Security Assessment

Elevate the Security of Your Business Systems

In today’s digital landscape, cyber threats are becoming increasingly sophisticated and relentless. Critical business data, websites, applications, and IT infrastructure are constantly targeted by cyberattacks. Identifying and addressing security vulnerabilities before they can be exploited is no longer optional—it’s essential for protecting your business, ensuring operational continuity, and maintaining customer trust.

Orange Thailand provides comprehensive Vulnerability Assessment (VA) and Cybersecurity Assessment services designed to evaluate your organization’s security posture against internationally recognized standards. Our experts identify vulnerabilities, assess potential risks, and deliver clear, actionable remediation recommendations, enabling your organization to strengthen its cyber defenses, reduce security risks, and stay resilient against evolving cyber threats.

Cybersecurity Assessment Services

Security Test Services

To meet the diverse security requirements of businesses, we offer two levels of security assessment services. Each service is designed to address different security needs, system environments, and operational constraints, allowing organizations to choose the most suitable approach for their infrastructure.

01.
Web Application Vulnerability Assessment (VA Scan) และ OWASP Top 10 Compliance

An external vulnerability assessment using the Black-box Testing (DAST) approach. This service leverages industry-standard automated security scanning tools, such as OWASP ZAP (Zed Attack Proxy), to simulate the perspective of an external attacker. The assessment identifies security weaknesses in publicly accessible web applications and evaluates them against the OWASP Top 10, the globally recognized standard for the most critical web application security risks.

Open Port Discovery, Service & Version Detection, Operating System & Outdated Software Detection, CVE-Based Vulnerability Scanning, SSL/TLS & Certificate Security Assessment and HTTP Security Headers Assessment

Identify critical web application vulnerabilities that could lead to serious security incidents, including SQL Injection (SQLi), Cross-Site Scripting (XSS), Security Misconfiguration, Broken Authentication, Sensitive Data Exposure, and Information Disclosure. The assessment is performed in accordance with the OWASP Top 10 to help identify and prioritize the most critical web application security risks.

As the assessment is performed externally through a publicly accessible URL (Black-box Testing), the scanning tools cannot access or analyze the application’s underlying source code. As a result, they are unable to identify vulnerabilities that require source code review or assess business logic flaws that depend on application-specific workflows and internal logic.

Ideal for corporate websites, WordPress websites, web applications, APIs, or login portals that require a baseline security assessment.
Our service is available with a standard assessment fee for vulnerability scanning. If remediation is required, the Orange Thailand security team can provide vulnerability remediation services with pricing quoted separately based on the severity and complexity of the identified vulnerabilities. In most cases, remediation can be completed within 3–5 business days.

02.
Penetration Testing
Professional Penetration Testing Services

While automated vulnerability scanning is an effective first step in identifying common security weaknesses, it cannot guarantee complete security. If your environment is highly complex, processes sensitive personal data, or requires the highest level of security assurance, a standard Vulnerability Assessment (VA) may not be sufficient.

For these scenarios, Orange Thailand collaborates with trusted Cybersecurity Partners to provide expert-led Penetration Testing performed by experienced ethical hackers (white-hat hackers). By simulating real-world attack techniques, this service uncovers complex vulnerabilities, business logic flaws, and security issues that automated scanning tools may not detect.

Security experts can identify business logic flaws that automated scanning tools are unable to detect. These include complex vulnerabilities such as Broken Access Control, unauthorized access to other users’ data, privilege escalation, and manipulation of business workflows, such as bypassing or altering payment processes and transaction flows.

This service is suitable for large enterprises, financial institutions, e-commerce platforms, and critical infrastructure systems that require the highest level of security assurance.
Due to the complexity and depth of advanced penetration testing, pricing cannot be provided upfront. Each engagement requires a preliminary technical discussion with the client’s technical team, along with an initial review of the target environment, including system URLs and architectural details. This information is necessary to accurately define the scope of work and provide a tailored quotation for each assessment.

