Skip to main content

The engagement

What a VAPT engagement covers

A vulnerability assessment enumerates what is exposed. A penetration test establishes what somebody could do with it. Most Indian regulators ask for both, and most buyers are quoted for them together without being told where one stops.

This page sets out the engagement types, the effort each one takes, and what arrives at the end. The work is delivered by Security Brigade, CERT-In empanelled since 2008.

What can be tested, and what it takes

Effort is in tester-days. That is the unit an assessment is bought in and the unit to hold a proposal against, ours included. Elapsed time is shorter wherever more than one tester runs at once, so a calendar window and an effort figure are two different numbers and a quote should give you both.

Engagement What the band assumes Tester-days
Web application One application, authenticated, two to three roles, moderate distinct functionality 8 to 15
Mobile application One platform, plus its backing API. Both platforms is not double, because the backend is shared 8 to 14
External network Perimeter, up to roughly fifty distinct live hosts 5 to 10
Internal network One site or segment, assumed-breach starting position 8 to 15
API Documented, one authorisation model. Undocumented adds discovery 5 to 12
Cloud configuration review One account or subscription, against a recognised benchmark 5 to 10
Secure code review Targeted at security-relevant components, not the whole tree 8 to 20
Red team Objective-based, multi-vector, several weeks of elapsed time 25 to 60

Reporting sits inside these bands. A proposal that itemises it separately is being open about something usually buried.

What arrives at the end

  • A report where every finding is reproduced. The request, the response and the steps between them, so your engineers can see the issue for themselves.
  • Severity scored under CVSS v4.0. With the vector string printed beside it, so a score can be argued with instead of accepted.
  • Remediation written against your stack. The fix in the framework and language you are using, and where a fix is not available, what reduces the exposure meanwhile.
  • A retest inside the remediation window. Included in the effort above. A finding is closed when it has been retested, and the retest is the evidence an auditor asks for.

Before a finding reaches you

Every finding passes an L1, L2 and L3 review. That is an escalation model for the finding, not a grading of the tester: each level challenges the evidence, the severity and the wording, and a finding that survives all three is one we are prepared to defend to your engineers and to your auditor.

For the full methodology on any one engagement type, read the service pages on securitybrigade.com.

Start with the scope

Work out the effort first and bring the number to the conversation. It takes about two minutes and it runs in your browser.