Author
Ms.Pragya Dwivedi
Pragya Dwivedi is an Associate Director at SecureRoot Risk Advisory LLP. She holds the CISM and eWPTX certifications and works across security governance and advanced web application penetration testing, translating findings into fixes that hold up in audits and in production.
Credentials
- CISM
- eWPTX
- Associate Director
- SecureRoot Risk Advisory LLP
Articles by Pragya Dwivedi
Guidance written up from the engagements this author scopes and delivers.
Managed SOC11 min readManaged SOC Services in India: What 24/7 Monitoring Actually Includes
Managed SOC proposals all promise 24/7 monitoring. What that phrase covers varies enormously, from an alert-forwarding service to analysts who investigate, contain and report. This guide sets out the six things a managed SOC should include, how to compare it with building your own, and what to ask before signing.
Read Article
Penetration Testing11 min readAPI Security Testing Services: OWASP API Top 10 Coverage and Retesting
APIs fail on authorisation and business logic far more than on classic injection bugs, and a scanner cannot tell whether one tenant can read another's data. This guide sets out what a manual API security test covers, how each OWASP API Security Top 10 category is tested, what the report and the verified retest contain and what an engagement costs.
Read Article
Phishing Simulation8 min readPhishing Simulation Services in India: Process, Metrics and Cost
The average click rate for untrained employees sits at roughly 33 percent. After a year of regular simulation and training, organisations typically get that under 5 percent. Those two numbers are why phishing simulation exists as a service category. They are also why most programmes stall. …
Read Article
Cloud Security8 min readAWS Cloud Security Audit Checklist for Indian SaaS Teams
Most AWS security checklists you will find were written for a US audience. They cover IAM hygiene and public S3 buckets well, and they say nothing about the two requirements that will actually appear in your next India audit: a six hour incident reporting clock and …
Read Article
Penetration Testing8 min readRed Team vs Penetration Testing: Key Differences Explained
The terms get used interchangeably, but red team vs penetration testing is a real distinction. One measures how vulnerable a system is; the other measures how well your organisation detects and responds to a determined attacker.
Read Article
Penetration Testing8 min readTypes of Penetration Testing: A Complete Guide
Not all security tests are the same. The types of penetration testing differ by how much the tester knows and what they target – and choosing the right one decides whether a test finds real risk or just ticks a box.
Read Article
DevSecOps8 min readDevSecOps Best Practices: Build Security Into Every Release
Security bolted on at the end slows releases and misses flaws. DevSecOps best practices fix that by building security into every stage of development – so teams ship faster and safer at the same time.
Read Article
Penetration Testing8 min readOWASP Top 10 Vulnerabilities Explained (With Fixes)
If you build or run web applications, the OWASP Top 10 vulnerabilities are the risks most likely to get you breached. They represent the consensus of the global security community on where web apps fail most often.
Read Article
Cloud Security8 min readCloud Security Best Practices: A Practical 2026 Guide
Most cloud breaches are not sophisticated attacks – they are simple mistakes. Strong cloud security best practices exist precisely to stop the misconfigurations, over-broad permissions and exposed secrets that cause the majority of incidents.
Read Article
Penetration Testing7 min readPenetration Testing Cost in India: 2026 Pricing Guide
Real numbers, not a sales pitch. Indicative penetration testing price ranges by engagement type, the five factors that move a quote, and the warning signs of a test priced too low to be real.
Read Article