
There is a fundamental difference between being compliant and being secure. Compliance means satisfying the requirements of a framework — ISO 27001, SOC 2, PCI-DSS, RBI cybersecurity guidelines — at the point in time when an audit is conducted. Security means that your systems are genuinely difficult to breach today, against the actual techniques attackers are using. Penetration testing is the only meaningful way to measure the gap between these two states.
In India, the RBI has mandated annual VAPT (Vulnerability Assessment and Penetration Testing) for all scheduled commercial banks since 2019. SEBI extended similar requirements to market infrastructure institutions in 2023. IRDAI has issued cybersecurity guidelines requiring insurers to conduct VAPT on internet-facing systems at least twice annually.
The most sophisticated organisations go further. Red team operations — extended, adversary-simulation exercises in which a specialist team attempts to breach an organisation using the full range of techniques a real attacker would employ, including social engineering, physical access attempts, and zero-day exploitation — are becoming standard practice among financial institutions, critical infrastructure operators, and large technology companies.
The MOVEit transfer vulnerability exploited by the Cl0p ransomware group in 2023 affected over 2,000 organisations worldwide — including several that had SOC 2 compliance certifications but had not specifically tested their file transfer infrastructure. Many of those affected discovered the vulnerability because criminals found it before their security teams did.
Key Takeaway
The organisations that test themselves proactively choose their discomfort. The ones that don't have it chosen for them.
By Grey Platforms

Grey Platforms Private Limited
CIN: U62099OD2024PTC047119
Head Office:
Zone C, Ground Floor, Fortune Towers, Chandrasekharpur, Bhubaneswar, Odisha, 751023
Solutions
© Copyright Grey Platforms 2025