Security Assessment
Elevate the Security of Your Business Systems
In today’s digital landscape, cyber threats are becoming increasingly sophisticated and relentless. Critical business data, websites, applications, and IT infrastructure are constantly targeted by cyberattacks. Identifying and addressing security vulnerabilities before they can be exploited is no longer optional—it’s essential for protecting your business, ensuring operational continuity, and maintaining customer trust.
Orange Thailand provides comprehensive Vulnerability Assessment (VA) and Cybersecurity Assessment services designed to evaluate your organization’s security posture against internationally recognized standards. Our experts identify vulnerabilities, assess potential risks, and deliver clear, actionable remediation recommendations, enabling your organization to strengthen its cyber defenses, reduce security risks, and stay resilient against evolving cyber threats.
Cybersecurity Assessment Services
Security Test Services
To meet the diverse security requirements of businesses, we offer two levels of security assessment services. Each service is designed to address different security needs, system environments, and operational constraints, allowing organizations to choose the most suitable approach for their infrastructure.
Web Application Vulnerability Assessment (VA Scan) และ OWASP Top 10 Compliance
An external vulnerability assessment using the Black-box Testing (DAST) approach. This service leverages industry-standard automated security scanning tools, such as OWASP ZAP (Zed Attack Proxy), to simulate the perspective of an external attacker. The assessment identifies security weaknesses in publicly accessible web applications and evaluates them against the OWASP Top 10, the globally recognized standard for the most critical web application security risks.
- Infrastructure Vulnerability Assessment
Open Port Discovery, Service & Version Detection, Operating System & Outdated Software Detection, CVE-Based Vulnerability Scanning, SSL/TLS & Certificate Security Assessment and HTTP Security Headers Assessment
- Web Application Vulnerability Assessment (OWASP Top 10)
Identify critical web application vulnerabilities that could lead to serious security incidents, including SQL Injection (SQLi), Cross-Site Scripting (XSS), Security Misconfiguration, Broken Authentication, Sensitive Data Exposure, and Information Disclosure. The assessment is performed in accordance with the OWASP Top 10 to help identify and prioritize the most critical web application security risks.
- Assessment Scope & Limitations
As the assessment is performed externally through a publicly accessible URL (Black-box Testing), the scanning tools cannot access or analyze the application’s underlying source code. As a result, they are unable to identify vulnerabilities that require source code review or assess business logic flaws that depend on application-specific workflows and internal logic.
- Service Suitability & Pricing
Ideal for corporate websites, WordPress websites, web applications, APIs, or login portals that require a baseline security assessment.
Our service is available with a standard assessment fee for vulnerability scanning. If remediation is required, the Orange Thailand security team can provide vulnerability remediation services with pricing quoted separately based on the severity and complexity of the identified vulnerabilities. In most cases, remediation can be completed within 3–5 business days.
Penetration Testing
Professional Penetration Testing Services
While automated vulnerability scanning is an effective first step in identifying common security weaknesses, it cannot guarantee complete security. If your environment is highly complex, processes sensitive personal data, or requires the highest level of security assurance, a standard Vulnerability Assessment (VA) may not be sufficient.
For these scenarios, Orange Thailand collaborates with trusted Cybersecurity Partners to provide expert-led Penetration Testing performed by experienced ethical hackers (white-hat hackers). By simulating real-world attack techniques, this service uncovers complex vulnerabilities, business logic flaws, and security issues that automated scanning tools may not detect.
- Advanced Assessment Capabilities
Security experts can identify business logic flaws that automated scanning tools are unable to detect. These include complex vulnerabilities such as Broken Access Control, unauthorized access to other users’ data, privilege escalation, and manipulation of business workflows, such as bypassing or altering payment processes and transaction flows.
- Service Suitability & Pricing
This service is suitable for large enterprises, financial institutions, e-commerce platforms, and critical infrastructure systems that require the highest level of security assurance.
Due to the complexity and depth of advanced penetration testing, pricing cannot be provided upfront. Each engagement requires a preliminary technical discussion with the client’s technical team, along with an initial review of the target environment, including system URLs and architectural details. This information is necessary to accurately define the scope of work and provide a tailored quotation for each assessment.
