Skip to content
Ambara Digital Nusantara

FAQ

Frequently asked questions

Short answers to the questions we are asked most often. For anything specific to your organisation, contact us.

01

Working with ADN

What does ADN do?

ADN provides three connected service lines: cybersecurity (assessment, advisory, incident response and forensics), Odoo ERP and CRM (implementation, migration, customisation, integration, training and support), and IoT and industrial electronics (PCB design and assembly, telemetry, Odoo integration and OT security).

How does an engagement start?

With a scoping conversation. We agree objectives, scope, constraints and success criteria, then send a written proposal. No work starts before the proposal is accepted.

How is pricing determined?

Pricing depends on scope, effort and schedule. We quote after the scoping conversation, as a fixed price for defined deliverables or as a time-based estimate for work that cannot be fully defined in advance.

Will you sign a non-disclosure agreement?

Yes. A non-disclosure agreement can be signed before we receive any sensitive information.

Where do you work?

We are based in Jakarta and Tangerang Selatan. Advisory and assessment work can be delivered remotely or on site; on-site work outside Greater Jakarta is agreed per project.

02

Cybersecurity

What is the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment identifies and rates known weaknesses, largely with automated tools. A penetration test goes further: testers attempt to exploit weaknesses manually, including business-logic flaws that scanners do not find, to show the real impact.

Can ADN certify us for ISO/IEC 27001?

No. Certification is issued by an accredited certification body. We prepare organisations for certification through gap assessment, risk assessment, policies and control implementation support.

Can you help us comply with UU PDP?

Yes. We assess current practices against UU No. 27 Tahun 2022, prepare records of processing activities and DPIA templates, and help implement technical and organisational controls.

We have an active security incident. What should we do?

Call our main number and state that it is an incident. Preserve evidence where possible: do not wipe or rebuild affected systems before they have been assessed.

03

Odoo ERP and CRM

Do you work with Odoo Community or Enterprise?

Both. We recommend an edition after the fit-gap analysis, based on the modules and support you need.

Can you migrate our data from another system?

Yes. Migration covers data inventory, mapping, cleansing, trial loads and reconciliation with the source system before cut-over.

Is security part of an Odoo implementation?

Yes. User roles, record rules, audit trail settings, backups and server configuration are reviewed before go-live.

04

IoT and industrial electronics

Can machine data be connected to Odoo?

Yes. Field data can be connected to Odoo Manufacturing, Maintenance and Inventory through the Odoo IoT Box or the Odoo API, via an edge gateway where industrial protocols are involved.

Which protocols do you work with?

Commonly Modbus RTU and Modbus TCP, OPC UA and MQTT. Other protocols are assessed during discovery.

Which security standards do you reference for IoT and OT?

IEC 62443 for industrial systems, ETSI EN 303 645 and NIST IR 8259 for device baselines, and the OWASP IoT Top 10.

05

Pricing and packages

How much does a penetration test cost?

It depends on scope: the number of applications, roles, APIs and hosts. A web application penetration test starts from Rp 15 million. We quote a fixed price after a short scoping call.

What is included in the price of a penetration test?

Scoping, manual and tool-assisted testing, a technical report with evidence and fix steps, an executive summary, a findings presentation, and a retest of remediated findings.

How much does an Odoo implementation cost?

The SME package starts at Rp 30 million, the Business package at Rp 80 million, and larger projects are quoted by proposal. The Odoo subscription is paid to Odoo separately; see the Odoo pricing page for both.

Is the first consultation free?

Yes. The first scoping conversation is free and comes with no obligation. You receive a written proposal afterwards.

Can we start small?

Yes. Many clients start with a vulnerability assessment or a few core Odoo apps, then expand once the first phase is stable.

06

Technical and methodology

Which methodologies do you follow for penetration testing?

OWASP WSTG and ASVS for web applications, OWASP MASVS for mobile apps, PTES and NIST SP 800-115 for the overall test process, and MITRE ATT&CK to describe attacker techniques.

Is penetration testing safe for production systems?

Yes, with the right precautions. Rules of engagement define targets, exclusions and test windows; we keep an open line to your team during testing, and highly sensitive systems can be tested in staging instead.

How do you handle our sensitive data during an engagement?

We sign an NDA, use encrypted channels, collect only what the test needs, restrict access to the engagement team and delete working data at the end according to the agreed retention period.

We already have a SIEM. Do we have to switch to Wazuh?

No. We implement Wazuh when there is no SIEM yet. If you already run Microsoft Sentinel, Google SecOps (Chronicle), FortiSIEM, Elastic, or EDR/XDR such as Palo Alto Cortex XDR, SentinelOne and Trellix, we monitor and improve it on that platform.

Do you only use automated scanners?

No. Scanners help with coverage, but most valuable findings, such as business-logic and access-control flaws, come from manual testing.

Not answered here?