ZENTARA
The adversary's side of the screen — hooded operator at red-lit displays
VAPT & Offensive Security

Think like the attacker. Engineer like the architect.

VAPT, red teaming, and adversary simulation — one practice spanning 136 services and every attack surface, made simple by three questions: what we test, how far we push, and how you buy it.

136

Services in the portfolio

0

False positives reported

83

Banking & FSI-specific tests

How it works

Every engagement is three simple choices

The catalog only looks vast because these three questions get tangled together. Separate them, and it's navigable.

1

What we test

The attack surface — network, application, cloud, specialized, human, or the Banking & FSI deep vertical.

2

How far we push

The depth ladder — from vulnerability assessment through penetration test and red team to continuous validation.

3

How you buy it

The commercial model — a fixed-scope engagement, a pool of bulk mandays, or a continuous subscription.

Your industryjust pre-selects sensible defaults across all three — which is why Banking & FSI, our deepest sector, has its own dedicated coverage.

The full catalog

All 136 services, one filter away

Filter by what you need tested and how far you want to go — or search the whole portfolio.

Who it’s for — industry

What we test — attack surface

How far we push — depth

Showing 12 of 33

Found what you need?

Turn a service into a scoped engagement

Send us the target and the outcome you're after. We'll respond with surface, depth, method, and timeline — an engineer's answer, not a pitch deck.

Start here

Guided engagements

Don't want to assemble tests from the catalog? These packaged plays are how most teams start — scoped for a specific moment, with one SOW and one timeline.

Bank CSM Foundation

8–12 weeks

Tier-2/3 Bank

Banks needing baseline POJK 11 readiness with a board-ready maturity uplift.

Included

  • External + Internal Pentest
  • Web + Mobile Banking VAPT
  • Phishing Simulation
  • OJK POJK 11 Gap
  • Active Directory Assessment

Bundled CSM Score uplift report — board-ready.

Fintech Pre-Launch

4–6 weeks

Fintech / Digital Bank / P2P

Pre-launch fintechs needing OJK/BI sign-off and audit-ready evidence.

Included

  • Web + API + Mobile Pentest
  • Cloud Config Assessment
  • Phishing Simulation
  • Threat Model

Single SOW, single timeline — built for product-led firms.

Payment Rail Onboarding

5–8 weeks

Bank / PSP integrating BI rails

Firms onboarding BI-FAST or SNAP under tight regulator timelines.

Included

  • BI-FAST or SNAP API VAPT
  • Mobile Pentest
  • OAuth / FAPI Review
  • HSM Review

Indonesia-only specialism — first-mover.

SWIFT Annual + Threat-Led

8–12 weeks

SWIFT-connected bank

Banks under the annual CSP cycle who want real validation, not just attestation.

Included

  • SWIFT CSP CSCF Assessment
  • SAA / SAG Audit
  • Assumed-Breach vs SWIFT Zone
  • Tabletop Exercise

Validation beyond CSP attestation — board-grade output.

Ransomware Resilience

6–10 weeks

Bank / Critical Infra

Boards demanding a ransomware readiness posture after an industry incident.

Included

  • Ransomware Readiness Assessment
  • Tabletop Exercise
  • Backup / Recovery Validation
  • AD Tier Review

Recovery-focused, not just defense.

AI Launch Safe

4–6 weeks

Firm deploying LLM / agentic AI

Teams launching customer-facing or agentic AI in regulated contexts.

Included

  • LLM App Pentest
  • AI/ML Model Security
  • Threat Model
  • OWASP LLM Coverage Map

First-mover — Indonesia AI-security specialism.

OT / Critical Infra Foundation

6–10 weeks

BSSN-designated CII operator

Critical-infrastructure operators needing a first technical baseline.

Included

  • OT / ICS Assessment
  • Network Segmentation Test
  • AD Assessment
  • Phishing Simulation
  • Architecture Review

Sovereign critical-infra specialism.

CTEM Subscription

Annual

Mature security program

Firms moving from annual VAPT to continuous, always-on validation.

Included

  • External Attack Surface Management
  • Breach & Attack Simulation
  • Quarterly Pentest Rotation
  • Detection Engineering Validation
  • Quarterly Board Report

Always-on validation — not a point-in-time snapshot.

Axis 2 · How far we push

One depth ladder, not separate products

Red Team isn't a different thing from VAPT — it's the deep end of the same discipline.

01

Vulnerability Assessment

Find and prioritize known weaknesses across the surface. Breadth first.

VA
02

Penetration Test

Exploit them the way an attacker would — black, grey, or white box. Proof, not just presence.

PT
03

Red Team

Objective-based, covert, full-scope. People, process, and technology tested as one.

Full-scope
04

Purple Team

Red and blue in the same room — every attack turned into detection engineering uplift.

Red + Blue
05

Continuous

BAS and CTEM — stop testing once a year, validate every TTP every week.

Always-on

Inside a penetration test · the “box” models

“Box” simply means how much we’re told before we start. It’s a choice within a pentest, not a separate service.

Black box

Zero prior knowledge — we start where a real external attacker starts.

Grey box

Partial knowledge or a low-privilege account — the assumed-breach reality.

White box

Full access to source, architecture, and credentials — maximum depth per day.

