// Section 01

Testing
Methodology

Pendekatan komprehensif yang disesuaikan dengan kebutuhan dan postur keamanan sistem Anda.

// Method 01

Black Box

Simulasi serangan hacker eksternal tanpa informasi apapun tentang sistem Anda. Tester hanya mengetahui target URL dan mencoba menembus sistem seperti attacker sungguhan.

Core Benefits:
  • Perspektif real-world attacker
  • Menemukan vulnerability yang terekspos ke publik
  • Menguji perimeter defense Anda
  • Cocok untuk compliance requirements (PCI DSS, ISO 27001)
BEST FOR: E-commerce
RATE: Premium (1.4x)
// Method 02

Grey Box

Testing dengan informasi terbatas seperti akun user biasa. Mensimulasikan skenario insider threat atau hacker yang sudah mendapat akses awal ke sistem.

Core Benefits:
  • Balance antara coverage dan biaya
  • Fokus pada privilege escalation
  • Menemukan logic flaws di business process
  • Lebih efisien dari segi waktu
BEST FOR: Web applications
RATE: Standard (1.0x)
// Method 03

White Box

Testing komprehensif dengan full access ke source code, dokumentasi, dan infrastructure. Termasuk code review dan architecture analysis.

Core Benefits:
  • Coverage paling lengkap (termasuk code-level vulnerabilities)
  • Menemukan logic bombs dan backdoors
  • Code review untuk secure coding practices
  • Detailed remediation guidance
BEST FOR: Applications sebelum production launch
RATE: Premium+ (1.2x)
// Section 02

Pricing &
Complexity Tiers

SIMPLE

Rp 5-10 Juta
Karakteristik:
  • Website statis atau WordPress basic
  • 5-20 halaman/endpoints
  • Minimal atau tanpa database interaction
  • Login sederhana (admin panel only)
  • No payment gateway
  • No API integration
  • Shared hosting atau basic VPS
Scope:
  • OWASP Top 10 basic checks
  • Authentication testing
  • Input validation
  • SSL/TLS configuration
  • Basic information disclosure
Durasi: 3-5 Hari
Output: Executive summary, Vulnerability report, Risk rating, Basic remediation steps.

MEDIUM

Rp 10-20 Juta
Karakteristik:
  • Dynamic web application dengan database
  • 20-50 endpoints/pages
  • User authentication & role-based access
  • Form processing & file upload
  • Payment gateway integration
  • CRUD operations
  • REST API (basic)
Scope:
  • Full OWASP Top 10
  • Business logic testing
  • Session management
  • Authorization bypass attempts
  • API security testing
  • File upload vulnerabilities
  • Payment flow security
Durasi: 5-7 Hari
Output: Executive summary, Detailed tech report, PoC, Risk matrix, Remediation roadmap.

COMPLEX

Rp 18-30 Juta
Karakteristik:
  • Multi-tier architecture
  • 50-100+ endpoints
  • Complex user roles & permissions
  • Multiple API integrations
  • Real-time features (WebSocket)
  • Mobile app backend
  • Cloud infrastructure (AWS/GCP/Azure)
Scope:
  • OWASP Top 10 + API Security
  • Advanced business logic flaws
  • Race conditions
  • GraphQL/REST API deep testing
  • Third-party integration security
  • Mobile API security
  • Cloud misconfigurations
Durasi: 7-12 Hari
Output: Exec summary, Detailed report, Attack narratives, Video PoC, CVSS scoring, Compliance mapping.
// Section 03

Client
Requirements

Wajib Disiapkan

  • Scope definition: Target URL/IP, In-scope subdomains, Allowed hours
  • Legal docs: Signed agreement, Auth letter, NDA
  • Emergency contact: Tech support (24/7), Escalation contact
  • Persiapan: Backup sistem sebelum testing, informasi tim IT

X TIDAK Perlu Diberikan

  • User credentials
  • Source code
  • Documentation (Architecture, dll)
  • Infrastructure details
// Section 04

Testing Process

Engagement Timeline
End-to-end Execution
PHASE 01

Pre-engagement

Kickoff meeting, scope finalization, legal agreement signing, access provisioning, dan rules of engagement (2-3 hari).

PHASE 02

Reconnaissance

Information gathering, asset discovery, attack surface mapping, dan threat modeling (1-2 hari).

PHASE 03

Active Testing

Vulnerability scanning, manual exploitation, business logic testing, privilege escalation attempts (3-15 hari).

PHASE 04

Reporting

Vulnerability documentation, risk assessment, proof of concept creation, executive summary (2-3 hari).

PHASE 05

Presentation

Findings presentation, Q&A session, remediation roadmap discussion, dan priority setting (1 hari).

PHASE 06

Retest (Optional)

Verify fixes, regression testing, updated report, dan security posture assessment (2-3 hari).

// Deliverables & Add-ons

Value Added
Services

Retest Service

Verify remediation effectiveness. Test hanya untuk issues yang ditemukan.

RATE: Rp 3.000.000
// Why Choose Us

Our Competitive
Edge

Proven Track

50+ successful assessments, 0 data breach during testing, 95% client satisfaction.

Manual Focus

Manual testing (bukan scanner), business logic focus, real-world attack scenarios.

Local Support

Bahasa Indonesia reporting, local business hours, on-site meeting available.