Comprehensive Security Testing by Certified Professionals
Vulnerability Assessment & Penetration Testing covering the full attack surface — web, mobile, network, API, cloud, and red team exercises — before attackers find the gap.
Data from leading industry reports that explain why regular security testing is not optional — it is essential.
Investment
From IDR 15 million
for a single small-scale web application using a grey box approach, including the full report and one verification retest.
Penetration testing at Cloudsphere starts at IDR 15 million for a single small-scale web application, including the technical report, executive summary, and one verification retest. The final price depends on the number of targets, the complexity of user roles, testing depth, and whether mobile, API, network, or red team testing is required.
One web application differs from a combination of web, two mobile platforms, and an API. Each target is scoped on its own.
02
User role complexity
Applications with many roles and layered authorisation flows require far longer horizontal and vertical access testing.
03
Testing depth
Black box, grey box, or white box. The more information and access provided, the deeper the findings we can reach.
04
Compliance requirements
Testing to satisfy OJK, Bank Indonesia, or an ISO 27001 audit requires mapping findings to controls and a specific report format.
The figure above covers testing and reporting. Fixing application-side vulnerabilities is done by your development team — we provide the technical recommendations and the verification retest.
Our VAPT service covers the entire modern attack surface — not just web applications, but your complete security ecosystem.
Red Team Exercise
Advanced
Long-term adversary simulation based on business objectives — not just finding gaps, but realistically testing your security team's detection and response capabilities.
Multi-vector AttackC2 SimulationLateral MovementObjective-basedPurple Team Ready
Methodology Approach
We tailor our testing approach to each client's context, objectives, and budget — every engagement is designed to deliver maximum value.
Black Box
The tester has no prior information about the target system. Simulates an attack by an unknown external adversary.
Advantages
Most realistic threat simulation
Findings reflect genuine external risk
Suitable for
External pentest, regulatory compliance testing
Grey Box
The tester is provided with partial information (user accounts, API documentation, or basic architecture). Most commonly used for web and mobile applications.
Advantages
Balance between realism and efficiency
Broader coverage within limited time
Suitable for
Web & mobile app testing, authenticated API testing
White Box
The tester receives full access to source code, system architecture, and technical documentation. Produces the most in-depth and comprehensive audit possible.
Our methodology follows industry standards PTES (Penetration Testing Execution Standard) and the OWASP Testing Guide for consistent, well-documented results.
01
Pre-Engagement & Scoping
Defining the testing scope, target systems, time constraints, and rules of engagement. Preparation of a written authorisation letter that protects both parties legally.
02
Reconnaissance & OSINT
Passive information gathering about the target — subdomains, technologies in use, email addresses, leaked configurations, public breach data, and initial attack surface mapping.
03
Scanning & Enumeration
Active port scanning, service enumeration, technology fingerprinting, software version identification, and mapping of endpoints and services running on the target.
04
Vulnerability Analysis
Identifying vulnerabilities through a combination of automated scanning and manual testing — validating false positives and prioritising by genuine risk (CVSS scoring).
05
Exploitation
Exploiting validated vulnerabilities with documented Proof of Concept — demonstrating real-world impact without disrupting the integrity of production systems.
06
Post-Exploitation (Where Applicable)
For network/infrastructure testing: privilege escalation, lateral movement, and assessment of further impact potential if an attacker gains an initial foothold.
07
Reporting & Remediation Support
Delivery of a comprehensive report with an Executive Summary and Technical Finding Report — including CVSS ratings, exploitation evidence, and actionable remediation recommendations.
What You Receive
Every engagement produces a comprehensive set of deliverables — not just a list of CVEs, but actionable insight.
Internationally Certified Team
Every pentest is conducted by a team holding globally recognized industry certifications — not just those who learned from online tutorials.
We also apply peer review among team members for every engagement so that no finding is missed due to individual blind spots.
OSCP
Offensive Security Certified Professional
CEH
Certified Ethical Hacker — EC-Council
eWPT
eLearnSecurity Web Penetration Tester
CompTIA PenTest+
CompTIA Penetration Testing Certification
Security+
CompTIA Security+
When Does a Company Need Pentesting?
Pentesting is not only for large enterprises — it is an essential security practice relevant in the following situations.
Compliance
Indonesian Regulations That Require Security Testing
Most penetration tests in Indonesia are triggered by a regulatory obligation rather than an internal initiative. These are the rules that most often bring clients to us — and the form of testing each one calls for.
POJK 11/POJK.03/2022 & SEOJK 29/SEOJK.03/2022
Financial Services Authority (OJK)
Applies to
Commercial banks and OJK-supervised financial institutions.
What we do
Require periodic cyber resilience and security testing. We run the pentest with findings mapped to the SEOJK requirements and a report format ready to submit to the supervisor.
PBI 23/6/PBI/2021
Bank Indonesia
Applies to
Payment Service Providers (PJP): e-wallets, payment gateways, and fund transfer operators.
What we do
Requires IT risk management and security testing of payment systems. We test transaction flows, authorisation, and third-party integrations — not just the application surface.
