Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Author

Ms.Pragya Dwivedi

Pragya Dwivedi is an Associate Director at SecureRoot Risk Advisory LLP. She holds the CISM and eWPTX certifications and works across security governance and advanced web application penetration testing, translating findings into fixes that hold up in audits and in production.

Credentials

  • CISM
  • eWPTX
Associate Director
SecureRoot Risk Advisory LLP

Articles by Pragya Dwivedi

Guidance written up from the engagements this author scopes and delivers.

All Articles
  • 8 min readBy Pragya Dwivedi, Associate Director

    Phishing Simulation Services in India: Process, Metrics and Cost

    Phishing Simulation Services in India: Process, Metrics and Cost The average click rate for untrained employees sits at roughly 33 percent. After a year of regular simulation and training, organisations typically get that under 5 percent. Those two numbers are why phishing simulation exists as a service category. They are also why most programmes stall. […]

    Read Article
  • 8 min readBy Pragya Dwivedi, Associate Director

    AWS Cloud Security Audit Checklist for Indian SaaS Teams

    AWS Cloud Security Audit Checklist for Indian SaaS Teams Most AWS security checklists you will find were written for a US audience. They cover IAM hygiene and public S3 buckets well, and they say nothing about the two requirements that will actually appear in your next India audit: a six hour incident reporting clock and […]

    Read Article
  • Red Team vs Penetration Testing: Key Differences Explained

    8 min readBy Pragya Dwivedi, Associate Director

    Red Team vs Penetration Testing: Key Differences Explained

    The terms get used interchangeably, but red team vs penetration testing is a real distinction. One measures how vulnerable a system is; the other measures how well your organisation detects and responds to a determined attacker.

    Read Article
  • Types of Penetration Testing: A Complete Guide

    8 min readBy Pragya Dwivedi, Associate Director

    Types of Penetration Testing: A Complete Guide

    Not all security tests are the same. The types of penetration testing differ by how much the tester knows and what they target – and choosing the right one decides whether a test finds real risk or just ticks a box.

    Read Article
  • DevSecOps Best Practices: Build Security Into Every Release

    8 min readBy Pragya Dwivedi, Associate Director

    DevSecOps Best Practices: Build Security Into Every Release

    Security bolted on at the end slows releases and misses flaws. DevSecOps best practices fix that by building security into every stage of development – so teams ship faster and safer at the same time.

    Read Article
  • OWASP Top 10 Vulnerabilities Explained (With Fixes)

    8 min readBy Pragya Dwivedi, Associate Director

    OWASP Top 10 Vulnerabilities Explained (With Fixes)

    If you build or run web applications, the OWASP Top 10 vulnerabilities are the risks most likely to get you breached. They represent the consensus of the global security community on where web apps fail most often.

    Read Article
  • Cloud Security Best Practices: A Practical 2026 Guide

    8 min readBy Pragya Dwivedi, Associate Director

    Cloud Security Best Practices: A Practical 2026 Guide

    Most cloud breaches are not sophisticated attacks – they are simple mistakes. Strong cloud security best practices exist precisely to stop the misconfigurations, over-broad permissions and exposed secrets that cause the majority of incidents.

    Read Article
  • Penetration Testing Cost in India: 2026 Pricing Guide

    8 min readBy Pragya Dwivedi, Associate Director

    Penetration Testing Cost in India: 2026 Pricing Guide

    Ask three firms for a quote and you will get three very different numbers. penetration testing cost in india depends on what is tested, how deeply, and by whom – so understanding the drivers helps you scope sensibly instead of overpaying.

    Read Article