The VAPT Recurrence Trap
Every quarter, thousands of Indian organizations dutifully conduct Vulnerability Assessment and Penetration Testing (VAPT) — as required by SEBI CSCRF (DE.2), RBI cybersecurity framework, and ISO 27001 (A.8.8). The VAPT vendor delivers a report. The security team reviews it. Findings are logged. And then... the pipeline breaks.
Where closure is not tracked, a disturbing pattern emerges: findings identified in one cycle reappear in the next. Critical and high-severity findings fare only slightly better, meaning many of your most dangerous vulnerabilities survive from one assessment to the next.