Frequently Asked Questions
Common questions about Vulnera's services, methodology, and engagement process.
What types of security assessments do you offer?
+
Vulnera offers comprehensive security assessment services including:
- â Penetration Testing: External and internal network testing, application security, wireless assessments, social engineering
- â Red Team Exercises: Advanced adversarial simulations, multi-stage attacks, persistence testing
- â Web Application Security: Source code review, API security, OWASP testing
- â Mobile Security: iOS and Android application testing, mobile infrastructure
- â Cloud Security: AWS, Azure, GCP configuration and security assessment
- â Infrastructure Assessment: Network, systems, identity and access management
- â Compliance Assessments: ISO 27001, PCI-DSS, HIPAA, SOC 2 evaluations
Will testing cause downtime to our systems?
+
No. Our testing is carefully designed to avoid disruption:
- â Controlled Scope: We establish clear testing boundaries and rules of engagement before assessment begins
- â Non-Destructive: Our testing identifies vulnerabilities without damaging systems or data
- â Scheduled Coordination: We work during agreed-upon windows and maintain communication with your teams
- â Graceful Failure: If we identify a critical issue, we stop immediately and report it
- â Production systems are tested in a manner that validates real-world risk without operational impact
What certifications does your team hold?
+
Our team maintains industry-leading certifications:
- â CCNP Security (Cisco)
- â CREST-Level (Advanced Pen Testing)
- â CEH (Certified Ethical Hacker)
- â OSCP (Offensive Security)
- â FCSS (Google Cloud Security)
- â CISSP (Information Security)
- â AWS/Azure Security certifications
- â Continuous professional development
Certifications are maintained and renewed regularly. All team members commit to staying current with emerging threats and technologies.
What does a typical report include?
+
All Vulnera reports include:
- â Executive Summary: High-level overview, risk score, and key findings for non-technical stakeholders
- â Technical Findings: Detailed vulnerability descriptions, CVSS scores, evidence, and reproduction steps
- â Risk Scoring: CVSS v3.1 scoring and business risk prioritization
- â Remediation Guidance: Step-by-step instructions for fixing each vulnerability
- â Compliance Mapping: Correlation with ISO 27001, PCI-DSS, HIPAA, and other standards
- â Retest Validation: Free retesting to verify remediation effectiveness
- â Timeline & Recommendations: Prioritized remediation roadmap aligned with your business
Do you offer retesting?
+
Yes. Retesting is included free as part of every assessment:
- â Included Retesting: One full retest is included to verify remediation of all findings
- â Flexible Timing: Schedule retesting when remediation is complete (typically 30-60 days after report)
- â Same Tester: Original assessor conducts retesting for continuity and expertise
- â Additional Retests: Additional retests available at discounted rates if needed
- â Documentation: Closure report confirming remediation effectiveness provided
Do you work with banks and government?
+
Yes. We have extensive experience in highly regulated sectors:
- â Banking Sector: Trusted by banks and finance industries in Oman. PCI-DSS expertise.
- â Government & Public Sector: Proven experience with national agencies and critical infrastructure operators
- â Classified Environments: Clearance holders available for testing sensitive systems
- â Regulatory Knowledge: Deep understanding of banking regulations, national security requirements, and government compliance standards
- â Sensitive Handling: Strict confidentiality and secure data management for government and financial clients
Can you test our internal network?
+
Absolutely. We offer flexible deployment options:
- â VPN Access: Remote testing through secure VPN tunnel to your internal infrastructure
- â On-Site Testing: Physical presence at your facility for direct network access and social engineering
- â Hybrid Approach: Combination of remote and on-site assessment for comprehensive coverage
- â Air-Gapped Networks: Specialized protocols for testing isolated or classified networks
- â Scoping Call: We discuss your environment and determine the best testing approach
How long does a typical assessment take?
+
Assessment duration depends on scope and complexity:
- â Web Application: 1-2 weeks (depending on size and complexity)
- â Network Penetration Testing: 2-3 weeks (external + internal, typical enterprise)
- â Red Team / Full Simulation: 4-6 weeks (multi-stage, persistence-focused)
- â Compliance Assessment: 1-4 weeks (depending on framework and infrastructure size)
- â Reporting: 2-3 weeks from testing completion for comprehensive report and analysis
Timeline discussed and agreed upon during scoping call. Custom assessments may require different timeframes.
Is our data kept confidential?
+
Yes. Confidentiality is paramount:
- â NDA Coverage: Comprehensive non-disclosure agreement protecting all assessment data
- â Encrypted Communications: All findings, reports, and data transmitted over encrypted channels
- â Secure Storage: Assessment data stored in encrypted databases with access controls
- â Data Destruction: All assessment materials securely deleted after engagement concludes
- â No Third Parties: Your data is never shared with external vendors or intelligence services
- â Legal Compliance: Full GDPR and data protection regulation compliance
How do we get started?
+
Getting started is simple:
Initial Contact
Email sales@vulnera.om or fill out the contact form with your security assessment needs
Scoping Call
Schedule a 30-minute call to discuss your organization, infrastructure, and assessment objectives
Proposal & NDA
Receive detailed proposal with scope, timeline, and pricing. Execute NDA for data protection.
Assessment
Begin testing according to agreed scope, rules of engagement, and schedule
Reporting & Support
Receive comprehensive report with findings, guidance, and support for remediation
Didn't find your answer?
Contact our team directly for specific questions about your assessment needs.
Contact Us