VAPT and Penetration Testing for Singapore Companies
Budget Security delivers VAPT to Singapore companies as one scoped engagement: a vulnerability assessment of the in-scope systems, then manual penetration testing by OSCP-certified testers to confirm what is exploitable. Delivered remotely from The Hague, started within 7 days of booking, with every finding tracked in your dashboard and a report written for MAS TRM, Cyber Trust, PDPA, SOC 2 or ISO 27001 evidence.
Scope it in the platform and see the tester-day estimate first. Try the calculator or sign up.
If the terms VAPT and penetration testing get used interchangeably at your company, start with VAPT vs penetration testing. This page is about ordering one.
VAPT scope: what we assess and what we test
In the platform you register the assets, choose the goal and set a budget. The scoping engine returns a plan that separates the two halves of VAPT. The vulnerability assessment half covers discovery, weak configurations, exposed services and known-vulnerable components across everything in scope. The penetration testing half assigns tester-days to the assets where manual exploitation changes the answer: your customer-facing application, the APIs behind it, and the identity layer in your cloud accounts.
Assets we take into scope:
- Web application penetration testing: authenticated testing of business logic, authorisation and session management, the areas a scanner cannot judge.
- API penetration testing: REST, GraphQL and the partner and payment interfaces that carry your most sensitive calls.
- Cloud penetration testing: IAM, misconfiguration and privilege escalation in AWS, Azure and Google Cloud, including the Singapore regions.
- External and internal network penetration testing: the perimeter first, then lateral movement once inside over an authorised VPN.
- Mobile penetration testing: iOS and Android apps plus the backends they call.
The plan shows the trade-off live. Add a tester-day and the plan tells you which asset gets deeper coverage. Remove one and it tells you what is cut, and whether the scope still meets the goal you named.
MAS Technology Risk Management Guidelines: VA and PT for financial institutions
The MAS Technology Risk Management Guidelines, published 18 January 2021, set out "risk management principles and best practice standards to guide financial institutions in managing technology risk". They apply to the financial institutions MAS supervises, including banks, insurers, capital markets services licensees, payment institutions and financial advisers. They are guidelines rather than a notice: MAS states that they "do not affect, and should not be regarded as a statement of the standard of care owed by FIs to their customers", and that it takes an FI's degree of observance with their spirit into account in supervision. Source: MAS, Technology Risk Management Guidelines and the guidelines text.
Chapter 13 is the one your VAPT scope is built around. Section 13.1.1: "The FI should establish a process to conduct regular vulnerability assessment (VA) on their IT systems to identify security vulnerabilities and ensure risk arising from these gaps are addressed in a timely manner." Section 13.2.1: "The FI should carry out penetration testing (PT) to obtain an in-depth evaluation of its cyber security defences." Section 13.2.4: "For systems that are directly accessible from the Internet, the FI is expected to conduct PT to validate the adequacy of the security controls at least once annually or whenever these systems undergo major changes or updates."
That is why Singapore buys VAPT as a pair. The VA half satisfies 13.1, the PT half satisfies 13.2, and the annual cadence for internet-facing systems sets the renewal date. Our report labels each finding as VA-discovered or PT-confirmed so the two obligations are evidenced separately in one document. If you are a fintech or SaaS vendor to an MAS-regulated institution rather than one yourself, the same guidelines arrive via your customer's outsourcing and third-party risk reviews.
CSA Cyber Essentials and Cyber Trust marks
The Cyber Security Agency of Singapore runs two certification marks for organisations. Cyber Essentials is "designed for businesses of all sizes" and certifies "essential cybersecurity measures, helping organisations mitigate common cyber risks", with coverage extended to cloud, OT and AI security. Cyber Trust "certifies advanced organisations' security readiness, using risk-based approach to match protection with digital exposure levels" and "is suited for organisations with more extensive digitalised business operations". Sources: CSA, Cyber Essentials and Cyber Trust.