Axis 3 · How you buy it

Three commercial models

Fixed-scope engagement

One target, one statement of work, one report. The classic pentest.

Best for annual compliance & point-in-time assurance

Bulk mandays

A pool of expert days you draw down across many tests through the year, at a locked rate.

Best for programs with continuous, varied testing needs

Continuous subscription

CTEM / BAS — always-on validation with quarterly rotation and detection engineering.

Best for mature SOCs moving beyond annual testing

Map to your regulation

What your regulator requires — and the tests that satisfy it

Regulated buyers arrive with a mandate, not a shopping list. Here's how the obligations you answer to map to Zentara services.

Indonesia

OJK

POJK 11/2022 — IT for Commercial Banks

Annual + ad hoc

Cyber risk & resilience framework, ITRM, third-party and incident response.

External/Internal Pentest, Web/Mobile VAPT, POJK 11 maturity, resilience testing

OJK

POJK 10/2022 — P2P Lending (LPBBTI)

Annual

IT systems, data protection, and control standards for P2P lenders.

P2P Platform VAPT, Web/API Pentest, e-KYC test

Bank Indonesia

QRIS · BI-FAST · SNAP

Onboarding + periodic

Payment-rail participant security, settlement integrity, standardized open APIs.

QRIS / BI-FAST / SNAP API VAPT, OAuth/FAPI review, mobile pentest

BSSN

Critical Information Infrastructure

Continuous

Elevated cyber requirements for designated CII operators.

OT/ICS assessment, segmentation validation, architecture review

UU PDP

Personal Data Protection Law

Continuous

Data controller/processor obligations and breach notification.

Privacy impact + technical testing, data-exposure assessment

Regional

MAS

TRM Guidelines (Singapore)

Annual

Technology risk management — pentest and threat-led testing for systemic firms.

Pentest, adversarial attack simulation (ART), red team

Global

PCI SSC

PCI DSS v4.0 — Req 11.4

Annual + 6-monthly segmentation

Mandatory annual testing of the cardholder data environment.

PCI 11.4 internal/external/segmentation/app pentest, HSM review

SWIFT

Customer Security Programme (CSP)

Annual

Annual attestation against CSCF; community-standard assessment.

SWIFT CSP CSCF assessment, environment pentest, assumed-breach

EU

DORA — Digital Operational Resilience

Continuous

ICT risk, third-party, and threat-led testing for designated firms.

TLPT (TIBER-EU aligned), third-party pentest, resilience testing

ISO / IEC

27001:2022 (+27017 / 27018)

3-year cycle

ISMS framework with cybersecurity and cloud-security technical evidence.

Technical testing evidence, config audit, gap assessment

What you receive

A report your board and your engineers can both act on

Every engagement ships a dual-layer report — an executive risk narrative and a per-finding technical breakdown with CVSS v3.1 scoring, proof-of-concept, and remediation. Delivered as DOCX + PDF, with a retest report to prove closure. Sample below uses fictional data.

Zentara_VAPT_Report_[CLIENT]_2026.pdf — sampleConfidential

Layer 1 · Executive summary

Risk posture at a glance

68

/100

Resilience score

Moderate exposure — two critical findings require action before the next release.

23 findings · CVSS v3.1

Critical
2
High
5
Medium
9
Low
7

Compliance mapping: ISO 27001 · NIST CSF · BSSN · PCI DSS 11.4 — traceable per finding.

Layer 2 · Technical findings

Broken Object-Level Authorization (BOLA) on transfer API

Critical · 9.1

Affected asset

POST /api/v2/accounts/{id}/transfer

Proof of concept

$ curl -H "Authorization: Bearer <userA>" \
    -X POST /api/v2/accounts/80421/transfer \
    -d '{"to":"attacker","amount":50000}'
→ 200 OK  { "status": "settled" }   # account 80421 belongs to userB

Business impact

An authenticated low-privilege user can enumerate account IDs and initiate transfers from accounts they do not own — direct financial loss and regulatory-reportable breach.

Remediation

Enforce server-side ownership checks on every object reference; bind the account to the authenticated principal, not the request body.

Executive summary + resilience scoreCVSS v3.1 per findingProof-of-concept evidencePrioritized remediation roadmapFree retest & closure report

Compliance deadline or board ask?

Get a compliance-mapped scope in days, not weeks

Tell us the regulation you answer to. We'll map it to the right tests and come back with a scope your auditors and board will accept.

The ZENTARA wall — red marble, Jakarta headquarters

The practice

Certified operators. Zero false positives.

Every finding is manually validated and reproduced by a certified operator before it reaches your report. Automated tooling discovers; humans confirm.

Delivered by certified operators

OSCPOSEPOSWEOSEDOSMROSCECRTOGXPNGPENGWAPTCEHCKSAWS SecurityPCI HSM / PINSWIFT CSP

FAQ

Common questions

Straight answers. If yours isn't here, ask us directly.

They're points on one depth ladder, not separate products. A vulnerability assessment finds weaknesses; a penetration test exploits them to prove impact; a red team runs an objective-based, covert, full-scope campaign against people, process, and technology together. VAPT is assessment plus pentest combined — the foundation the rest builds on.

Scope an offensive engagement

Tell us what you're protecting and how far you want us to push. We'll respond with surface, depth, method, and timeline.