SIRI Security — Exact Header + WhatsApp Widget (verbatim extract)
CREST VAPT | Security Testing (VAPT) — SIRI Security
Security Testing (VAPT) › CREST VAPT

CREST VAPT — Penetration testing to the standard regulators and auditors recognise

Some regulators, insurers, and enterprise clients specifically require testing performed to CREST-aligned methodology. SIRI Security runs engagements against that standard, with the documentation and rigor to satisfy the auditor asking for it.

62%Of cloud detections
70%Of malware detections
29.44LIncidents CERT-In handled
Why testing evidence is now a named requirement
Live tracking · scroll to see every relevant change
Effective
31 JUL 2026
RBI's 2026 Framework requires commercial banks to run and evidence regular security testing as part of a continuous assurance programme, not a one-off exercise.
Named standard
OWASP TOP 10
Application and API testing scoped against the current OWASP Top 10 and OWASP ASVS remains the reference baseline auditors and regulators expect to see.
Growing gap
62% CLOUD
Cloud misconfiguration and IAM exploitation account for 62% of detections in cloud environments (DSCI) — testing scoped to on-premises infrastructure alone misses most of current risk.
Baseline
70% MALWARE
Trojans and file infectors make up 70% of malware detections (Seqrite 2026) — the entry point most exploitation testing has to account for.
Evidentiary bar
6 HR WINDOW
CERT-In's breach-notification window depends on already knowing your exposure — tested, documented findings are what makes that deadline realistic to meet.

Testing evidence, not a scan report

What is CREST-aligned VAPT?

CREST (the Council of Registered Ethical Security Testers) sets a globally recognised methodology and code of conduct for penetration testing. Where a regulator, cyber insurer, or enterprise customer specifically requires CREST-aligned testing — common in BFSI, insurance, and cross-border engagements — the engagement needs to follow that methodology precisely and be documented accordingly.

We scope, execute, and report CREST-aligned engagements end to end: structured methodology across reconnaissance, exploitation, and reporting, with the audit trail and evidence package your compliance or insurance team can hand directly to whoever is asking for it.

Scanners find the obvious; testers find what gets you breached
62% of cloud detections trace to misconfiguration and IAM exploitation (DSCI) — exactly the class of issue automated scanning alone tends to miss.

SIRI Security delivers CREST VAPT to this standard directly — practitioner-led, documented, and connected to SIRI Law LLP's legal and regulatory response if a finding ever needs to go further.

What organisations get wrong

Four assumptions that leave real exposure untested

A scanner report and a genuine security test are not the same evidence — and auditors increasingly know the difference.

01 — TOOLING

“We ran an automated scan, so we're covered”

Automated tools catch known signatures; they consistently miss business-logic flaws and chained vulnerabilities a human tester finds by thinking like an attacker.

02 — SCOPE

“Our last test covered the main system”

New features, integrations, and cloud services ship continuously — a test scoped a year ago doesn't speak to what's live today.

03 — EVIDENCE

“We fixed the findings, so we're done”

Without a documented retest, there's no evidence the fix actually worked — which is exactly what an auditor or insurer will ask for.

04 — FRAMING

“A clean report means we're secure”

A test result is a point-in-time statement about what was in scope — not a permanent guarantee, and not a substitute for ongoing monitoring.

What CREST VAPT covers

What's included, start to finish

Deployed once per engagement, documented to a standard auditors and insurers actually accept.

01

CREST-aligned methodology

Reconnaissance, exploitation, and reporting structured to the CREST framework, not an ad-hoc process.

    See Web Application VAPT →
    02

    Insurer & regulator-ready documentation

    Evidence and reporting formatted for the specific auditor or underwriter requesting it.

      See Mobile App Security →
      03

      Full audit trail

      Every test action logged and traceable, supporting later compliance or insurance review.

        See API Security Testing →
        04

        Cross-border engagement support

        Relevant where a global counterparty specifically mandates CREST-aligned testing.

          See Web Application VAPT →
          05

          Combined with any Assurance service

          CREST alignment can be applied to Web, Mobile, API, Network, or Cloud testing as needed.

            See Mobile App Security →

            Evidence, not guesswork

            Unscoped internal effort vs. a documented SIRI engagement

            The gap is rarely the tooling — it's whether the result holds up as evidence.

