We’re proud to be the first to achieve this global standard, alongside our existing ISO27001:2022, SOC 2 Type I, and SOC 2 Type II certifications. Entersoft’s expertise was instrumental in this process, ensuring our systems were thoroughly tested and hardened to meet the stringent NORS requirements.”
The NORS certification, along with Pier Two joining the Liquid Collective, acts as a filtering mechanism, ensuring that only the highest-quality node operators meet the bar for securing and strengthening Ethereum validator infrastructure. Entersoft’s contribution helped validate Pier Two’s adherence to standardised risk management practices. The assessment focused on Pier Two’s web application and API surfaces, following the CREST Testing Methodology and aligning with globally recognised standards such as the OWASP Top 10, WASC Threat Classification and the SANS Top 25, Entersoft’s offensive security team employed manual exploitation techniques with a business logic-oriented mindset, going beyond automated scans to uncover complex, contextual vulnerabilities that could impact the integrity of validator operations.
“It has been a great opportunity to work alongside another forward-thinking local business making serious moves on the global stage. At Entersoft, we are always excited to partner with emerging technology companies, especially in the digital assets, AI and fintech space, that take a proactive approach to security. Pier Two’s commitment to embedding security from day one gives them a strategic advantage and builds trust with stakeholders by demonstrating that security is not an afterthought, but a foundation. Achieving NORS is a major milestone and a true reflection of their security-first mindset. We are proud to have supported them in this effort and look forward to seeing where they go from here”, said Paul Kang, Entersoft Co-Founder and Director.
This collaboration between two APAC-based industry leaders signals a strong commitment to elevating the standards of security and reliability within the digital asset space. As demand for institutional-grade staking solutions continues to grow, the need for verifiable and stress-tested security practices becomes non-negotiable.
Entersoft is a leading provider of end-to-end cybersecurity solutions, with deep expertise in Application Security, Penetration Testing, Smart Contract Audits, Cloud Security, Threat Monitoring and Cyber Education. As an ISO 27001-certified and CREST-accredited organisation, Entersoft supports companies on the global stage, from early-stage startups to Tier 1 financial institutions. With a strong focus on emerging technologies, we take an offensive, ethical hacker mindset to uncover high-impact vulnerabilities before attackers do. Backed by over a decade of experience, Entersoft is trusted by organisations seeking to establish and maintain a robust security foundation.
Pier Two runs Institutional staking services for global clients, with multi-zonal 24/7 operations, high-performance hybrid cloud and bare metal infrastructure. With ~$4B in assets staked and delegated, Pier Two serves as a strategic partner in achieving sustainable rewards and growth while helping protocol security. Holding ISO27001:2022, SOC 2 Type I and SOC 2 Type II certifications, Pier Two is the first NORS Certified Node Operator worldwide, a specialised blockchain security standard for professional operators.
Manisha Kaur
(Marketing and Communications)
[email protected]