
Think like the attacker. Engineer like the architect.
VAPT, red teaming, and adversary simulation — one practice spanning 136 services and every attack surface, made simple by three questions: what we test, how far we push, and how you buy it.
136
Services in the portfolio
0
False positives reported
83
Banking & FSI-specific tests
How it works
Every engagement is three simple choices
The catalog only looks vast because these three questions get tangled together. Separate them, and it's navigable.
What we test
The attack surface — network, application, cloud, specialized, human, or the Banking & FSI deep vertical.
How far we push
The depth ladder — from vulnerability assessment through penetration test and red team to continuous validation.
How you buy it
The commercial model — a fixed-scope engagement, a pool of bulk mandays, or a continuous subscription.
Your industryjust pre-selects sensible defaults across all three — which is why Banking & FSI, our deepest sector, has its own dedicated coverage.
The full catalog
All 136 services, one filter away
Filter by what you need tested and how far you want to go — or search the whole portfolio.
Who it’s for — industry
What we test — attack surface
How far we push — depth
Showing 12 of 27
Found what you need?
Turn a service into a scoped engagement
Send us the target and the outcome you're after. We'll respond with surface, depth, method, and timeline — an engineer's answer, not a pitch deck.
Start here
Guided engagements
Don't want to assemble tests from the catalog? These packaged plays are how most teams start — scoped for a specific moment, with one SOW and one timeline.
Bank CSM Foundation
8–12 weeksTier-2/3 Bank
Banks needing baseline POJK 11 readiness with a board-ready maturity uplift.
Included
- External + Internal Pentest
- Web + Mobile Banking VAPT
- Phishing Simulation
- OJK POJK 11 Gap
- Active Directory Assessment
Bundled CSM Score uplift report — board-ready.
Fintech Pre-Launch
4–6 weeksFintech / Digital Bank / P2P
Pre-launch fintechs needing OJK/BI sign-off and audit-ready evidence.
Included
- Web + API + Mobile Pentest
- Cloud Config Assessment
- Phishing Simulation
- Threat Model
Single SOW, single timeline — built for product-led firms.
Payment Rail Onboarding
5–8 weeksBank / PSP integrating BI rails
Firms onboarding BI-FAST or SNAP under tight regulator timelines.
Included
- BI-FAST or SNAP API VAPT
- Mobile Pentest
- OAuth / FAPI Review
- HSM Review
Indonesia-only specialism — first-mover.
SWIFT Annual + Threat-Led
8–12 weeksSWIFT-connected bank
Banks under the annual CSP cycle who want real validation, not just attestation.
Included
- SWIFT CSP CSCF Assessment
- SAA / SAG Audit
- Assumed-Breach vs SWIFT Zone
- Tabletop Exercise
Validation beyond CSP attestation — board-grade output.
Ransomware Resilience
6–10 weeksBank / Critical Infra
Boards demanding a ransomware readiness posture after an industry incident.
Included
- Ransomware Readiness Assessment
- Tabletop Exercise
- Backup / Recovery Validation
- AD Tier Review
Recovery-focused, not just defense.
AI Launch Safe
4–6 weeksFirm deploying LLM / agentic AI
Teams launching customer-facing or agentic AI in regulated contexts.
Included
- LLM App Pentest
- AI/ML Model Security
- Threat Model
- OWASP LLM Coverage Map
First-mover — Indonesia AI-security specialism.
OT / Critical Infra Foundation
6–10 weeksBSSN-designated CII operator
Critical-infrastructure operators needing a first technical baseline.
Included
- OT / ICS Assessment
- Network Segmentation Test
- AD Assessment
- Phishing Simulation
- Architecture Review
Sovereign critical-infra specialism.
CTEM Subscription
AnnualMature security program
Firms moving from annual VAPT to continuous, always-on validation.
Included
- External Attack Surface Management
- Breach & Attack Simulation
- Quarterly Pentest Rotation
- Detection Engineering Validation
- Quarterly Board Report
Always-on validation — not a point-in-time snapshot.
Axis 2 · How far we push
One depth ladder, not separate products
Red Team isn't a different thing from VAPT — it's the deep end of the same discipline.
Vulnerability Assessment
Find and prioritize known weaknesses across the surface. Breadth first.
VAPenetration Test
Exploit them the way an attacker would — black, grey, or white box. Proof, not just presence.
PTRed Team
Objective-based, covert, full-scope. People, process, and technology tested as one.
Full-scopePurple Team
Red and blue in the same room — every attack turned into detection engineering uplift.
Red + BlueContinuous
BAS and CTEM — stop testing once a year, validate every TTP every week.
Always-onInside a penetration test · the “box” models
“Box” simply means how much we’re told before we start. It’s a choice within a pentest, not a separate service.
Black box
Zero prior knowledge — we start where a real external attacker starts.
Grey box
Partial knowledge or a low-privilege account — the assumed-breach reality.
