Home / VAPT & DPDP Explained

// Knowledge base

VAPT and DPDP, explained without the jargon.

Two terms you'll hear constantly if you do business in India right now — one technical, one legal. Here's what each actually means, what it costs you, where it genuinely helps, and where it doesn't. Including the parts most vendors leave out.

// Definition

VAPT — Vulnerability Assessment & Penetration Testing

VAPT is two different security activities bundled under one name. The confusion between them is the single most common reason companies overpay for the wrong thing.

/ The VA half

Vulnerability Assessment

A broad, largely automated sweep of your systems to find known weaknesses — missing patches, outdated software, weak configurations, exposed services.

The question it answers: "What weaknesses exist across my estate?"

  • Wide coverage, shallow depth
  • Fast and repeatable — often run monthly
  • Produces a prioritised list of issues
  • Cheaper; can be partly automated
VS
/ The PT half

Penetration Testing

A skilled human actively attempting to exploit those weaknesses, chaining them together the way a real attacker would to reach something valuable.

The question it answers: "What could an attacker actually do to me?"

  • Narrow scope, deep exploitation
  • Manual, expert-driven, time-boxed
  • Proves real business impact
  • Costlier; typically annual or per-release

In short: a vulnerability assessment tells you the door is unlocked. A penetration test walks through it, opens your safe, and shows you photos of what's inside. You need both — the assessment for coverage, the test for proof.

// Approach

Three ways a test can be run

How much we're told upfront changes what the test simulates — and what it will find.

/ Black box

Zero knowledge

We start with nothing but your company name, exactly like an external attacker. Most realistic simulation of an opportunistic breach.

Best for: testing your external perimeter and how exposed you look from the internet.

Trade-off: time is spent on reconnaissance rather than depth, so internal issues can be missed.

/ Grey box

Partial knowledge

We're given user-level credentials and basic architecture. Simulates a rogue employee, a compromised account, or a malicious customer.

Best for: most engagements. The best balance of realism and value for money.

Trade-off: doesn't fully replicate either an outsider's blindness or a full code review.

/ White box

Full knowledge

We get source code, architecture diagrams and admin access. Maximum coverage per hour spent, nothing hidden.

Best for: pre-launch products, critical applications, and secure code review.

Trade-off: least realistic as an attack simulation; findings need business-context triage.

// Scope

What can be put under test

TypeWhat it coversTypical trigger
Network VAPTServers, firewalls, routers, exposed services, internal segmentationAnnual compliance, new infrastructure
Web ApplicationAuthentication, session handling, injection, access control, business logicMajor release, customer security review
API TestingREST/GraphQL endpoints, authorisation flaws, rate limiting, data exposureNew integration or mobile backend
Mobile ApplicationAndroid/iOS binaries, local storage, certificate pinning, backend callsApp store release cycle
Cloud ConfigurationIAM policy, storage exposure, network rules, logging gapsCloud migration, audit finding
WirelessWi-Fi encryption, rogue access points, guest network isolationOffice expansion, ISO 27001 audit
Social EngineeringPhishing susceptibility, pretexting, physical access attemptsSecurity awareness baseline
// The honest assessment

Pros and cons of VAPT

Every security vendor will list the pros. Here are the limitations too — because knowing them is what stops you buying a test that gives false comfort.

Advantages

  • Finds real risk before attackers do. Issues get fixed on your schedule and budget rather than during an incident.
  • Proves impact, not theory. A working exploit turns "we should patch that eventually" into a funded priority.
  • Satisfies regulators and customers. RBI, SEBI and IRDAI frameworks expect periodic testing; enterprise clients ask for reports before signing.
  • Supports DPDP defensibility. Demonstrates the "reasonable security safeguards" the Act requires.
  • Catches what tools can't. Business-logic flaws and broken authorisation are invisible to scanners.
  • Cheaper than a breach. Incident response, legal costs, penalties and lost customers dwarf the price of testing.
  • Prioritises effort. Tells your team which of a thousand alerts to fix first.

Limitations & risks

  • It's a snapshot, not a subscription. A test is valid for the configuration on the day it ran. Deploy next week and the picture changes.
  • Scope defines the result. Anything outside the agreed scope is untested — and attackers don't respect your scope document.
  • A clean report isn't proof of safety. It means nothing was found in that scope, in that window, by that team.
  • Quality varies wildly. Plenty of "VAPT" in the market is an automated scan with a logo on it. Ask to see a redacted sample report.
  • Small risk of disruption. Active testing can occasionally destabilise fragile systems — mitigated with proper windows and rules of engagement.
  • Findings without fixes are worthless. The report is the easy part; remediation takes engineering time most teams haven't budgeted.
  • Cost is real. Genuine manual testing takes senior people days or weeks. If a quote looks too cheap, it is.

How to buy VAPT well: ask how many hours are manual versus automated, who specifically will test (and their experience), whether a retest is included, and to see a redacted sample report. Any vendor unwilling to answer those four questions is selling you a scan.

// Standards

The frameworks a credible test follows

OWASP WSTG

The web and API testing standard. Defines what must be checked in an application test.

PTES

Penetration Testing Execution Standard. Structures the engagement end to end.

NIST SP 800-115

Technical guide to security testing. Strong on planning and governance.

CERT-In guidance

India's national CERT sets audit expectations and the six-hour incident reporting rule.

// Apply it

Now find out where you actually stand.

Reading about it is the easy part. We'll assess your real environment and give you a prioritised, costed picture of what to fix first.