Vulnerability assessment and penetration testing, explained properly
Independent guides to VAPT in India — what it costs, how it is scoped, who is qualified to run one, and how to read the report you get back.
25 guides, written and maintained by Security Brigade.
Buying one
What it costs, who is qualified to do it, and what you receive at the end.
Writing a VAPT RFP That Gets Comparable Quotes
Most VAPT tenders return responses that cannot be compared. Four ways an RFP causes that, and what to specify instead so three proposals answer t…
The VAPT Certificate: What It Evidences
There is no standardised VAPT certificate and no authority that issues one. What the document actually is, what it proves, what it does not, and…
What a Scanner Finds, and What It Cannot
Automated tooling is genuinely good at a defined set of problems and structurally incapable of another set. Both lists are specific, and knowing…
What a VAPT Actually Is, and What You Receive
Somebody has asked you for a VAPT. What the two halves are, what happens during one, what you get at the end, and the four things it is not.
Comparing Two CERT-In Empanelled Vendors
Once both firms are empanelled, the empanelment stops helping. What the public register already tells you about each, and the three differences t…
How to Check an Auditor Is Really CERT-In Empanelled
Empanelment is claimed more often than it is checked. The register is a public PDF, it takes two minutes to search, and it carries more about eac…
How the testing works
What a tester actually does, by asset class, and what tooling does and does not reach.
The Phases of a Penetration Test
Every credible methodology describes the same arc, under different names. What happens in each phase, how long each takes, and how to tell whethe…
External and Internal Network Penetration Testing
External and internal network tests answer different questions. What each one looks for, the findings that recur in almost every internal engagem…
Mobile Application Security Testing, Explained
A mobile test has three parts — the binary, the device, and the API behind them. Most of the serious risk is in the third, and the reason is that…
API Penetration Testing, Explained
APIs fail differently from the applications in front of them. What a tester looks for, why object-level authorisation is the dominant finding, an…
Web Application Penetration Testing, Explained
What a tester actually does to a web application over two weeks, what they need from you before they start, and which classes of flaw only turn u…
Scope and preparation
What to have ready, what can and cannot be tested, and how the boundary gets drawn.
How a VAPT Scope Gets Sized
Testers do not count lines of code. They count functions, roles and entry points. What actually drives the number of days, and how to give a vend…
What Can and Cannot Be Tested, and Why
Some things are excluded because they would break something. Others because they are not yours to authorise. Cloud, SaaS, third parties and the p…
Black, Grey and White Box Testing
The three terms describe how much you tell the tester, not how much access they get. Which one to choose, and why the realism argument for black…
Preparing for Your First VAPT
Most of what makes a penetration test go badly is decided before it starts. Eight things to have ready — scope, environment, accounts, contacts,…
What Moves the Price of a Penetration Test
Quotes for the same system arrive at wildly different numbers, and the reason is almost never margin. Testing is sold in tester-days, and the thi…
Reading the report
Severity, CVSS and the vector string — and how to tell written work from tool output.
Retest, Closure and the Evidence That Ends an Engagement
A report describes a moment. What turns it into a closed engagement is the retest — and the three things to agree about it before the first test…
What Separates a Written Finding From a Scanner Alert
The same underlying flaw, as a scanner reports it and as a tester writes it up. Six things present in one and absent from the other, using a find…
How to Read a Security Finding
Severity, CVSS and the vector string, and why a 9.8 on one system is not a 9.8 on another. How to convert a report ranking into your own.
What Is Actually Inside a VAPT Report
A penetration test ends in a document, and most people receive one before they have any way of judging it. Here is what each section is for, and…
After the test
Sequencing the fixes, proving closure, and deciding when to test again.
What Changes by Your Third VAPT
The first report is mostly hygiene. By the third, the findings that remain are the ones that required someone to understand your business. What t…
How Often Should You Run a VAPT
Annual is the default answer and it is a floor, not a plan. What actually drives cadence: what changed, what you are subject to, and what the las…
Prioritising Findings for Remediation
Sixty findings and two engineers. How to sequence the work so the risk comes down fastest, and why fixing by severity order is rarely the right p…
Where the requirement comes from
Which regulators name you — and where the obligation arrives from when none do.
VAPT When No Regulator Requires It
Unregulated companies still end up buying penetration tests. The requirement arrives through customers, contracts, insurers and investors — and e…
Which Indian Regulators Require Security Testing
A map rather than a manual: which regulator binds you, what instrument sets the requirement, and where to read the detail that applies to your en…
Getting a test scoped
Security Brigade is CERT-In empanelled and has been running these engagements since 2006. If you want the scope and the price worked out against your actual estate rather than a template, start there.
Talk to Security Brigade