Security and Compliance Services
Certification and privacy programmes, manual penetration testing, code and dependency review, configuration hardening, and security work we run for you month after month. Most clients arrive with one problem and grow into a programme delivered by the same team.
Compliance
Certifications and Privacy Programmes Across 13 Frameworks
Practice Area OverviewMeasured Against
ISO/IEC 27001:2022NIST Privacy FrameworkISO/IEC 27701:2025GDPRDigital Personal Data Protection Act 2023Services in This Area
13 services- 01ISO 27001Build and certify your information security management system.
- 02ISO 27701Build a certifiable privacy information management system.
- 03ISO 22301Certify how your business keeps running through disruption.
- 04ISO 42001Govern your AI systems with the first AI management standard.
- 05DPDP ActGet ready for India's Digital Personal Data Protection Act.
- 06PCI DSSProtect cardholder data and pass your PCI assessment.
- 07HIPAAProtect health information and meet HIPAA requirements.
- 08SOC 2Earn a SOC 2 report your customers can trust.
- 09CCPAMeet California's consumer privacy requirements.
- 10GDPRMeet Europe's data protection standard with confidence.
- 11NEN 7510Certify information security for Dutch healthcare.
- 12EU AI ActPrepare for Europe's risk-based AI regulation.
- 13Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.
VAPT
Manual, Exploit-Driven Penetration Testing Across 7 Surfaces
Practice Area OverviewMeasured Against
PTESCVSS v4.0NIST SP 800-115OWASPWSTGOWASPASVSServices in This Area
7 services- 01Web ApplicationManual testing of your web apps against the OWASP WSTG
- 02Mobile ApplicationAndroid and iOS app testing against the OWASP MASVS
- 03APIREST, GraphQL and SOAP testing against the OWASP API Top 10
- 04Thick Client ApplicationDesktop app testing across binary, traffic and backend
- 05Network InfrastructureExternal and internal network testing with lateral movement
- 06IoT and EmbeddedDevice testing across firmware, hardware and radio
- 07CloudConfiguration and IAM testing across AWS, Azure and GCP
Secure Code Review (SCR)
We read the code that matters. Our engineers walk your authentication, authorization, payment and data-handling paths line by line, then confirm which findings are truly exploitable.
A practice area in its own right, with no sub-services beneath it.
What We Run
SemgrepSonarQubeCheckmarxSnyk CodeMeasured Against
- OWASPCode Review Guide
- OWASPASVS
- OWASPTop 10
- CWEMITRETop 25
Software Composition Analysis (SCA)
Most of your application is code you did not write. We inventory your open-source and third-party dependencies, map their known vulnerabilities, check their licenses, and generate the SBOM that ties it all together.
A practice area in its own right, with no sub-services beneath it.
What We Run
SnykOWASP Dependency-CheckTrivyGrypeMeasured Against
- OWASPDependency-Check
- OWASPCycloneDX
- SPDXLinux Foundation
- NIST SSDF (SP 800-218)
Hardening and Configuration Review
Benchmark-Based Configuration Hardening Across Cloud, OS, Network and Data Tiers
Practice Area OverviewMeasured Against
NIST SP 800-53MSMicrosoftSecurity BaselinesMITRE ATT&CKVENDORHardening GuidesCISAWS FoundationsServices in This Area
5 services- 01Cloud Security Configuration AssessmentBenchmark review of your AWS, Azure and GCP accounts against secure baselines
- 02Operating System Hardening ReviewBenchmark comparison of your Windows and Linux builds against CIS and STIG baselines
- 03Firewall and Perimeter ReviewRule-base and configuration review of your firewalls, VPNs and edge devices
- 04Active Directory and Domain Controller AuditSecurity review of your AD forest, domain controllers and privilege paths
- 05Database and Web Server ConfigurationHardening review of your databases and web servers against CIS Benchmarks
Managed Services
Ongoing Offensive, Defensive and Advisory Security Run by Our Team
Practice Area OverviewMeasured Against
MITRE ATT&CKDPDPIndiaActISO/IEC 27001:2022NIST SP 800-50SANSAwareness Maturity ModelServices in This Area
9 services- 01Red Team AssessmentGoal-based adversary simulation across people, process and technology
- 02SOC as a ServiceA 24/7 security operations centre run by our analysts
- 03Attack Surface ManagementRecurring discovery of what you expose to the internet, and what is wrong with it
- 04Dark Web MonitoringAnalyst-validated monitoring for leaked credentials, documents and brand abuse
- 05vCISOSenior security leadership on demand, without a full-time hire
- 06vDPOA data protection officer as a service for the DPDP Act and beyond
- 07Phishing SimulationsSafe, realistic phishing tests that build lasting instincts
- 08Awareness TrainingsSecurity training your people actually remember and use
- 09Digital and Cyber ForensicsSound investigation and evidence when something has gone wrong
We know we need something. Which service should we start with?
