Home / VAPT & DPDP Explained
// Knowledge baseVAPT and DPDP, explained without the jargon.
Two terms you'll hear constantly if you do business in India right now — one technical, one legal. Here's what each actually means, what it costs you, where it genuinely helps, and where it doesn't. Including the parts most vendors leave out.
VAPT — Vulnerability Assessment & Penetration Testing
VAPT is two different security activities bundled under one name. The confusion between them is the single most common reason companies overpay for the wrong thing.
Vulnerability Assessment
A broad, largely automated sweep of your systems to find known weaknesses — missing patches, outdated software, weak configurations, exposed services.
The question it answers: "What weaknesses exist across my estate?"
- Wide coverage, shallow depth
- Fast and repeatable — often run monthly
- Produces a prioritised list of issues
- Cheaper; can be partly automated
Penetration Testing
A skilled human actively attempting to exploit those weaknesses, chaining them together the way a real attacker would to reach something valuable.
The question it answers: "What could an attacker actually do to me?"
- Narrow scope, deep exploitation
- Manual, expert-driven, time-boxed
- Proves real business impact
- Costlier; typically annual or per-release
In short: a vulnerability assessment tells you the door is unlocked. A penetration test walks through it, opens your safe, and shows you photos of what's inside. You need both — the assessment for coverage, the test for proof.
Three ways a test can be run
How much we're told upfront changes what the test simulates — and what it will find.
Zero knowledge
We start with nothing but your company name, exactly like an external attacker. Most realistic simulation of an opportunistic breach.
Best for: testing your external perimeter and how exposed you look from the internet.
Trade-off: time is spent on reconnaissance rather than depth, so internal issues can be missed.
Partial knowledge
We're given user-level credentials and basic architecture. Simulates a rogue employee, a compromised account, or a malicious customer.
Best for: most engagements. The best balance of realism and value for money.
Trade-off: doesn't fully replicate either an outsider's blindness or a full code review.
Full knowledge
We get source code, architecture diagrams and admin access. Maximum coverage per hour spent, nothing hidden.
Best for: pre-launch products, critical applications, and secure code review.
Trade-off: least realistic as an attack simulation; findings need business-context triage.
What can be put under test
| Type | What it covers | Typical trigger |
|---|---|---|
| Network VAPT | Servers, firewalls, routers, exposed services, internal segmentation | Annual compliance, new infrastructure |
| Web Application | Authentication, session handling, injection, access control, business logic | Major release, customer security review |
| API Testing | REST/GraphQL endpoints, authorisation flaws, rate limiting, data exposure | New integration or mobile backend |
| Mobile Application | Android/iOS binaries, local storage, certificate pinning, backend calls | App store release cycle |
| Cloud Configuration | IAM policy, storage exposure, network rules, logging gaps | Cloud migration, audit finding |
| Wireless | Wi-Fi encryption, rogue access points, guest network isolation | Office expansion, ISO 27001 audit |
| Social Engineering | Phishing susceptibility, pretexting, physical access attempts | Security awareness baseline |
Pros and cons of VAPT
Every security vendor will list the pros. Here are the limitations too — because knowing them is what stops you buying a test that gives false comfort.
Advantages
- Finds real risk before attackers do. Issues get fixed on your schedule and budget rather than during an incident.
- Proves impact, not theory. A working exploit turns "we should patch that eventually" into a funded priority.
- Satisfies regulators and customers. RBI, SEBI and IRDAI frameworks expect periodic testing; enterprise clients ask for reports before signing.
- Supports DPDP defensibility. Demonstrates the "reasonable security safeguards" the Act requires.
- Catches what tools can't. Business-logic flaws and broken authorisation are invisible to scanners.
- Cheaper than a breach. Incident response, legal costs, penalties and lost customers dwarf the price of testing.
- Prioritises effort. Tells your team which of a thousand alerts to fix first.
Limitations & risks
- It's a snapshot, not a subscription. A test is valid for the configuration on the day it ran. Deploy next week and the picture changes.
- Scope defines the result. Anything outside the agreed scope is untested — and attackers don't respect your scope document.
- A clean report isn't proof of safety. It means nothing was found in that scope, in that window, by that team.
- Quality varies wildly. Plenty of "VAPT" in the market is an automated scan with a logo on it. Ask to see a redacted sample report.
- Small risk of disruption. Active testing can occasionally destabilise fragile systems — mitigated with proper windows and rules of engagement.
- Findings without fixes are worthless. The report is the easy part; remediation takes engineering time most teams haven't budgeted.
- Cost is real. Genuine manual testing takes senior people days or weeks. If a quote looks too cheap, it is.
How to buy VAPT well: ask how many hours are manual versus automated, who specifically will test (and their experience), whether a retest is included, and to see a redacted sample report. Any vendor unwilling to answer those four questions is selling you a scan.
The frameworks a credible test follows
OWASP WSTG
The web and API testing standard. Defines what must be checked in an application test.
