Visionary entrepreneur with 18+ years of global techno-consulting and enterprise-transformation experience. Founded MAST Consulting Group in 2016 as a self-funded UAE startup (MAS Tech Consulting) and has since grown it into a regional consulting force spanning UAE, India and Greece — adding MAS Tech General Trading and MAST Advisory Services along the way.
Context, scope, delivery and impact — written for buyers, boards, auditors and search engines alike.
Layer 01 — Context
Context & Why It Matters
01
Vulnerability assessment and penetration testing (VAPT) is now an explicit requirement across PCI DSS v4.0.1 (Req 11), CBUAE IS Regulation, SAMA CSF, NCA ECC, ADHICS V2, RBI CSF, SEBI CSCRF, ISO 27001 (A.8.8, A.8.29) and SOC 2 (CC4.1, CC7.1) — typically annually plus after significant change.
Beyond compliance, VAPT is the most reliable way to validate whether security controls actually work against current attacker techniques.
Layer 02 — Scope
Scope & What It Covers
02
Testing types include external network, internal network, web application (OWASP Top 10, OWASP API Top 10), mobile (iOS, Android, OWASP MASVS), API (REST, GraphQL, SOAP), cloud configuration (AWS, Azure, GCP, OCI, Kubernetes), wireless, social engineering (phishing, vishing, physical), Active Directory and identity, segmentation testing (PCI Req 11.4.5), purple-team and red-team simulations aligned to MITRE ATT&CK.
Methodology follows OWASP Testing Guide, OWASP API Security, PTES, OSSTMM and NIST SP 800-115.
Every engagement includes scoping, rules-of-engagement, testing window, manual exploitation (not just scanner output), a risk-ranked report with proof-of-concept, executive summary, technical report and a re-test of remediated findings within 90 days.
Layer 04 — Impact
Business Impact & Outcomes
04
Exploit-proven findings with clear remediation steps, an attestation letter accepted by regulators, customers, insurers and certification bodies, and measurable reduction in exploitable surface area.
Most clients run quarterly testing on internet-facing assets and annual deep tests on internal and application surface, with continuous attack-surface monitoring between.
At a glance
Process flow, compliance checklist and benefits.
A visual breakdown of how the engagement runs, what evidence we leave behind, and the business outcomes you can defend at the board.
Process flow
How we deliver VAPT — Vulnerability Assessment & Penetration Testing.
01
Scoping
Targets, rules of engagement, success criteria.
02
Testing
OWASP, PTES and OSSTMM-aligned testing.
03
Reporting
Executive summary plus technical report with PoCs.
04
Re-test
Validation of remediated findings.
Compliance checklist
What auditors and regulators expect to see.
What a credible VAPT engagement delivers — aligned to OWASP, PTES, OSSTMM and CREST / OSCP methodologies.
Scoping document and rules of engagement
Targets, timing, exclusions, escalation contacts and success criteria signed off.
Methodology declaration
OWASP WSTG / MASTG, PTES, OSSTMM or CREST methodology selected per engagement type.
Authenticated and unauthenticated testing
Where applicable, both perspectives covered — including privileged user roles.
Exploit-proven findings
Each issue backed by a proof-of-concept demonstrating real impact.
CVSS v3.1 risk rating
Standardised severity scoring with environmental adjustments.
Executive and technical reports
Board summary plus a developer-actionable technical report with remediation guidance.
Free re-test of remediated issues
Confirmation testing within the engagement window.
Attestation letter
Signed letter summarising scope, methodology, dates and outcome for clients and regulators.
Benefits
What you walk away with.
Validated, exploit-proven findings
No false positives — every issue ranked by demonstrated impact.
External, internal, web, mobile, API, cloud, wireless and social engineering.
Meets PCI / ISO / regulator obligations
Satisfies PCI DSS 11.4, ISO 27001 A.8.29 and CBUAE / SAMA / NCA testing requirements.
Re-test included
Confirmation of fixes built into the engagement, not billed separately.
Client and partner attestation
Signed letter accepted by enterprise buyers and regulators.
FAQ
Frequently asked questions.
What testing types do you offer?+
External and internal infrastructure, web application, mobile (iOS/Android), API, cloud (AWS/Azure/GCP), wireless, social engineering and red team simulations.
Do you provide an attestation letter?+
Yes — a signed attestation summarising scope, methodology and outcome is included with every engagement.
Are your testers certified?+
Yes — every consultant holds at least OSCP. Senior testers hold OSCE, OSWE, OSEP, CRTO and / or CREST CRT / CCT credentials.
How long does a typical pentest take?+
Web app: 5 to 10 working days. External infra: 3 to 7 days. Mobile: 7 to 12 days. Red team: 4 to 8 weeks. We confirm at scoping based on attack surface size.
Will testing impact our production systems?+
We run pentests against production with agreed rules of engagement and rate limits. Where impact risk is material we test in pre-prod and validate any safe checks in production.
Do you include re-testing?+
Yes — one round of re-testing for remediated findings is included in every engagement within 60 days of report delivery. Additional rounds are quoted separately.
Will your report satisfy PCI DSS / ISO / SOC 2 requirements?+
Yes — our reports meet PCI DSS 11.4, ISO 27001 A.8.29, SOC 2 CC4.1 and CBUAE / SAMA / NCA testing requirements, with the attestation letter accepted by enterprise buyers and auditors.
Can we agree a multi-engagement retainer?+
Yes — annual retainers with quarterly tests, bug-bounty triage and on-call validation are available at preferential rates.
Take the next step
Choose how you'd like to engage on VAPT — Vulnerability Assessment & Penetration Testing.
Explore every facet of VAPT — Vulnerability Assessment & Penetration Testing.
Methodology, deliverables, week-by-week timeline, pricing models, industry context, tooling and extended FAQs — each on its own page for fast reference and deep linking.