Start with whatever is blocking a deal, an audit or a release, because that usually settles the order of everything else. If a customer or a regulator has named a framework, the compliance programme comes first and the testing follows the scope it defines. If you are shipping software and nobody has asked you for a certificate yet, a manual penetration test of your main application tells you more about your real exposure than any policy set would. If an auditor has already found gaps, a hardening and configuration review is often the cheapest way to close them. You do not have to decide this alone, and you should not guess: the scoping call exists precisely to work out which of the six practice areas answers the question in front of you. We will say plainly when the honest answer is that you need less work than you asked for.
What is the difference between VAPT and compliance, and do we need both?
They answer different questions and they are strongest together. A compliance programme such as ISO 27001, SOC 2, PCI DSS or DPDP Act readiness proves that you manage security deliberately: policies, ownership, risk decisions and evidence an auditor can follow. A penetration test proves whether the systems you actually run hold up when somebody tries them by hand. One without the other leaves a gap you can feel. Certified organisations still ship exploitable applications, and a clean test report does nothing for a procurement questionnaire. Most frameworks require testing outright, so the two meet on the evidence anyway: the test report becomes a control artefact, and the fixes it drives become your change record. We usually run them on one control set and one evidence trail rather than as two projects, so a single access review or retest answers several requirements at once instead of being repeated for each.
How does an engagement run from the first call to the closing report?
It begins with a scoping call, usually 30 to 45 minutes, with the people who would do the work rather than an account manager. We ask what you run, who is asking you for what, and what has already been tried. You then get a written scope with a timeline and a fixed price, so the commercial question is settled before anything starts. From there the work is done by hand: testing is manual, findings reach you as they are confirmed rather than being held back for the report, and each one carries specific remediation guidance. Your engineers can talk to ours while the fixes land. When you tell us the fixes are in, we retest to confirm each closure, and that retest is part of the engagement rather than a separate invoice. Compliance programmes run the same way, with evidence assembled as we go so the audit is not a scramble at the end.
How quickly can work start?
Faster than most people expect, and the limit is usually scope rather than our calendar. The scoping call can normally be held within a few days of you asking for one, and the written scope, timeline and price follow it quickly. Once you accept that scope, the start date depends mainly on what has to be in place first: test accounts, environment access, a change window if the systems are in production, or a document set if the engagement is a compliance programme. We will tell you on the call what those prerequisites are, so nothing surprises you afterwards. If something is genuinely urgent, say so on the call and we will tell you honestly whether we can meet it rather than accepting the date and missing it later. We would rather turn down a deadline than take one we cannot hold.
Do you work with teams outside Delhi NCR?
Yes. Our registered office is in Kanpur and we work from Greater Noida West, but the work itself is not tied to either. Testing, compliance programmes and managed services are delivered remotely for clients across India and beyond it, and that is how most engagements run: the scoping call, the working sessions with your engineers and the walkthrough of findings all happen the same way regardless of where your team sits. Where an engagement genuinely needs somebody on site, an internal network assessment or a physical review of a facility, we plan those visits into the scope and the timeline before you sign, rather than adding travel afterwards. SecureRoot Risk Advisory is certified to ISO/IEC 27001:2022 and ISO 9001:2015, so the way we handle your data and run an engagement is the same wherever you are. Distance changes the logistics, not the method.
Tell Us What You Need to Prove
An auditor's finding, a customer's security questionnaire, a board asking about the last penetration test. Start anywhere and we will scope the smallest piece of work that answers it properly.