Ayati One — Managed Cyber Defence

Vulnerability Assessment & Penetration Testing (VAPT)

Find the paths an attacker would take — before an attacker does — and fix what actually matters.

A proven attack path from an exposed VPN appliance through foothold, privilege escalation and lateral movement to the customer database, with findings graded by exploitability

What it is

Vulnerability Assessment & Penetration Testing pairs two complementary disciplines. Vulnerability assessment systematically scans and catalogues weaknesses across your estate; penetration testing goes further — skilled testers chain those weaknesses the way a real adversary would, demonstrating actual impact: data accessed, privileges gained, systems controlled.

The output is not a scanner dump. An enterprise-grade VAPT engagement produces evidence of exploitability, business-ranked risk, and a remediation path your engineers can actually execute.

The business case

Why enterprises need it

  • You can't defend what you haven't measured

    Unknown internet-facing assets, forgotten test environments and unpatched services are how breaches begin. Regular assessment keeps your real attack surface — not your assumed one — in view.

  • Compliance and customers demand proof

    ISO 27001, SOC 2, PCI DSS, RBI/SEBI guidelines and enterprise procurement all require periodic independent testing. A credible VAPT report is now table stakes for closing enterprise deals.

  • Severity scores lie without context

    A 'critical' CVE on an isolated system may matter less than a 'medium' misconfiguration on your identity provider. Exploitation-led testing ranks findings by real business impact, so remediation effort lands where it reduces risk most.

How we deliver

Cloud Armor's approach

  1. Scoping & rules of engagement

    We define the target estate — external, internal, web applications, APIs, cloud configuration, wireless, social engineering — with clear rules of engagement, testing windows and safe-handling of production systems.

  2. Methodology-driven testing

    Testing aligned to OWASP (WSTG/ASVS, API Top 10), PTES and NIST SP 800-115, executed by experienced testers — automated breadth, manual depth, and exploitation with evidence captured at every step.

  3. Reporting for two audiences

    An executive summary that speaks business risk for leadership and auditors, and a technical annex with reproduction steps, evidence and specific remediation guidance for engineers — no filler findings.

  4. Remediation support & retest

    We stay engaged through the fix: prioritised remediation workshops, direct support to your engineering teams, and a formal retest that verifies closure — so the report ends in reduced risk, not a shelf document.

Methodology

VAPT methodologies

There is no single "penetration test". What you get depends on how much we are told before we start and how much of the work is done by a human. We agree both in the scoping document, in writing, so you know exactly what was and was not covered when the report lands.

How the testing is performed

  • Manual testing

    A human working through the application the way an attacker would — chaining flaws, abusing business logic, and finding the authorisation gaps that only make sense once you understand what the application is for. This is where the findings that matter come from, and it is the majority of every engagement we run.

  • Automated testing

    Tooling runs first and runs broad: known CVEs, outdated components, default credentials, TLS and configuration weaknesses across the whole scope. It gives coverage a human cannot match on volume — but every result is verified by an engineer before it reaches your report, because an unvalidated scanner finding is noise, not a vulnerability.

How much we are told beforehand

  • Black box

    We start with nothing but the target — no credentials, no source, no architecture diagram. It models an external attacker with no inside knowledge and tests what is genuinely reachable from the internet. Realistic, but it can miss depth simply because time runs out before a tester finds the door.

  • White box

    Full disclosure: source code, architecture, privileged credentials and design documents. Nothing is hidden, so coverage is the deepest available and the report can point at the exact line of code. This is the right choice when the goal is to find everything rather than to simulate an outsider.

  • Grey box

    The middle ground, and what most engagements actually use. We get standard user credentials and a basic understanding of the architecture, then test as an attacker who has already gained a foothold or as a malicious insider. It buys most of the depth of white box without spending the engagement mapping what you could simply have told us.

What the testing follows

  • Recognised methodology, not a personal checklist

    Web and API testing follows the OWASP Testing Guide and the OWASP Top 10 and API Top 10; infrastructure work follows the Penetration Testing Execution Standard and NIST SP 800-115. Findings carry CWE classification so they can be grouped and tracked against any framework you already report on.

  • Evidence for every finding

    Each finding is reproducible: the request, the response, the steps and the proof of impact. If we cannot demonstrate it, it does not go in the report as a vulnerability — it goes in as an observation, clearly marked as such.

Client feedback

What clients say after the retest

Client email following a retest and revalidation assessment, thanking the Cloud Armor team for completing the work before the deadline
Client feedback following a retest and revalidation assessment. Recipient details and the sender address have been removed.

Related practice areas

VAPT is a service capability rather than a product resale — testing uses a mixed toolchain (commercial and open-source) selected per engagement.

Scope a VAPT engagement

A 30-minute conversation with our engineers is usually enough to map your requirement to a concrete plan and honest estimate.

Tip: tell us your current cyber security requirement — what you are trying to protect, roughly how large the estate is, and any audit or deadline driving it. The more specific you are, the more useful our first reply will be.

We reply from a named engineer, not a sales queue. Your details are used only to answer this enquiry — see our privacy policy.