Security Assessment & Consulting
Penetration testing, vulnerability assessment, cloud configuration review, VoIP and SIP security audits, compliance gap analysis for ISO 27001, PCI-DSS and SOC 2, OT/ICS security and virtual CISO - findings ranked by real risk, with fixes you can act on.

CREST · OSCP
Certified testing team
5
Business days to first report
SIP · SS7 · OT
Specialist audit domains
What is Security Assessment & Consulting?
Dollu Security Assessment & Consulting finds the weaknesses in your infrastructure, applications, cloud estate and voice platforms before someone else does, and helps you fix them in priority order. Engagements range from a single external penetration test to a multi-year virtual CISO relationship, delivered by consultants holding OSCP, OSCE, CREST, CISSP, CISA and cloud-provider security certifications. Every engagement produces findings ranked by exploitability and business impact, evidence you can reproduce, and remediation guidance written for the engineers who have to act on it.
Technical assessment covers external and internal infrastructure penetration testing, web and mobile application testing against OWASP standards, API testing, wireless and physical assessments, red-team and purple-team exercises, and continuous vulnerability assessment with managed scanning and retest. Cloud configuration reviews benchmark AWS, Azure, Google Cloud, Dollu Cloud and Kubernetes environments against CIS and provider best practice, and examine identity, network exposure, storage permissions, logging and secrets handling.
Because Dollu operates carrier voice and messaging infrastructure, we test what most security firms cannot. VoIP and SIP security audits examine SBCs, PBXs, UCaaS tenants and contact-centre platforms for registration abuse, toll-fraud paths, weak authentication, media exposure and misconfigured trunks. Signalling assessments cover SS7 and Diameter interconnects for location tracking, interception and denial-of-service exposure. SMS platform reviews look at SMPP account security, sender-ID abuse and OTP interception risk. OT/ICS assessments apply the same discipline to plant networks using safe, passive techniques and IEC 62443 as the reference.
Advisory work turns findings into programmes. Compliance gap assessments map your controls to ISO 27001, PCI-DSS, SOC 2, GDPR, DPDP and RBI or TRAI requirements and produce a costed remediation roadmap. Virtual CISO retains a senior consultant for a set number of days a month to own security strategy, policy, risk register, board reporting, vendor risk and audit preparation. Architecture reviews and secure design workshops support cloud migrations, SASE rollouts and new product launches so security is designed in rather than tested in.
Why choose Dollu for security assessment.
The advantages of buying from a carrier that owns its network, interconnects and operations - rather than a reseller.
Know your real exposure
Manual testing by certified consultants goes beyond scanner output to chain findings into real attack paths and rank them by what an attacker could actually achieve.
Reports engineers can act on
Each finding includes reproduction steps, evidence, affected assets, a fix and a verification method, plus an executive summary for management and auditors.
Voice and signalling expertise
Assessors who run carrier infrastructure test SBCs, PBXs, SIP trunks and SS7/Diameter interconnects with the depth generic firms cannot offer.
Compliance with a roadmap, not a scramble
Gap assessments produce a prioritised, costed plan against ISO 27001, PCI-DSS, SOC 2 or regulatory requirements, so certification is a project with dates rather than an annual panic.
Senior security leadership on demand
Virtual CISO gives you strategy, policy, risk management and board reporting from an experienced practitioner for a fraction of a full-time hire.
Capabilities in detail.
Everything included with Security Assessment & Consulting - the platform features, options and controls you get from day one.
- 01
Penetration testing
External and internal infrastructure, web and mobile applications (OWASP ASVS/MASVS), APIs, wireless, thick clients and cloud-hosted systems; black-, grey- and white-box; manual exploitation with tool-assisted coverage.
- 02
Vulnerability assessment and management
Authenticated scanning of infrastructure and applications on a monthly or continuous basis, triage and de-duplication by analysts, risk-ranked reporting and retest tracking.
- 03
Red and purple team exercises
Objective-based adversary simulation against agreed scenarios, phishing and social engineering, physical intrusion where in scope, and purple-team sessions that tune your detections with Dollu MDR or your SOC.
- 04
Cloud configuration review
CIS benchmark and provider best-practice review of AWS, Azure, Google Cloud, Dollu Cloud and Kubernetes: IAM, network exposure, storage, encryption, logging, secrets and CI/CD pipeline security.
- 05
VoIP, SIP and UC security audit
Assessment of SBCs, IP-PBXs, UCaaS tenants and contact-centre platforms: SIP authentication and registration, toll-fraud paths, dial-plan abuse, TLS/SRTP configuration, media exposure, admin interfaces and trunk hardening.
