Assessment

Network Security Assessment

In short: An assessment answers a simpler question than a penetration test: what have we actually got, where is it exposed, and what should we deal with first? It is where most businesses should start.

Assessment or penetration test?

People use the words interchangeably and they are not the same thing. It is worth being clear, because buying the wrong one wastes money.

Security assessmentPenetration test (VAPT)
Question it answersWhat do we have and where are we weak?Can someone actually get in, and how far?
ApproachReview of design, configuration and exposureActive testing that attempts exploitation
Best whenYou have never done either, or inherited an undocumented networkA customer, auditor or insurer wants evidence
OutputA prioritised picture of your posture and a planA findings report suitable to send onward

If somebody external has asked you for proof, you want VAPT. If you genuinely do not know what you have, start here - an assessment usually pays for itself by telling you which of the things you were about to buy you do not need.

What we look at

What you get

A written report ranking what we found by what actually matters to your business, not by a generic severity score. A call to walk through it in plain English. And a prioritised plan that separates what should be fixed this month from what can reasonably wait a year - including the things we think you can safely ignore.

We will also tell you where you are already fine. An assessment that returns a list of forty problems and no context is not useful; you need to know the three that matter.

What it costs

Scoped on a short call and quoted as a fixed price before any work starts - no hourly billing and no surprise invoice. An assessment normally costs less than a full penetration test, because it reviews rather than actively exploits. For reference our VAPT engagements start at ₹35,000, and we will tell you on the call which of the two you actually need.

Frequently asked questions

How long does an assessment take?

Typically one to two weeks from the scoping call to the report for a single-site business, longer where there are several locations. Most of the work is remote, and we agree any on-site day in advance.

Do we need to prepare anything?

No. You do not need to tidy up, document anything or fix anything first. Finding what is actually there, including the things nobody remembers setting up, is the point of the exercise.

Will you try to sell us hardware off the back of it?

The report tells you what to fix, and where the answer is that your existing equipment is fine, it says so. We are an official partner of Sophos, Fortinet and WatchGuard, which means we have no incentive to push one brand - and no interest in selling you a box you do not need.

What if the assessment finds serious problems?

Then you know, which is better than not knowing. We prioritise them, tell you what to do first, and quote separately for any remediation work. There is no obligation to have us do the fixing.

Not sure what you have or where you stand?

A thirty-minute call, no cost, and we will tell you honestly whether an assessment is what you actually need.

Book a free consultation