PTES
Penetration Testing Execution Standard. Structures the engagement end to end.
NIST SP 800-115
Technical guide to security testing. Strong on planning and governance.
CERT-In guidance
India's national CERT sets audit expectations and the six-hour incident reporting rule.
DPDP — India's Digital Personal Data Protection Act
The DPDP Act, 2023 is India's first comprehensive data protection law. It received Presidential assent in August 2023, and the implementing DPDP Rules were notified in November 2025 — which is when it stopped being theoretical.
In one sentence: if your organisation handles the digital personal data of people in India, you now have legal obligations about how you collect it, why you hold it, how long you keep it, and how well you protect it.
It applies to processing inside India, and to processing outside India where you're offering goods or services to people in India. It covers digital personal data — including paper records later digitised.
What makes DPDP different from a policy exercise is that the largest penalty in the Act isn't attached to paperwork. It's attached to failing to implement reasonable security safeguards. That's an engineering standard, judged after a breach.
Who's who under the Act
The individual the data is about — your customer, employee or user.
You, if you decide why and how personal data is processed. Carries the obligations.
A vendor processing data on your behalf. You stay accountable for them.
Larger or higher-risk organisations, notified by government, with extra duties including a DPO and audits.
A registered intermediary letting individuals give and withdraw consent in one place.
Where we are in the timeline
The Rules phase obligations in over roughly eighteen months. The end of that runway is the date that matters.
-
01
August 2023 — Act passed
The DPDP Act receives Presidential assent, making India one of the last major economies to legislate comprehensive data protection.
-
02
November 2025 — Rules notified
The Digital Personal Data Protection Rules, 2025 are notified and gazetted, turning broad principles into operational requirements. Certain provisions take effect immediately.
-
03
The phased window
Day-to-day obligations — consent notices, breach notification, handling data principal requests — phase in across roughly eighteen months. This is your build period.
-
04
May 2027 — full enforcement
The remaining obligations and the full penalty schedule come into force. From this point, non-compliance is directly actionable by the Data Protection Board.
Why "we'll start in 2027" fails: data discovery and mapping alone typically takes three to six months in a mid-sized company, and consent re-architecture usually needs a product release cycle. The runway is generous only if you start using it.
What the Act requires of you
Lawful basis & notice
Process personal data only with valid consent or a legitimate use permitted by the Act — and give a clear, plain-language notice of what you collect and why.
Free, informed, revocable consent
Consent must be specific and unbundled, and withdrawing it must be as easy as giving it. Pre-ticked boxes and blanket consent do not qualify.
Purpose & storage limitation
Use data only for the stated purpose, and erase it once that purpose is served — unless a law requires you to retain it.
Reasonable security safeguards
Implement technical and organisational controls appropriate to the data you hold. This carries the highest penalty in the Act.
Breach notification
Notify the Data Protection Board and every affected individual in the event of a personal data breach, within the prescribed timelines.
Data principal rights
Provide working mechanisms for access, correction, erasure, grievance redressal and nomination — and respond within the prescribed period.
Children's data
Verifiable parental consent for under-18s, with no behavioural tracking or targeted advertising directed at children.
Processor accountability
Bind vendors by contract and stay responsible for their processing. Outsourcing the work does not outsource the liability.
Extra duties if significant
Significant Data Fiduciaries must appoint an India-based DPO, run periodic audits and conduct Data Protection Impact Assessments.
The penalty schedule
Penalties are financial and levied by the Data Protection Board. These are maximums, assessed against the nature and gravity of the breach.
| Failure | Maximum penalty | What it means in practice |
|---|---|---|
| Failure to take reasonable security safeguards to prevent a breach | ₹250 crore | The big one — and it's a technical standard, not a paperwork one |
| Failure to notify the Board or affected individuals of a breach | ₹200 crore | Silence after an incident is penalised separately from the incident |
| Non-compliance with obligations regarding children's data | ₹200 crore | Applies to any platform reachable by under-18s |
| Non-compliance with Significant Data Fiduciary duties | ₹150 crore | DPO, audits and impact assessments |
| Breach of duties by the Data Principal | ₹10,000 | Individuals filing frivolous or false complaints |
| Breach of any other provision | ₹50 crore | The catch-all residual category |
Pros and cons of the DPDP regime
Compliance is mandatory, so the real question isn't whether to comply — it's understanding what you gain and what it genuinely costs.
Advantages
- Enforceable rights for individuals. Indians finally get access, correction, erasure and grievance redressal over their own data.
- Trust becomes a differentiator. Demonstrable privacy practice increasingly wins enterprise deals and customer confidence.
- Forces overdue data hygiene. Most organisations discover they were holding data they didn't need, didn't know about, and couldn't protect.
- Simpler than GDPR. Deliberately lighter — fewer lawful bases, no mandatory DPO for everyone, more principles-based drafting.