GR 71/2019 & MoCI Regulation 5/2020
Ministry of Communication and Digital (Komdigi)
Applies to
Private-scope Electronic System Operators (PSE) required to register.
What we do
Require operators to maintain the reliability and security of their electronic systems and protect user data. Periodic pentesting is the most direct evidence that this obligation is met, not merely declared.
Law 27/2022 on Personal Data Protection
Statute
Applies to
Every personal data controller and processor in Indonesia.
What we do
Requires securing personal data and preventing unauthorised access. Our testing targets real data-leak paths — IDOR, weak access control, and exposed endpoints.
Presidential Regulation 95/2018 on SPBE
Government / BSSN
Applies to
Central and regional government agencies and their system providers.
What we do
Requires security for electronic-based government systems. We test public service applications and their supporting infrastructure with the same methodology as the private sector.
MoH Regulation 24/2022 on Electronic Medical Records
Ministry of Health
Applies to
Hospitals, clinics, and healthcare facilities connected to SATUSEHAT.
What we do
Requires securing electronic medical records and safe integration. We test medical record applications, patient portals, and the data exchange path into SATUSEHAT.
Cloudsphere is not a supervisory body and does not issue compliance statements. What we provide is technical testing evidence you can present to auditors, regulators, or business partners.
Before You Request a Proposal
The four pages prospective clients read most often before contacting us — market pricing, what to prepare, and how pentesting differs from a vulnerability assessment.
Frequently Asked Questions
Have specific questions about scope, methodology, or pricing? Reach our team via the contact page or footer.
Is it safe to conduct a pentest on a production system?
Yes, with proper pre-engagement. We establish strict rules of engagement before testing begins — including limits on permitted techniques, testing windows, and emergency procedures if systems are impacted. For critical systems, we always recommend testing in a staging environment first, followed by limited production testing.
How long does a pentest engagement take?
Duration depends on scope. A web application pentest typically requires 3–5 active testing days. Network & infrastructure assessments take 5–10 days. A red team exercise can run 2–4 weeks. After testing is complete, report preparation requires an additional 3–5 business days before delivery.
What is the difference between a Vulnerability Assessment and Penetration Testing?
A Vulnerability Assessment (VA) systematically identifies and classifies vulnerabilities — typically using automated tools with limited manual validation. Penetration Testing (PT) goes further by attempting to manually exploit identified vulnerabilities to prove real-world impact. Our VAPT service combines both for comprehensive results.
What information should be prepared before pentesting begins?
For black box: at minimum, a list of target domains, IPs, or applications along with a written authorisation letter. For grey box: additionally, active user accounts (various access levels), API documentation if available, and a basic architectural overview. For white box: full source code and system architecture diagrams. Our team will guide you through the pre-engagement checklist at kickoff.
Is there a confidentiality guarantee for findings and the pentest report?
Yes — every engagement is protected by a legally binding Non-Disclosure Agreement (NDA). Reports are delivered only to authorised parties within your organization. We never share, publish, or reference the technical details of your findings with any third party without your explicit consent.
How frequently should a company ideally conduct pentesting?
Industry standards and best practices recommend at least once per year. However, additional pentests are strongly advised before major feature launches, after infrastructure migrations, or following security incidents. Certain regulations such as POJK in the financial sector and PCI-DSS for payments mandate more specific testing frequencies.
Does Cloudsphere provide remediation assistance after the pentest?
Yes. In addition to the report with specific, actionable remediation recommendations, our team is available for technical Q&A sessions with your development team during the remediation period. Once fixes are in place, we conduct a retest to verify that every finding has been successfully closed and issue a formal retest report.
How much does penetration testing cost in Indonesia?
Penetration testing at Cloudsphere starts at IDR 15 million for a single small-scale web application, including the technical report, executive summary, and one retest. The Indonesian market range is typically IDR 15–75 million for small to medium applications, rising for complex applications, mobile, API, network, or red team engagements. The final price always follows the agreed scope.
Can a Cloudsphere pentest report be used to satisfy OJK or Bank Indonesia requirements?
Yes. POJK 11/POJK.03/2022 together with SEOJK 29/SEOJK.03/2022 require commercial banks to test cyber resilience and security periodically, and PBI 23/6/PBI/2021 imposes an equivalent duty on Payment Service Providers. We map findings to those requirements and produce the report in a format ready to submit to supervisors and auditors.
Are Electronic System Operators (PSE) in Indonesia required to run penetration tests?
GR 71/2019 and MoCI Regulation 5/2020 require operators to maintain the reliability and security of their electronic systems and protect user data, without prescribing one testing method. In practice, periodic penetration testing is the most direct evidence that the duty is actually being met — and it is what gets requested when an incident or audit occurs.
Products That Support This Service
Follow up on pentest findings in a structured way — record, escalate, and resolve security incidents in one platform.
Find the Gap Before Attackers Do
Get a pentest proposal tailored to your scope and budget. Free initial consultation, no obligation.