- 06
Signalling and messaging assessment
SS7 and Diameter interconnect testing for location disclosure, interception and DoS exposure; SMPP and SMS platform review for account security, sender-ID abuse and OTP interception risk; SMS firewall rule review.
- 07
OT/ICS security assessment
Passive network discovery, architecture and segmentation review, IEC 62443 zone and conduit mapping, remote access review and controlled active testing where safe, for plants, utilities and campuses.
- 08
Compliance gap assessment
Control mapping and evidence review against ISO 27001, PCI-DSS, SOC 2, GDPR, DPDP, RBI and TRAI/DoT requirements, with a costed and sequenced remediation roadmap and audit-readiness support.
- 09
Virtual CISO and advisory
Retained senior consultant for strategy, policy, risk register, security architecture review, vendor risk, incident readiness, board reporting and audit preparation; secure design workshops for new projects.
How it works.
From first conversation to live traffic - a tracked, engineer-led onboarding with a named owner at every step.
- Step 01
Scope
We agree objectives, assets, test types, rules of engagement, windows and contacts, and sign authorisation. Scoping is free and usually takes one call and a questionnaire.
- Step 02
Assess
Consultants perform the testing or review, keeping you informed daily and raising critical findings immediately rather than waiting for the report.
- Step 03
Report and debrief
You receive a report with executive summary, risk-ranked findings, evidence and remediation guidance, followed by a debrief with your technical and management stakeholders.
- Step 04
Remediate and retest
We support your team through fixes, retest critical and high findings free within 90 days, and issue an updated report or attestation letter for customers and auditors.
Who uses this and why.
Typical deployments across carriers, enterprises, platforms and contact centres.
Carriers, UCaaS and CPaaS providers
SIP, SBC, signalling and SMS platform audits that find toll-fraud paths, interception exposure and platform weaknesses before they cost minutes, money and reputation.
Banks, NBFCs and fintech
Regulator-mandated penetration testing, application and API assessments, cloud reviews and gap assessments against RBI, PCI-DSS and ISO 27001.
Manufacturers and utilities
OT/ICS assessments and IT/OT segmentation reviews using safe methods, mapped to IEC 62443, with practical remediation for plant environments.
SaaS and product companies
Application, API and cloud configuration testing on a release cadence, SOC 2 readiness and attestation letters that satisfy enterprise customer due diligence.
Enterprises without a CISO
Virtual CISO retainers that establish policy, risk management, vendor oversight and board reporting, backed by an annual programme of testing.
Technical & commercial specifications.
Key parameters at a glance. Ask us for the full service description and SLA document.
| Testing types | External, internal, web, mobile, API, wireless, red/purple team, social engineering |
|---|---|
| Methodologies | OWASP ASVS/MASVS/API, PTES, NIST SP 800-115, MITRE ATT&CK, IEC 62443 |
| Cloud platforms | AWS, Azure, Google Cloud, Dollu Cloud, Kubernetes; CIS benchmarks |
| Telecom scope | SIP/SBC/PBX/UCaaS, SS7/Diameter, SMPP/SMS platforms, SMS firewall |
| Compliance frameworks | ISO 27001, PCI-DSS, SOC 2, GDPR, DPDP, RBI, TRAI/DoT |
| Certifications | OSCP, OSCE, CREST, CISSP, CISA, CCSP, cloud security specialities |
| Deliverables | Executive summary, risk-ranked findings, evidence, remediation, attestation |
| Turnaround | Draft report within 5 business days of test completion |
| Retest | Critical and high findings retested free within 90 days |
| Engagement models | Fixed-price projects, annual programmes, vCISO retainers |
How Security is priced.
Security services are priced per protected site or circuit, per user or per endpoint - and MDR by endpoint count or log volume. Assessments and penetration tests are fixed-scope projects.
We publish the model, not a public rate card - actual rates depend on destination, route class, volume and regulatory cost. See how every Dollu service is priced.
- DDoS and managed firewall per protected site or circuit
- SASE and zero trust per user
- MDR per endpoint or by log volume
- Assessments and penetration tests as fixed-scope projects
- 12–36 month terms on managed services
- Billing
- Monthly recurring in advance; projects invoiced on milestones
- Commitment
- 12–36 months for managed services; none for assessments
Security Assessment - your questions answered.
The questions customers and carriers ask us most often before they interconnect. If yours is not here, our team answers within one business day.
Still have a question?
Ask our solutions teamRelated services.
Services customers commonly combine with Security Assessment & Consulting.
Scope a test in one call.
Tell us what you want assessed and why, and we will return a scoped, fixed-price proposal with dates and named consultants within two business days.