            ApproachNo dedicated testingAd hoc internal effortSIRI CREST VAPT
            MethodologyNoneVaries by who ran itOWASP / CREST-aligned, documented
            Manual exploitationNoRareIncluded as standard
            Evidence for auditors/insurersNoneInconsistentFormal report + CVSS ratings
            Retest on fixesN/ARarely trackedOne free retest cycle included
            Satisfies RBI/SEBI testing expectationsNoPartiallyYes, when scoped to your entity category

            Sources: RBI (Commercial Banks — Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026; OWASP Top 10; DSCI and Seqrite 2026 threat data. Summarised for comparison; confirm current testing obligations applicable to your entity category.

            Numbers every board should know

            What testing is actually catching

            62%

            Of cloud detections

            Trace to misconfiguration and IAM exploitation (DSCI) — the category testing has to explicitly cover.

            70%

            Of malware detections

            Are trojans and file infectors (Seqrite 2026) — the entry point most exploitation chains start from.

            29.44L

            Incidents CERT-In handled

            In the latest reporting year — the scale of activity testing exists to reduce a share of.

            6 HR

            CERT-In notification window

            Runs from discovery — tested, documented exposure is what makes that window realistic to meet.

            Why SIRI for CREST VAPT specifically

            Testing connected directly to legal and response, not a separate vendor

            The same roof runs the test, the fix verification, and — if a real finding turns into an incident — the legal response.

            01

            Findings connected directly to legal exposure

            SIRI Security runs under the same roof as SIRI Law LLP — when a finding carries real legal exposure, the engagement can be brought under attorney-client privilege from day one, not bolted on after the fact.

            02

            Led by named practitioners, not a rotating bench

            Vikram Rao, SIRI's Head of Cybersecurity, directs offensive security and incident response and leads CERT-In breach containment for enterprise clients.

            03

            Court-admissible evidence when it matters

            Ananya Krishnan, SIRI's Digital Forensics Lead, prepares court-admissible forensic reports and testifies as an expert witness when findings end up in front of a judge.

            04

            Built for RBI and SEBI's specific evidentiary bar

            Testing is scoped and documented to the standard RBI's 2026 Framework and SEBI's CSCRF expect from regulated entities, not a generic vendor template.

            Who this is built for

            Organisations this testing service is built for

            Banks & NBFCs SEBI-regulated intermediaries SaaS & cloud-native companies Enterprise vendors facing security questionnaires Organisations bringing new systems into production

            How we work

            From scoping to ongoing delivery

            01

            Scoping & Threat Modeling

            We map the in-scope environment attack surface with you, agree on rules of engagement, and build a threat model around what an attacker would actually go after first.

            Week 1
            02

            Manual + Automated Testing

            Our testers combine automated scanning with hands-on manual exploitation against the in-scope environment, since scanners alone miss business-logic and chained vulnerabilities.

            Weeks 2–3
            03

            Reporting & Risk Rating

            Every finding is written up with proof-of-concept, CVSS scoring, and business impact — not just a raw scanner export — so your team can prioritise by risk, not by noise.

            Week 4+
            04

            Remediation & Free Retest

            You fix the findings with our guidance, and we retest the fixed issues at no extra cost before issuing the final clearance report.

            Ongoing

            Frequently asked

            CREST VAPT, answered directly

            Who typically requires CREST-aligned testing?

            Cyber insurers, financial regulators, and enterprise clients in BFSI, insurance, and cross-border engagements most commonly mandate it.

            Can you apply this to an existing engagement type?

            Yes — CREST alignment is a methodology layer we can apply to Web, Mobile, API, Network, or Cloud testing rather than a separate test type on its own.

            How long does an engagement take?

            Most single-application or single-network engagements run 5 to 10 business days depending on scope, with the report and retest typically following within another week.

            Is the retest really included at no extra cost?

            Yes. One full retest cycle on the issues we found is included in every SIRI Security VAPT engagement — we don't charge again to confirm you fixed what we flagged.

            Close the evidence gap

            Scope CREST VAPT.

            Most engagements start with a short scoping call to confirm environment, timeline, and rules of engagement.

            Talk to SIRI Security: +91 79819 12046

            Visit or contact us

            SIRI Security — Hyderabad, India

            OfficeHITEC City, Madhapur, Hyderabad, Telangana 500081, India
            Telephone+91 79819 12046
            Emailcontact@sirisecurity.com
            Other officesNew Delhi, India · Austin, Texas, USA · Online worldwide
            HoursMon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7
            Scroll to Top