Cybersecurity Insights & Guides
Expert insights on cybersecurity, vulnerability management, and digital defence strategies.
VAPT When No Regulator Requires It
Unregulated companies still end up buying penetration tests. The requirement arrives through customers, contracts, insurers and investors — and each wants something slightly different.
Which Indian Regulators Require Security Testing
A map rather than a manual: which regulator binds you, what instrument sets the requirement, and where to read the detail that applies to your entity type.
Writing a VAPT RFP That Gets Comparable Quotes
Most VAPT tenders return responses that cannot be compared. Four ways an RFP causes that, and what to specify instead so three proposals answer the same question.
The VAPT Certificate: What It Evidences
There is no standardised VAPT certificate and no authority that issues one. What the document actually is, what it proves, what it does not, and who accepts it.
What Changes by Your Third VAPT
The first report is mostly hygiene. By the third, the findings that remain are the ones that required someone to understand your business. What that arc looks like, and where it goes wrong.
How Often Should You Run a VAPT
Annual is the default answer and it is a floor, not a plan. What actually drives cadence: what changed, what you are subject to, and what the last report found.
Prioritising Findings for Remediation
Sixty findings and two engineers. How to sequence the work so the risk comes down fastest, and why fixing by severity order is rarely the right plan.
How a VAPT Scope Gets Sized
Testers do not count lines of code. They count functions, roles and entry points. What actually drives the number of days, and how to give a vendor enough to quote accurately.
What Can and Cannot Be Tested, and Why
Some things are excluded because they would break something. Others because they are not yours to authorise. Cloud, SaaS, third parties and the paperwork that separates a test from an offence.
Black, Grey and White Box Testing
The three terms describe how much you tell the tester, not how much access they get. Which one to choose, and why the realism argument for black box is usually the wrong way round.
Retest, Closure and the Evidence That Ends an Engagement
A report describes a moment. What turns it into a closed engagement is the retest — and the three things to agree about it before the first test starts.
What Separates a Written Finding From a Scanner Alert
The same underlying flaw, as a scanner reports it and as a tester writes it up. Six things present in one and absent from the other, using a finding from a published sample report.
How to Read a Security Finding
Severity, CVSS and the vector string, and why a 9.8 on one system is not a 9.8 on another. How to convert a report ranking into your own.
What a Scanner Finds, and What It Cannot
Automated tooling is genuinely good at a defined set of problems and structurally incapable of another set. Both lists are specific, and knowing which is which is how you tell a penetration test from an expensive scan.
The Phases of a Penetration Test
Every credible methodology describes the same arc, under different names. What happens in each phase, how long each takes, and how to tell whether a proposal has a real methodology behind it or a diagram.
External and Internal Network Penetration Testing
External and internal network tests answer different questions. What each one looks for, the findings that recur in almost every internal engagement, and why the first output is usually a corrected asset inventory.
Mobile Application Security Testing, Explained
A mobile test has three parts — the binary, the device, and the API behind them. Most of the serious risk is in the third, and the reason is that the app itself is running on hardware the attacker owns.
API Penetration Testing, Explained
APIs fail differently from the applications in front of them. What a tester looks for, why object-level authorisation is the dominant finding, and why the endpoints nobody documented are the ones that hurt.
Web Application Penetration Testing, Explained
What a tester actually does to a web application over two weeks, what they need from you before they start, and which classes of flaw only turn up when a person is holding the keyboard.
What a VAPT Actually Is, and What You Receive
Somebody has asked you for a VAPT. What the two halves are, what happens during one, what you get at the end, and the four things it is not.
Comparing Two CERT-In Empanelled Vendors
Once both firms are empanelled, the empanelment stops helping. What the public register already tells you about each, and the three differences that survive the bar.
Preparing for Your First VAPT
Most of what makes a penetration test go badly is decided before it starts. Eight things to have ready — scope, environment, accounts, contacts, defenders, calendar, paperwork, retest.
What Moves the Price of a Penetration Test
Quotes for the same system arrive at wildly different numbers, and the reason is almost never margin. Testing is sold in tester-days, and the things that move the day count are knowable before you ask anyone for a price.
How to Check an Auditor Is Really CERT-In Empanelled
Empanelment is claimed more often than it is checked. The register is a public PDF, it takes two minutes to search, and it carries more about each firm than the claim itself — including how many audits they say they ran last year.
What Is Actually Inside a VAPT Report
A penetration test ends in a document, and most people receive one before they have any way of judging it. Here is what each section is for, and the specific thing to check in each — from the executive summary to the compliance mapping appendix.
Have a question this did not answer?
Our team answers regulatory and testing questions directly — no discovery call required to get a straight answer.
Talk to our team