Skip to content
Ambara Digital Nusantara

01 · Cybersecurity

Security assessment and response, scoped to your risk.

We test, advise and respond across applications, infrastructure and data. Each engagement starts with an agreed scope and ends with findings your team can act on and verify.

InternetFirewallDMZInternal networkWeb appVAPTAPIVAPTOdoo ERPVAPTServerEndpointsSOC: log collection and detectionSOCIRFORENSICS
Where the services apply: penetration testing on exposed systems, monitoring across all zones, incident response and forensics wherever an event occurs.

01Why it matters

Cybersecurity is about keeping the business running.

A good security programme makes incidents less likely, limits their impact and speeds up recovery. This is what is at stake.

  • Operations stop

    Ransomware and outages stop sales, production and customer service.

  • Financial loss

    Recovery costs, lost revenue and follow-on costs that last for months.

  • Regulatory and contractual exposure

    UU PDP, sector regulators and client contracts require data protection and incident reporting.

  • Customer trust

    Damage to reputation outlasts the incident itself.

  • Third-party exposure

    Weaknesses at vendors, third-party apps or remote access can spread into your systems.

USD 4.44M

global average cost of a data breach

Source: IBM, Cost of a Data Breach Report 2025

30%

of breaches involved a third party, double the year before

Source: Verizon, Data Breach Investigations Report 2025

USD 10.5T

projected annual global cost of cybercrime by 2025

Source: Cybersecurity Ventures
most incidents start with something small

02Problems we solve

What are you dealing with right now?

Start from the problem. Each card leads to the service that solves it.

03Services

Five services, one reporting standard

Services can be combined. Findings from every service use the same severity scale and remediation format, so they can be tracked in one place.

01

Vulnerability assessment and penetration testing

Manual and tool-assisted testing of web applications, Android and iOS apps, desktop applications, APIs, networks, servers and VPN or remote access, followed by a retest to confirm remediation.

Service detail : Vulnerability assessment and penetration testing

Deliverables

  • Rules of engagement and test plan
  • Executive summary for management
  • Technical findings with CVSS severity, evidence and reproduction steps
  • Remediation guidance prioritised by risk
  • Retest letter confirming closed findings

References: OWASP WSTG, OWASP ASVS, OWASP API Security Top 10, PTES, CVSS v3.1 and v4.0

02

SOC and NOC advisory

Monitoring operations built on Wazuh, or run and improved on the SIEM you already have (Microsoft Sentinel, Google SecOps (Chronicle), FortiSIEM, Elastic, or EDR/XDR such as Palo Alto Cortex XDR, SentinelOne and Trellix): log sources, detection use cases, alert triage and escalation.

Service detail : SOC and NOC advisory

Deliverables

  • Log source and visibility assessment
  • Detection use-case catalogue mapped to MITRE ATT&CK
  • Triage and escalation runbooks
  • Staffing and coverage model options
  • Implementation roadmap

References: MITRE ATT&CK, NIST SP 800-92, NIST CSF 2.0 (Detect function)

03

Incident response

Support during and after a security incident: containment, eradication, recovery and lessons learned. Preparation work, such as playbooks and tabletop exercises, can be engaged before an incident occurs.

Service detail : Incident response

Deliverables

  • Incident response plan and playbooks
  • Tabletop exercise and after-action report
  • Containment and recovery support
  • Incident report with timeline and root cause
  • Support with UU PDP notification obligations where personal data is involved

References: NIST SP 800-61 Rev. 3, ISO/IEC 27035

04

GRC and compliance readiness

Gap assessment, policy development and control implementation support for ISO/IEC 27001 and UU No. 27 Tahun 2022 (PDP). We prepare organisations for certification or regulatory review; certification itself is issued by an accredited body.

Service detail : GRC and compliance readiness

Deliverables

  • Gap assessment against the selected framework
  • Risk assessment and treatment plan
  • Policy and procedure set
  • Statement of Applicability (ISO/IEC 27001)
  • Records of processing activities and DPIA templates (UU PDP)
  • Internal audit readiness review

References: ISO/IEC 27001:2022, ISO/IEC 27002:2022, UU No. 27 Tahun 2022

05

Digital forensics

Acquisition and analysis of digital evidence from endpoints, servers, cloud accounts and logs, with chain of custody maintained throughout.

Service detail : Digital forensics

Deliverables

  • Evidence acquisition with hash verification
  • Chain-of-custody records
  • Timeline and artefact analysis
  • Forensic report written for technical and non-technical readers

References: ISO/IEC 27037, NIST SP 800-86

04Methodology

How a security assessment runs

The sequence below applies to penetration testing. Other services follow the same principle: agreed scope, evidence-based findings, verified remediation.

  1. Scoping and authorisation

    Targets, test windows, exclusions and contacts are agreed in a signed rules-of-engagement document.

  2. Reconnaissance

    The attack surface is mapped from the information in scope: hosts, services, application routes and user roles.

  3. Testing

    Automated scanning is followed by manual testing of authentication, authorisation, business logic and data handling.

  4. Analysis and rating

    Each finding is validated, rated with CVSS and assigned a business impact. False positives are removed before reporting.

  5. Reporting and debrief

    Results are presented to technical and management audiences. Critical findings are reported immediately, not held for the final report.

  6. Retest

    Remediated findings are retested and their status is confirmed in writing.

05Sample outputs

What you receive

Every assessment report follows the same structure, so management and technical teams can each find what they need.

Executive summary
  • Overall risk picture in plain language
  • Number of findings by severity
  • Top remediation priorities
  • Recommended next steps for management
Technical findings
  • Description and affected assets
  • CVSS score and business impact
  • Evidence and reproduction steps
  • Specific remediation guidance
Remediation tracker
  • One line per finding with owner
  • Target date by severity
  • Status after the retest
  • Spreadsheet format your team can update

06Standards referenced

Frameworks we align to

  • ISO/IEC 27001:2022 and ISO/IEC 27002:2022
  • NIST Cybersecurity Framework 2.0
  • OWASP Web Security Testing Guide, ASVS, Top 10 and API Security Top 10
  • MITRE ATT&CK
  • NIST SP 800-61 Rev. 3 and ISO/IEC 27035 for incident handling
  • ISO/IEC 27037 and NIST SP 800-86 for digital evidence
  • UU No. 27 Tahun 2022 tentang Pelindungan Data Pribadi

07FAQ

Frequently asked questions

How long does a penetration test take?
It depends on the scope: the number of applications, user roles, endpoints and environments to test. We give a time estimate after a short scoping conversation.
Will testing disrupt our production systems?
The risk is low. Test windows and limits are agreed in the rules of engagement, and risky tests can run on staging or outside working hours.
What is the difference between a vulnerability assessment and a penetration test?
A vulnerability assessment finds and rates known weaknesses, mostly with automated tools. A penetration test goes further: testers try to exploit weaknesses manually, including business logic flaws that scanners miss, to show the real impact.
How much does it cost?
Prices depend on scope. Starting prices are listed on each service page, and the final price is confirmed after a short scoping conversation.
We are dealing with a security incident right now. What should we do?
Call our main number and say it is an incident. Preserve evidence where you can: do not wipe or rebuild affected systems before they have been assessed.
Can ADN issue an ISO/IEC 27001 certificate?
No. Certificates are issued by accredited certification bodies. We prepare your organisation for certification through gap assessment, risk assessment, policies and control implementation.

08Contact

Discuss a security engagement

Share the systems in scope and any deadlines, such as an audit or a product launch. We will propose a scope and a test window.

Request a scoping call