Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Practice Area7 services in this area
VAPT

VAPT Services

We test the way a real attacker would, by hand and with intent, not by handing you a scanner printout. You get findings we have proven, ranked by the damage they do, with a fix you can act on and a retest that confirms it is closed.

How We Work

VAPT with SecureRoot is people-led work backed by good tooling. We scope tightly with you, map the attack surface, then chase the flaws that actually chain into impact, from web and mobile apps to APIs, thick clients, networks, IoT devices and cloud accounts. Every finding carries a proof of concept, a business-language explanation and clear remediation, and we retest the fixes so you can show they hold.

Jump to the 7 Services

Services in VAPT

Manual, Exploit-Driven Penetration Testing Across 7 Surfaces

7 services in this practice area

Measured Against

PTESCVSS v4.0NIST SP 800-115OWASPWSTGOWASPASVSOWASPAPI Top 10OSSTMMISECOMCISBenchmarks

What We Run

Burp Suite ProfessionalNucleiGhidraWiresharkffufNmapFridaOWASP ZAP

How We Rank What We Find

Whichever surface the test covers, the findings land in the same queue and are ranked by whether they are being exploited in the wild.

VAPT

Worked example

A vulnerability management product view. Illustrative snapshot of a typical programme, not a named client. Headline figures for the quarter across 1,340 in-scope assets and 40 web applications: 4,812 open findings, of which 288 are past their internal SLA; 37 critical findings open; blended mean time to remediate 84 days, computed from the 3,371 closures this quarter, 24 critical at 21 days each, 391 high at 38, 2,100 medium at 74 and 856 low at 130, which is 282,042 finding-days over 3,371 closures; SLA compliance 68 percent, 2,292 of 3,371 closures within SLA. Open findings by CVSS v3.1 band: Critical 37, which is 0.8 percent; High 412, 8.6 percent; Medium 1,954, 40.6 percent; Low 2,409, 50.1 percent. A further 1,106 informational findings are excluded from that total. 19 open findings are listed on the CISA Known Exploited Vulnerabilities catalogue and 4 of those are past their CISA BOD 22-01 due date. Findings over 13 weeks: 2,993 new against 3,371 remediated, so the open backlog fell from 5,190 to 4,812, with a spike of 402 new findings in week 6 when the quarterly authenticated scan ran. Mean time to remediate by severity against target: Critical 21 days against a 15-day target, High 38 against 30, Medium 74 against 90, Low 130 against 180. The table lists 13 representative findings ranked by exploitability, led by CVE-2024-3400, GlobalProtect OS command injection, CVSS 10.0, EPSS 0.944, on KEV, 13 days old and open; CVE-2023-4966, NetScaler session token leak, CVSS 9.4, on KEV, 41 days old and in progress; and CVE-2021-44228, Log4j2 JNDI remote code execution on a legacy build host, CVSS 10.0, on KEV, 402 days old and still open.

SecureRoot VAPTVulnerability Management

4,812

Open

288 past SLA

37

Critical

19 on KEV

84d

MTTR

3,371 closed

68%

Within SLA

2,292 of 3,371

By Severity, 4,812 Open

Critical 37High 412Medium 1,954Low 2,409

19 on CISA KEV, 4 past their CISA due date.

Illustrative snapshot of a typical programme, not a named client.

Illustrative figures for a 1,340-asset estate. 4,812 open findings, 19 of them on the CISA Known Exploited Vulnerabilities catalogue, 4 already past their due date. The overdue rows stay on the board.

Every one of these is scoped, run and reported by the same team. See All Practice Areas

Not Sure Which of These You Need?

Tell us what you are being asked to prove, or what you are worried about. We will point you at the right piece of work, even when it is smaller than you expected.