business@xdepthsense.com
+91 97695 13095  |  +91 98335 86361  |  +91 96197 39550
ANSWERS

Cybersecurity & Compliance FAQ

Straight answers to the questions clients ask most — about VAPT, SEBI CSCRF, DPDPA and working with us.

VAPT & penetration testing

What is the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment identifies and lists weaknesses across your systems — misconfigurations, missing patches, exposed services. A penetration test goes further: a tester manually exploits those weaknesses to prove real business impact, such as accessing data or taking over an account. XDepthSense delivers both together (VAPT), with every finding manually verified.

How long does a web application VAPT take?

A typical web application VAPT takes 5 to 10 working days depending on the number of pages, roles and APIs in scope, followed by reporting and a remediation retest. We scope the exact effort on a short discovery call.

Do you provide a retest after we fix the issues?

Yes. Every XDepthSense engagement includes a remediation retest — we re-examine each reported issue after your team applies fixes and confirm whether the risk is genuinely closed, then issue an attestation letter.

What methodologies do you follow?

Our testing follows the OWASP Web Security Testing Guide, PTES, the OWASP API Security Top 10, NIST 800-53 and MITRE ATT&CK. Testing is manual and methodology-driven, not automated scanner output.

SEBI CSCRF compliance

Does SEBI CSCRF require a VAPT?

Yes. Under SEBI's Cyber Security and Cyber Resilience Framework, regulated entities must run periodic VAPT. Mid-size, small-size and self-certification REs require an annual VAPT and an annual cyber audit; MIIs and Qualified REs test more frequently.

Is a CERT-In empanelled auditor mandatory under CSCRF?

It is mandatory for MIIs and Qualified REs. For mid-size, small-size and self-certification REs it is not mandated — those entities may engage a competent independent security firm, provided the testing is manual and methodology-driven.

How quickly must a SEBI-regulated entity report a cyber incident?

Cyber incidents must be reported to SEBI and CERT-In within 6 hours of detection.

DPDPA & data protection

Does the DPDPA apply to my business?

If your organisation processes the digital personal data of individuals in India — customers, users or employees — the DPDPA 2023 applies to you as a Data Fiduciary, regardless of company size.

What is the fastest way to start DPDPA readiness?

Begin with a data-flow map: list every place personal data enters, is stored and leaves your organisation. You cannot protect or lawfully process data you have not located. XDepthSense runs a fixed-scope DPDPA readiness assessment covering this.

Working with XDepthSense

Where is XDepthSense based?

XDepthSense LLP is based in Mumbai, India, at 603, 6th Floor, Nestle CHS, Shaikh Misree Road, Antop Hill, Mumbai 400037. We serve clients across India, the UAE, the UK and Australia.

What certifications does your team hold?

Our consultants hold certifications including OSCP, CRTE, CEH, CISM, CCSP, CISA, CISSP and ISO 27001 Lead Auditor. Engagements are led by senior professionals.

Can we see a sample report before engaging?

Yes. A redacted sample VAPT report is available to download from our site, showing our reporting format, depth of analysis and remediation guidance.

How do we get a quote?

Contact us through the website or email business@xdepthsense.com. We respond within one business day and scope the engagement on a short discovery call.

Still have a question?

Tell us what you need and we'll respond within one business day.