White box
Full access to source, architecture, and credentials — maximum depth per day.
Axis 3 · How you buy it
Three commercial models
Fixed-scope engagement
One target, one statement of work, one report. The classic pentest.
Best for annual compliance & point-in-time assurance
Bulk mandays
A pool of expert days you draw down across many tests through the year, at a locked rate.
Best for programs with continuous, varied testing needs
Continuous subscription
CTEM / BAS — always-on validation with quarterly rotation and detection engineering.
Best for mature SOCs moving beyond annual testing
Map to your regulation
What your regulator requires — and the tests that satisfy it
Regulated buyers arrive with a mandate, not a shopping list. Here's how the obligations you answer to map to Zentara services.
Indonesia
OJK
POJK 11/2022 — IT for Commercial Banks
Annual + ad hoc
Cyber risk & resilience framework, ITRM, third-party and incident response.
External/Internal Pentest, Web/Mobile VAPT, POJK 11 maturity, resilience testing
OJK
POJK 10/2022 — P2P Lending (LPBBTI)
Annual
IT systems, data protection, and control standards for P2P lenders.
P2P Platform VAPT, Web/API Pentest, e-KYC test
Bank Indonesia
QRIS · BI-FAST · SNAP
Onboarding + periodic
Payment-rail participant security, settlement integrity, standardized open APIs.
QRIS / BI-FAST / SNAP API VAPT, OAuth/FAPI review, mobile pentest
BSSN
Critical Information Infrastructure
Continuous
Elevated cyber requirements for designated CII operators.
OT/ICS assessment, segmentation validation, architecture review
UU PDP
Personal Data Protection Law
Continuous
Data controller/processor obligations and breach notification.
Privacy impact + technical testing, data-exposure assessment
Regional
MAS
TRM Guidelines (Singapore)
Annual
Technology risk management — pentest and threat-led testing for systemic firms.
Pentest, adversarial attack simulation (ART), red team
Global
PCI SSC
PCI DSS v4.0 — Req 11.4
Annual + 6-monthly segmentation
Mandatory annual testing of the cardholder data environment.
PCI 11.4 internal/external/segmentation/app pentest, HSM review
SWIFT
Customer Security Programme (CSP)
Annual
Annual attestation against CSCF; community-standard assessment.
SWIFT CSP CSCF assessment, environment pentest, assumed-breach
EU
DORA — Digital Operational Resilience
Continuous
ICT risk, third-party, and threat-led testing for designated firms.
TLPT (TIBER-EU aligned), third-party pentest, resilience testing
ISO / IEC
27001:2022 (+27017 / 27018)
3-year cycle
ISMS framework with cybersecurity and cloud-security technical evidence.
Technical testing evidence, config audit, gap assessment
What you receive
A report your board and your engineers can both act on
Every engagement ships a dual-layer report — an executive risk narrative and a per-finding technical breakdown with CVSS v3.1 scoring, proof-of-concept, and remediation. Delivered as DOCX + PDF, with a retest report to prove closure. Sample below uses fictional data.
Layer 1 · Executive summary
Risk posture at a glance
68
/100
Resilience score
Moderate exposure — two critical findings require action before the next release.
23 findings · CVSS v3.1
Compliance mapping: ISO 27001 · NIST CSF · BSSN · PCI DSS 11.4 — traceable per finding.
Layer 2 · Technical findings
Broken Object-Level Authorization (BOLA) on transfer API
Critical · 9.1Affected asset
POST /api/v2/accounts/{id}/transfer
Proof of concept
$ curl -H "Authorization: Bearer <userA>" \
-X POST /api/v2/accounts/80421/transfer \
-d '{"to":"attacker","amount":50000}'
→ 200 OK { "status": "settled" } # account 80421 belongs to userBBusiness impact
An authenticated low-privilege user can enumerate account IDs and initiate transfers from accounts they do not own — direct financial loss and regulatory-reportable breach.
Remediation
Enforce server-side ownership checks on every object reference; bind the account to the authenticated principal, not the request body.
Compliance deadline or board ask?
Get a compliance-mapped scope in days, not weeks
Tell us the regulation you answer to. We'll map it to the right tests and come back with a scope your auditors and board will accept.
Deep dives
Flagship engagements
Where a specific discipline earns a page of its own.

The practice
Certified operators. Zero false positives.
Every finding is manually validated and reproduced by a certified operator before it reaches your report. Automated tooling discovers; humans confirm.
Delivered by certified operators
FAQ
Common questions
Straight answers. If yours isn't here, ask us directly.
They're points on one depth ladder, not separate products. A vulnerability assessment finds weaknesses; a penetration test exploits them to prove impact; a red team runs an objective-based, covert, full-scope campaign against people, process, and technology together. VAPT is assessment plus pentest combined — the foundation the rest builds on.
Scope an offensive engagement
Tell us what you're protecting and how far you want us to push. We'll respond with surface, depth, method, and timeline.