Skip to content
Cyber Security

Security Assessment & Consulting

Penetration testing, vulnerability assessment, cloud configuration review, VoIP and SIP security audits, compliance gap analysis for ISO 27001, PCI-DSS and SOC 2, OT/ICS security and virtual CISO - findings ranked by real risk, with fixes you can act on.

Security Assessment & Consulting - Dollu
  • CREST · OSCP

    Certified testing team

  • 5

    Business days to first report

  • SIP · SS7 · OT

    Specialist audit domains

Overview

What is Security Assessment & Consulting?

Dollu Security Assessment & Consulting finds the weaknesses in your infrastructure, applications, cloud estate and voice platforms before someone else does, and helps you fix them in priority order. Engagements range from a single external penetration test to a multi-year virtual CISO relationship, delivered by consultants holding OSCP, OSCE, CREST, CISSP, CISA and cloud-provider security certifications. Every engagement produces findings ranked by exploitability and business impact, evidence you can reproduce, and remediation guidance written for the engineers who have to act on it.

Technical assessment covers external and internal infrastructure penetration testing, web and mobile application testing against OWASP standards, API testing, wireless and physical assessments, red-team and purple-team exercises, and continuous vulnerability assessment with managed scanning and retest. Cloud configuration reviews benchmark AWS, Azure, Google Cloud, Dollu Cloud and Kubernetes environments against CIS and provider best practice, and examine identity, network exposure, storage permissions, logging and secrets handling.

Because Dollu operates carrier voice and messaging infrastructure, we test what most security firms cannot. VoIP and SIP security audits examine SBCs, PBXs, UCaaS tenants and contact-centre platforms for registration abuse, toll-fraud paths, weak authentication, media exposure and misconfigured trunks. Signalling assessments cover SS7 and Diameter interconnects for location tracking, interception and denial-of-service exposure. SMS platform reviews look at SMPP account security, sender-ID abuse and OTP interception risk. OT/ICS assessments apply the same discipline to plant networks using safe, passive techniques and IEC 62443 as the reference.

Advisory work turns findings into programmes. Compliance gap assessments map your controls to ISO 27001, PCI-DSS, SOC 2, GDPR, DPDP and RBI or TRAI requirements and produce a costed remediation roadmap. Virtual CISO retains a senior consultant for a set number of days a month to own security strategy, policy, risk register, board reporting, vendor risk and audit preparation. Architecture reviews and secure design workshops support cloud migrations, SASE rollouts and new product launches so security is designed in rather than tested in.

Why Dollu

Why choose Dollu for security assessment.

The advantages of buying from a carrier that owns its network, interconnects and operations - rather than a reseller.

  • Know your real exposure

    Manual testing by certified consultants goes beyond scanner output to chain findings into real attack paths and rank them by what an attacker could actually achieve.

  • Reports engineers can act on

    Each finding includes reproduction steps, evidence, affected assets, a fix and a verification method, plus an executive summary for management and auditors.

  • Voice and signalling expertise

    Assessors who run carrier infrastructure test SBCs, PBXs, SIP trunks and SS7/Diameter interconnects with the depth generic firms cannot offer.

  • Compliance with a roadmap, not a scramble

    Gap assessments produce a prioritised, costed plan against ISO 27001, PCI-DSS, SOC 2 or regulatory requirements, so certification is a project with dates rather than an annual panic.

  • Senior security leadership on demand

    Virtual CISO gives you strategy, policy, risk management and board reporting from an experienced practitioner for a fraction of a full-time hire.

Capabilities

Capabilities in detail.

Everything included with Security Assessment & Consulting - the platform features, options and controls you get from day one.

  1. 01

    Penetration testing

    External and internal infrastructure, web and mobile applications (OWASP ASVS/MASVS), APIs, wireless, thick clients and cloud-hosted systems; black-, grey- and white-box; manual exploitation with tool-assisted coverage.

  2. 02

    Vulnerability assessment and management

    Authenticated scanning of infrastructure and applications on a monthly or continuous basis, triage and de-duplication by analysts, risk-ranked reporting and retest tracking.

  3. 03

    Red and purple team exercises

    Objective-based adversary simulation against agreed scenarios, phishing and social engineering, physical intrusion where in scope, and purple-team sessions that tune your detections with Dollu MDR or your SOC.

  4. 04

    Cloud configuration review

    CIS benchmark and provider best-practice review of AWS, Azure, Google Cloud, Dollu Cloud and Kubernetes: IAM, network exposure, storage, encryption, logging, secrets and CI/CD pipeline security.

  5. 05

    VoIP, SIP and UC security audit

    Assessment of SBCs, IP-PBXs, UCaaS tenants and contact-centre platforms: SIP authentication and registration, toll-fraud paths, dial-plan abuse, TLS/SRTP configuration, media exposure, admin interfaces and trunk hardening.

