The primary objective of this project was to identify and mitigate security vulnerabilities within a custom-built academic portal. By implementing a defense-in-depth strategy, the assessment utilized multiple security testing methodologies to ensure a robust security posture. The evaluation revealed moderate security risks, primarily involving server misconfigurations and missing security headers.