Assessment or penetration test?
People use the words interchangeably and they are not the same thing. It is worth being clear, because buying the wrong one wastes money.
| Security assessment | Penetration test (VAPT) | |
|---|---|---|
| Question it answers | What do we have and where are we weak? | Can someone actually get in, and how far? |
| Approach | Review of design, configuration and exposure | Active testing that attempts exploitation |
| Best when | You have never done either, or inherited an undocumented network | A customer, auditor or insurer wants evidence |
| Output | A prioritised picture of your posture and a plan | A findings report suitable to send onward |
If somebody external has asked you for proof, you want VAPT. If you genuinely do not know what you have, start here - an assessment usually pays for itself by telling you which of the things you were about to buy you do not need.
What we look at
- What is reachable from the internet. Every service exposed at your perimeter, whether you know about it or not. This is where the surprises usually are.
- Firewall configuration and rule base. What the rules actually permit, as opposed to what everyone believes they permit. See firewall audit and rule review.
- Network structure. Whether the network is segmented at all, and what a single compromised machine could reach from where staff actually sit.
- Remote access. Who can get in from outside, using what, and whether anyone left has still got a way in.
- Servers and patching. What is running, what is out of support, and what has not been updated.
- Email authentication. Whether someone can send invoices that appear to come from your domain. See email security and DMARC.
- Backups. Whether they exist, whether they have ever been restored, and whether ransomware could reach them.
What you get
A written report ranking what we found by what actually matters to your business, not by a generic severity score. A call to walk through it in plain English. And a prioritised plan that separates what should be fixed this month from what can reasonably wait a year - including the things we think you can safely ignore.
What it costs
Scoped on a short call and quoted as a fixed price before any work starts - no hourly billing and no surprise invoice. An assessment normally costs less than a full penetration test, because it reviews rather than actively exploits. For reference our VAPT engagements start at ₹35,000, and we will tell you on the call which of the two you actually need.