VA Scan Service Process
(Standard Process)
To ensure confidence in the quality and outcomes, our service is delivered through a structured process consisting of six systematic steps:
| Process | Service Execution Details |
|---|---|
| 1. Scope Definition | We collaborate with your team to discuss, assess, and clearly define the target scope for the assessment. This includes identifying specific assets to be scanned, such as websites, web applications, APIs, servers, public IP addresses, or subdomains, ensuring that the testing scope is accurately defined and aligned with your security objectives. |
| 2. Automated Vulnerability Scanning | Perform vulnerability scanning on system infrastructure, including open ports, exposed services, SSL/TLS configurations, and insecure server settings (misconfigurations). |
| 3. Web Application Security Assessment | Scan for web application vulnerabilities based on the OWASP Top 10 standard, including critical security risks such as SQL Injection (SQLi) and Cross-Site Scripting (XSS), to identify and assess common web security weaknesses. |
| 4. Risk Assessment & Prioritization | Security experts classify the severity of identified vulnerabilities into five levels: Critical, High, Medium, Low, and Informational. Each finding is accompanied by a detailed description of the issue, its potential business impact, recommended remediation steps, and long-term prevention strategies to strengthen overall security posture. |
| 5. Executive Summary Report | The final deliverables consist of two comprehensive reports:
|
| 6. Re-Scan | Additional Service: Retesting & Validation |
Service Exclusions & Limitations
To prevent misunderstandings, the Automated Vulnerability Assessment (VA Scan) service does not include the following activities:
- Active exploitation attempts, including efforts to gain unauthorized access or extract real data from systems (Penetration Testing activities).
- Social engineering activities, including phishing simulations or deceptive email-based employee testing, are not included within the scope of the VA Scan service.
- Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks, including load testing or attempts to intentionally overwhelm and disrupt server availability, are not included within the scope of the VA Scan service.
- Accessing production databases or retrieving real customer data, including any personal data protected under PDPA or similar privacy regulations, is not included within the scope of the VA Scan service.
- Direct modification of client source code is not included within the scope of the VA Scan service. The assessment report is intended to identify vulnerabilities and provide remediation recommendations only, serving as a guideline for the client’s development team to implement the necessary fixes.
Proactive Security Solutions
It is important for clients to understand that the VA Scan service focuses on vulnerability detection, not prevention. The service is designed to identify and report security weaknesses, but it does not provide active protection against cyberattacks. If identified vulnerabilities are not properly remediated, or if organizations require stronger protection against repeated or advanced threats, Orange Thailand recommends adopting a comprehensive, layered security approach in addition to vulnerability assessment services.
- Cloud VPS Services
We recommend migrating your system away from shared hosting environments to isolate your resources and infrastructure within a dedicated setup. This helps ensure that your system operates independently, reducing the risk of security breaches caused by vulnerabilities in other websites hosted on the same server.
- Web Application Firewall (WAF) Implementation
We recommend implementing a world-class Web Application Firewall (WAF) such as Cloudflare, with starting costs of approximately USD 25–30 per month (around a few thousand baht).
The WAF acts as a first line of defense for your system by filtering incoming traffic, blocking malicious IP addresses, mitigating bot attacks, protecting against DDoS attacks, and preventing brute-force login attempts. This helps significantly enhance the overall security posture of your website or application.
Knowledge Note: Many organizations, particularly government agencies, often inquire about W3C compliance. In reality, W3C (World Wide Web Consortium) is a set of standards focused on web structure and markup languages such as HTML and CSS, ensuring proper rendering and compatibility across different web browsers.
However, it is important to note that W3C standards are not related to cybersecurity or security assurance frameworks. They do not define or provide guidelines for web application security, vulnerability prevention, or protection against cyber threats.
Investing in cybersecurity today is far more cost-effective than recovering from potential damages in the future.
Contact Orange Thailand today to consult with our experts, define your system scope, and receive a tailored quotation for your security assessment needs.