  6. 06

    Signalling and messaging assessment

    SS7 and Diameter interconnect testing for location disclosure, interception and DoS exposure; SMPP and SMS platform review for account security, sender-ID abuse and OTP interception risk; SMS firewall rule review.

  7. 07

    OT/ICS security assessment

    Passive network discovery, architecture and segmentation review, IEC 62443 zone and conduit mapping, remote access review and controlled active testing where safe, for plants, utilities and campuses.

  8. 08

    Compliance gap assessment

    Control mapping and evidence review against ISO 27001, PCI-DSS, SOC 2, GDPR, DPDP, RBI and TRAI/DoT requirements, with a costed and sequenced remediation roadmap and audit-readiness support.

  9. 09

    Virtual CISO and advisory

    Retained senior consultant for strategy, policy, risk register, security architecture review, vendor risk, incident readiness, board reporting and audit preparation; secure design workshops for new projects.

How it works

How it works.

From first conversation to live traffic - a tracked, engineer-led onboarding with a named owner at every step.

  1. Step 01

    Scope

    We agree objectives, assets, test types, rules of engagement, windows and contacts, and sign authorisation. Scoping is free and usually takes one call and a questionnaire.

  2. Step 02

    Assess

    Consultants perform the testing or review, keeping you informed daily and raising critical findings immediately rather than waiting for the report.

  3. Step 03

    Report and debrief

    You receive a report with executive summary, risk-ranked findings, evidence and remediation guidance, followed by a debrief with your technical and management stakeholders.

  4. Step 04

    Remediate and retest

    We support your team through fixes, retest critical and high findings free within 90 days, and issue an updated report or attestation letter for customers and auditors.

Use cases

Who uses this and why.

Typical deployments across carriers, enterprises, platforms and contact centres.

  • Carriers, UCaaS and CPaaS providers

    SIP, SBC, signalling and SMS platform audits that find toll-fraud paths, interception exposure and platform weaknesses before they cost minutes, money and reputation.

  • Banks, NBFCs and fintech

    Regulator-mandated penetration testing, application and API assessments, cloud reviews and gap assessments against RBI, PCI-DSS and ISO 27001.

  • Manufacturers and utilities

    OT/ICS assessments and IT/OT segmentation reviews using safe methods, mapped to IEC 62443, with practical remediation for plant environments.

  • SaaS and product companies

    Application, API and cloud configuration testing on a release cadence, SOC 2 readiness and attestation letters that satisfy enterprise customer due diligence.

  • Enterprises without a CISO

    Virtual CISO retainers that establish policy, risk management, vendor oversight and board reporting, backed by an annual programme of testing.

Specifications

Technical & commercial specifications.

Key parameters at a glance. Ask us for the full service description and SLA document.

Testing typesExternal, internal, web, mobile, API, wireless, red/purple team, social engineering
MethodologiesOWASP ASVS/MASVS/API, PTES, NIST SP 800-115, MITRE ATT&CK, IEC 62443
Cloud platformsAWS, Azure, Google Cloud, Dollu Cloud, Kubernetes; CIS benchmarks
Telecom scopeSIP/SBC/PBX/UCaaS, SS7/Diameter, SMPP/SMS platforms, SMS firewall
Compliance frameworksISO 27001, PCI-DSS, SOC 2, GDPR, DPDP, RBI, TRAI/DoT
CertificationsOSCP, OSCE, CREST, CISSP, CISA, CCSP, cloud security specialities
DeliverablesExecutive summary, risk-ranked findings, evidence, remediation, attestation
TurnaroundDraft report within 5 business days of test completion
RetestCritical and high findings retested free within 90 days
Engagement modelsFixed-price projects, annual programmes, vCISO retainers
Pricing model

How Security is priced.

Security services are priced per protected site or circuit, per user or per endpoint - and MDR by endpoint count or log volume. Assessments and penetration tests are fixed-scope projects.

We publish the model, not a public rate card - actual rates depend on destination, route class, volume and regulatory cost. See how every Dollu service is priced.

Monthly recurring · per site, user or endpoint
  • DDoS and managed firewall per protected site or circuit
  • SASE and zero trust per user
  • MDR per endpoint or by log volume
  • Assessments and penetration tests as fixed-scope projects
  • 12–36 month terms on managed services
Billing
Monthly recurring in advance; projects invoiced on milestones
Commitment
12–36 months for managed services; none for assessments
Talk to salesActual rates within one business day.
FAQ

Security Assessment - your questions answered.

The questions customers and carriers ask us most often before they interconnect. If yours is not here, our team answers within one business day.

Still have a question?

Ask our solutions team

At least annually and after significant change to infrastructure or applications, which is also what PCI-DSS, ISO 27001 auditors and most regulators expect. Organisations shipping frequently usually combine an annual full test with continuous vulnerability assessment and targeted tests on major releases.

Let’s talk

Scope a test in one call.

Tell us what you want assessed and why, and we will return a scoped, fixed-price proposal with dates and named consultants within two business days.

Abstract globe with connected network lines