Neither mark's page names penetration testing as a condition, and we do not claim it does. Where VAPT fits is evidence. Both marks ask you to declare measures that are in place; Cyber Trust ties those measures to your risk profile. A certifying body or a customer reviewing your mark can ask how you know the measures hold. A VAPT report that targeted those measures, dated and independent, is a direct answer. In the platform, choose the measures you want validated as the goal, and the plan scopes the test around them.
PDPA: the Protection Obligation and breach notification
Singapore's Personal Data Protection Act applies to "any individual, company, association or body of persons, corporate or unincorporated" carrying out activities involving personal data in Singapore. The Protection Obligation in section 24 requires an organisation to "protect personal data in its possession or under its control by making reasonable security arrangements" against unauthorised access, disclosure and similar risks, and against the loss of storage media. The Act also requires organisations to "assess whether a data breach is notifiable and notify the affected individuals and/or the Commission where it is assessed to be notifiable". Source: PDPC, Advisory Guidelines on Key Concepts in the PDPA.
The guidelines do not prescribe penetration testing as a security arrangement. What a VAPT engagement gives a Singapore organisation is the record: an independent, dated test of the systems that hold personal data, the findings that were confirmed, and the retest showing they were closed. That record is what "reasonable" looks like when a breach assessment or a PDPC enquiry asks what you did beforehand.
SOC 2, ISO 27001 and PCI DSS for Singapore companies selling globally
Singapore companies rarely sell only to Singapore. US customers ask for SOC 2. European and regional enterprise buyers ask for ISO 27001. Anyone handling card data is under PCI DSS. The same VAPT engagement serves each of them when the framework is set as the goal at scoping time, because the report maps every finding to the framework's control.
- SOC 2 penetration testing: evidence for the common criteria your auditor samples.
- ISO 27001 penetration testing: evidence for Annex A technical vulnerability management.
- PCI DSS penetration testing: external and internal testing of the cardholder data environment and segmentation.
One scope, one report, multiple mappings. Re-order the retest from the dashboard when findings are fixed, and the closed loop is visible to every assessor.
How a VAPT engagement runs from The Hague
Budget Security has no office or staff in Singapore. Testing is delivered remotely from the Netherlands by OSCP-certified testers, and for the scopes above remote is the normal way VAPT is done.
- Overnight delivery. Singapore is 6 to 7 hours ahead of the Netherlands. Our testers start around 3 to 4 pm Singapore time and work until past midnight your time. Confirmed findings land in the dashboard with severity and reproduction steps as they are verified, so your engineers open the morning with a prioritised list and fix during a day when the test is not running.
- Start within 7 days of booking. A start within 24 hours is possible only when a tester is available, carries an urgency fee, and is never guaranteed.
- Report within 48 hours after the test ends, with the VA findings, the PT findings, remediation per finding, and the compliance mapping for the goal you chose.
- Payment after report delivery. You do not pay when you book.
- Rescheduling a confirmed start is not free; the tester-days were reserved for you.
- Retests are booked from the dashboard and close the finding in the same tracker.
Before the start date, the platform collects scope sign-off, test credentials, and a signed authorisation letter.
What you receive
The deliverable is a dashboard, with a report exported from it. The dashboard holds every finding with its status, so a MAS TRM review, a Cyber Trust assessment or a customer's third-party risk team can see what was found, what was fixed and when the retest confirmed it. The exported report contains an executive summary written for management, a technical section with evidence for each finding, severity ratings, and remediation guidance written for the engineer who has to fix it. For regulated scopes, findings are labelled VA-discovered or PT-confirmed so the two parts of VAPT are evidenced separately.
FAQ
VAPT in Singapore FAQ
What does a penetration test cost in Singapore?
Do you deliver VAPT as one engagement or two?
How often does MAS expect penetration testing?
Do Cyber Essentials or Cyber Trust require a penetration test?
Do you have an office in Singapore?
Can the report be shared with my MAS-regulated customer?
How fast can you start?
When do I pay?
VAPT for your Singapore company, scoped in minutes, priced before you commit.
OSCP-certified testers. Start within 7 days. Findings in your dashboard by morning. Report within 48 hours after the test ends.