- Eases global business. A recognised regime makes it easier to serve EU and US clients who demand data-protection assurances.
- Reduces breach blast radius. Minimisation and deletion mean less data to lose when something does go wrong.
- Relatively open transfers. Cross-border transfer is permitted except to countries the government restricts — friendlier than a whitelist model.
Costs & criticisms
- Real implementation cost. Discovery, consent re-architecture, retention automation and vendor contracts consume engineering and legal budget.
- Heaviest on smaller firms. A 40-person company faces broadly the same obligations as a large enterprise, with none of the compliance headcount.
- "Reasonable safeguards" is undefined. The largest penalty attaches to a standard you only find out you failed after an incident.
- Broad government exemptions. The State and its agencies can be exempted from key provisions — a frequent criticism from privacy advocates.
- No compensation for individuals. Penalties go to the government; the affected person receives nothing directly.
- Consent fatigue is real. More notices and prompts can degrade user experience without meaningfully improving comprehension.
- Narrower than GDPR in scope. It covers digital personal data only, with no separate category for sensitive data such as health or biometrics.
- Enforcement is still unproven. How strictly the Board interprets obligations won't be clear until the first cases are decided.
A practical readiness sequence
This is the order we run it in, because each step depends on the one before it.
- 01
Find the data
Discover every system, database, spreadsheet and SaaS tool holding personal data. Almost nobody's initial list is complete.
- 02
Map how it flows
Trace collection, storage, processing, sharing and deletion — including every third party who touches it.
- 03
Assess the gaps
Compare current practice against the Act and Rules, and rank gaps by penalty exposure rather than by ease of fixing.
- 04
Fix consent and notice
Rebuild consent capture so it's specific, unbundled and withdrawable, with a clear notice at the point of collection.
- 05
Build the rights workflows
Stand up real processes for access, correction, erasure and grievance — with owners and response-time tracking.
- 06
Harden the safeguards
Encryption, access control, logging, retention automation and vendor controls. This is where VAPT and DPDP meet.
- 07
Rehearse breach response
Notification has a clock on it. A tabletop exercise now is far cheaper than improvising during a real incident.
Where VAPT and DPDP meet: the Act's biggest penalty is for inadequate security safeguards. Penetration testing is one of the clearest ways to demonstrate you assessed and hardened those safeguards. The two aren't separate purchases — one is evidence for the other.
This page is a plain-English summary for general guidance, not legal advice. For obligations specific to your organisation, consult qualified legal counsel alongside your security assessment.
Questions we get asked constantly
At minimum annually, and additionally after any significant change — a major release, an infrastructure migration, or a new integration. Regulated entities under RBI or SEBI frameworks generally need testing at defined intervals. If you deploy weekly, an annual test alone leaves fifty-one weeks unexamined, which is why continuous vulnerability management usually sits alongside the annual deep test.
It shouldn't, and we plan specifically to avoid it. We agree rules of engagement before starting: testing windows, excluded systems, an escalation contact, and a stop condition. Denial-of-service testing is only ever performed on explicit written request. That said, genuinely fragile systems can behave unpredictably under active testing — which is itself useful information about your resilience.
Yes, and it's often the right call — provided staging genuinely mirrors production in configuration, data volume and integrations. Where it diverges, findings won't fully transfer. A common approach is deep testing in staging plus a lighter, carefully scoped validation pass in production.
Almost certainly yes. The Act has no general small-business exemption. If you process the digital personal data of people in India — including employee data — you're a Data Fiduciary with obligations. The additional duties reserved for Significant Data Fiduciaries won't apply, but the core requirements around consent, notice, security safeguards, breach notification and data principal rights do.
You're a long way ahead, but not automatically compliant. GDPR gives you the hard parts — data mapping, rights processes, breach procedures. The gaps are usually India-specific: DPDP's narrower set of lawful bases (consent and defined legitimate uses, with no broad "legitimate interests"), verifiable parental consent for under-18s rather than 13–16, notice content requirements, and Indian breach-reporting timelines and formats.
A VAPT is technical and adversarial — we attack your systems to see what breaks. A security audit is procedural and evidence-based — it checks your controls, policies and records against a standard such as ISO 27001. Auditors typically ask to see a recent VAPT report as evidence, so the two are complementary rather than competing.
Two reports and a conversation. An executive summary framing business risk for leadership, and a technical report with each finding's severity, affected assets, reproduction steps, evidence and specific remediation guidance. We then walk your engineers through it live, stay reachable while they remediate, and retest to confirm closure.
Yes, with proper written authorisation — which we require before any engagement begins. Unauthorised access to computer systems is an offence under the Information Technology Act, so authorisation isn't a formality. If your systems are hosted with a third party such as a cloud provider or SaaS platform, their terms may require notification or restrict certain testing, and we'll flag that during scoping.
Now find out where you actually stand.
Reading about it is the easy part. We'll assess your real environment and give you a prioritised, costed picture of what to fix first.