Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Author

Pragya Dwivedi

Pragya Dwivedi is an Associate Director at SecureRoot Risk Advisory LLP. She holds the CISM and eWPTX certifications and works across security governance and advanced web application penetration testing, translating findings into fixes that hold up in audits and in production.

Credentials

  • CISM
  • eWPTX
Associate Director
SecureRoot Risk Advisory LLP

Articles by Pragya Dwivedi

Guidance written up from the engagements this author scopes and delivers.

All Articles
  • Penetration Testing16 min read

    CERT-In Incident Reporting: The Six-Hour Runbook

    The CERT-In Directions give you six hours from noticing a listed incident. This is the execution side: what starts the clock, which of the 20 Annexure I types are reportable, the channels and fields, who is allowed to submit, and what to send when the facts are still moving at hour five.

    Read Article
  • Penetration Testing: How often to run VAPT. Illustrated cover by SecureRoot Risk Advisory.
    Penetration Testing13 min read

    How Often Should VAPT Be Done? Annual Baseline, Change Triggers and Regulator Cadence in India

    Once a year is the floor, not the plan. This guide sets out when VAPT must be repeated after change, what RBI, SEBI, IRDAI and PCI DSS each require, and how to set a risk-based cadence by asset type.

    Read Article
  • Penetration Testing: CERT-In Directions, in practice. Illustrated cover by SecureRoot Risk Advisory.
    Penetration Testing14 min read

    CERT-In Directions Compliance in India: 6-Hour Reporting, Logs and NTP

    The CERT-In Directions of 28 April 2022 apply to almost every organisation running ICT systems for Indian users. This guide walks through each obligation, what CERT-In's own FAQs clarify, and how VAPT and log monitoring make the 6-hour clock achievable.

    Read Article
  • Penetration Testing: API security testing. Illustrated cover by SecureRoot Risk Advisory.
    Penetration Testing12 min read

    API Security Testing Services: OWASP API Top 10 Coverage and Retesting

    APIs fail on authorisation and business logic far more than on classic injection bugs, and a scanner cannot tell whether one tenant can read another's data. This guide sets out what a manual API security test covers, how each OWASP API Security Top 10 category is tested, what the report and the verified retest contain and what an engagement costs.

    Read Article
  • Managed SOC: What 24/7 monitoring actually includes. Illustrated cover by SecureRoot Risk Advisory.
    Managed SOC12 min read

    Managed SOC Services in India: What 24/7 Monitoring Actually Includes

    Managed SOC proposals all promise 24/7 monitoring. What that phrase covers varies enormously, from an alert-forwarding service to analysts who investigate, contain and report. This guide sets out the six things a managed SOC should include, how to compare it with building your own, and what to ask before signing.

    Read Article
  • Phishing Simulation: Phishing simulation: process, metrics, cost. Illustrated cover by SecureRoot Risk Advisory.
    Phishing Simulation11 min read

    Phishing Simulation Services in India: Process, Metrics and Cost

    The average click rate for untrained employees sits at roughly 33 percent. After a year of regular simulation and training, organisations typically get that under 5 percent. Those two numbers are why phishing simulation exists as a service category. They are also why most programmes stall. …

    Read Article
  • Cloud Security: AWS audit checklist for Indian SaaS. Illustrated cover by SecureRoot Risk Advisory.
    Cloud Security11 min read

    AWS Cloud Security Audit Checklist for Indian SaaS Teams

    Most AWS security checklists you will find were written for a US audience. They cover IAM hygiene and public S3 buckets well, and they say nothing about the two requirements that will actually appear in your next India audit: a six hour incident reporting clock and …

    Read Article
  • Penetration Testing: Red team or penetration test? Illustrated cover by SecureRoot Risk Advisory.
    Penetration Testing9 min read

    Red Team vs Penetration Testing: Key Differences Explained

    The terms get used interchangeably, but red team vs penetration testing is a real distinction. One measures how vulnerable a system is; the other measures how well your organisation detects and responds to a determined attacker.

    Read Article
  • Penetration Testing: Types of penetration testing. Illustrated cover by SecureRoot Risk Advisory.
    Penetration Testing9 min read

    Types of Penetration Testing: A Complete Guide

    Not all security tests are the same. The types of penetration testing differ by how much the tester knows and what they target – and choosing the right one decides whether a test finds real risk or just ticks a box.

    Read Article
  • DevSecOps: Security in every release. Illustrated cover by SecureRoot Risk Advisory.
    DevSecOps9 min read

    DevSecOps Best Practices: Build Security Into Every Release

    Security bolted on at the end slows releases and misses flaws. DevSecOps best practices fix that by building security into every stage of development – so teams ship faster and safer at the same time.

    Read Article
  • Penetration Testing: OWASP Top 10, explained with fixes. Illustrated cover by SecureRoot Risk Advisory.
    Penetration Testing9 min read

    OWASP Top 10 Vulnerabilities Explained (With Fixes)

    If you build or run web applications, the OWASP Top 10 vulnerabilities are the risks most likely to get you breached. They represent the consensus of the global security community on where web apps fail most often.

    Read Article
  • Cloud Security: Cloud security best practices, 2026. Illustrated cover by SecureRoot Risk Advisory.
    Cloud Security24 min read

    Cloud Security Best Practices: A Practical 2026 Guide

    Most cloud guides stop at advice. This one names the control, gives the command on all three providers, maps it to the CIS Benchmark and NIST CSF item an auditor will ask for, and adds the India layer that global guides leave out.

    Read Article
  • Penetration Testing: Penetration testing cost in India, 2026. Illustrated cover by SecureRoot Risk Advisory.
    Penetration Testing11 min read

    Penetration Testing Cost in India: 2026 Pricing Guide

    Real numbers, not a sales pitch. Indicative penetration testing price ranges by engagement type, the five factors that move a quote, and the warning signs of a test priced too low to be real.

    Read Article