VA Scan Service Process

(Standard Process)

To ensure confidence in the quality and outcomes, our service is delivered through a structured process consisting of six systematic steps:

ProcessService Execution Details
1. Scope DefinitionWe collaborate with your team to discuss, assess, and clearly define the target scope for the assessment. This includes identifying specific assets to be scanned, such as websites, web applications, APIs, servers, public IP addresses, or subdomains, ensuring that the testing scope is accurately defined and aligned with your security objectives.
2. Automated Vulnerability ScanningPerform vulnerability scanning on system infrastructure, including open ports, exposed services, SSL/TLS configurations, and insecure server settings (misconfigurations).
3. Web Application Security Assessment

Scan for web application vulnerabilities based on the OWASP Top 10 standard, including critical security risks such as SQL Injection (SQLi) and Cross-Site Scripting (XSS), to identify and assess common web security weaknesses.

4. Risk Assessment & Prioritization

Security experts classify the severity of identified vulnerabilities into five levels: Critical, High, Medium, Low, and Informational. Each finding is accompanied by a detailed description of the issue, its potential business impact, recommended remediation steps, and long-term prevention strategies to strengthen overall security posture.

5. Executive Summary Report

The final deliverables consist of two comprehensive reports:

  • Executive Summary – A high-level overview designed for management, including the total number of identified vulnerabilities and their risk levels, providing clear insight into the overall security posture.

  • Technical Report – A detailed technical document for development and security teams, including in-depth findings, affected URLs, supporting evidence, and recommended remediation steps for each identified vulnerability.

6. Re-Scan

Additional Service: Retesting & Validation
After the client has completed the remediation of identified vulnerabilities, we provide one round of retesting within 30 days to verify that all issues have been properly resolved. A formal confirmation report will be issued immediately upon completion of the validation process, certifying the effectiveness of the implemented fixes.

Service Exclusions & Limitations

To prevent misunderstandings, the Automated Vulnerability Assessment (VA Scan) service does not include the following activities:

Proactive Security Solutions

It is important for clients to understand that the VA Scan service focuses on vulnerability detection, not prevention. The service is designed to identify and report security weaknesses, but it does not provide active protection against cyberattacks. If identified vulnerabilities are not properly remediated, or if organizations require stronger protection against repeated or advanced threats, Orange Thailand recommends adopting a comprehensive, layered security approach in addition to vulnerability assessment services.

We recommend migrating your system away from shared hosting environments to isolate your resources and infrastructure within a dedicated setup. This helps ensure that your system operates independently, reducing the risk of security breaches caused by vulnerabilities in other websites hosted on the same server.

We recommend implementing a world-class Web Application Firewall (WAF) such as Cloudflare, with starting costs of approximately USD 25–30 per month (around a few thousand baht).

The WAF acts as a first line of defense for your system by filtering incoming traffic, blocking malicious IP addresses, mitigating bot attacks, protecting against DDoS attacks, and preventing brute-force login attempts. This helps significantly enhance the overall security posture of your website or application.

Knowledge Note: Many organizations, particularly government agencies, often inquire about W3C compliance. In reality, W3C (World Wide Web Consortium) is a set of standards focused on web structure and markup languages such as HTML and CSS, ensuring proper rendering and compatibility across different web browsers.

However, it is important to note that W3C standards are not related to cybersecurity or security assurance frameworks. They do not define or provide guidelines for web application security, vulnerability prevention, or protection against cyber threats.

Are you ready to protect your business reputation and safeguard your critical data?

Investing in cybersecurity today is far more cost-effective than recovering from potential damages in the future.

Contact Orange Thailand today to consult with our experts, define your system scope, and receive a tailored quotation for your security assessment needs.

ISO 27001
Information Security Management System Standard (ISMS)

Contact Us

We are happy to provide free consultation, development time estimates, and budget planning, both online and on-site.