Practice details
How each practice works, in detail.
What you receive, how an engagement runs, how long it takes and who does the work, for all six Coditing practices. Jump straight to the one you need.
01Cyber Security
Attack-ready testing that ends in fixes, not just findings
Attackers do not read your architecture diagrams; they probe what is actually exposed. Our security specialists test your web apps, mobile apps, APIs, cloud accounts, networks and AI features using the same techniques adversaries use, then rank every issue by real-world exploitability so your engineers know exactly what to fix first.

What you get
- Penetration testingManual, scoped testing of web, mobile, API and network targets, with proof-of-concept evidence for every finding.
- Cloud security reviewConfiguration and identity review of AWS, Azure or Google Cloud against hardening benchmarks.
- Red team exerciseGoal-based simulation of a determined attacker to test detection and response, not just prevention.
- LLM and AI red teamingPrompt injection, data leakage, jailbreak and abuse testing for chatbots, copilots and agents.
- Secure SDLC and DevSecOpsSecurity checks built into your CI/CD pipeline, plus secure code review of critical components.
- Retest of fixesA retest of fixed critical and high findings, so you can show customers the issues are closed.
How an engagement runs
- Scoping call to agree targets, rules of engagement and test windows.
- Testing by certified specialists, with critical issues reported the same day.
- Readout with your engineers: what to fix first and how.
- Retest and a clean summary letter you can share with customers.
Typical timeline
1 to 3 weeks for most penetration tests; red team exercises run longer.
Who does the work
Our 7 security specialists, holding OSCP and CEH credentials.
Proof
78% fewer exploitable findings for a US healthcare SaaSCyber Security: common questions
How often should we run a penetration test?
At least once a year and after any major release, infrastructure change or acquisition. Many enterprise customers and standards such as PCI DSS and SOC 2 expect annual testing as a minimum.
Will testing disrupt our production systems?
We agree test windows and safe limits in advance, avoid destructive techniques unless you approve them, and can test a staging environment that mirrors production.
What is the difference between a pentest and a red team exercise?
A penetration test finds as many weaknesses as possible in a defined scope. A red team exercise pursues a specific goal, such as reaching customer data, to test whether your people and tools detect and stop a realistic attack.
02Information Security
Senior security leadership without a full-time hire
Most growing companies reach a point where security needs an owner: someone to set priorities, answer the board and keep certifications on track. Our compliance analysts and senior auditors build the programme around how your business already works, and a virtual CISO leads it until you are ready to hire your own.

What you get
- Virtual CISOA named senior leader who owns your security roadmap, attends leadership meetings and reports to the board.
- Security roadmapA prioritised 12 to 18 month plan that links security spend to business risk and revenue.
- ISO 27001 implementationScope, risk assessment, Statement of Applicability, policies and evidence, ready for the certification body.
- Risk managementA living risk register with owners, treatment plans and quarterly reviews.
- Business continuityISO 22301-aligned continuity and recovery plans, tested through exercises.
- Board reportingA short quarterly report the board and investors can actually read and act on.
How an engagement runs
- Baseline assessment of where you stand today.
- Roadmap agreed with leadership, with owners and dates.
- Monthly delivery: policies, controls, evidence and training.
- Quarterly board report and roadmap refresh.
Typical timeline
vCISO engagements usually run for 6 months or more; ISO 27001 readiness typically takes 3 to 6 months.
Who does the work
A senior consultant supported by our 9 compliance analysts.
Proof
A board-ready security report in 60 days for a GCC bankInformation Security: common questions
When does a company need a vCISO?
When customers, investors or regulators start asking security questions that nobody on the team owns. A vCISO is often the right step before you can justify a full-time chief information security officer.
How long does ISO 27001 certification take?
For a focused scope, readiness typically takes three to six months, followed by the two-stage certification audit. One of our fintech clients certified in four months with zero major non-conformities.
Do you replace our internal IT team?
No. We work alongside your IT and engineering teams, set the direction and do the specialist work, and leave them with clear processes they can run.
03Data Privacy
Privacy programmes that satisfy regulators and reassure customers
Privacy laws now reach almost every company that handles customer or employee data. India’s Digital Personal Data Protection Act, the GDPR and similar laws require you to know what personal data you hold, have a lawful reason to use it and respond quickly when people exercise their rights or when something goes wrong. We make that practical.

What you get
- Data discovery and mappingA record of what personal data you collect, where it lives, who accesses it and who you share it with.
- DPDP Act readinessGap assessment and remediation for notices, consent, data principal rights and breach reporting.
- GDPR complianceRecords of processing, DPIAs, transfer safeguards and processor agreements.
- DPO or vCPO as a serviceAn experienced privacy lead who handles requests, advises teams and represents you to regulators.
- Privacy by designPrivacy reviews built into product development, so new features launch compliant.
- Breach readinessA tested playbook for assessing, containing and reporting personal data breaches on time.
How an engagement runs
- Discovery workshops with product, engineering, HR and legal.
- Data map and gap report against the laws that apply to you.
- Remediation: notices, consent, processes and contracts.
- Ongoing privacy operations through a DPO or vCPO service.
Typical timeline
Data mapping and a gap report in 4 to 8 weeks; full programmes over 3 to 6 months.
Who does the work
Privacy-certified consultants from our compliance team.
Proof
How we work alongside your teamsData Privacy: common questions
Does the DPDP Act apply to my company?
If you process digital personal data of individuals in India, or offer goods or services to people in India from abroad, it is likely to apply. We can confirm your position in a short assessment.
We already comply with GDPR. Are we ready for DPDP?
GDPR work gives you a strong head start, but the DPDP Act has its own rules on consent, notices, children’s data and obligations for significant data fiduciaries. A focused gap assessment shows what is left to do.
What is a DPIA and when do we need one?
A data protection impact assessment analyses high-risk processing, such as large-scale profiling or sensitive data, before it starts. It identifies risks to individuals and the safeguards that reduce them.
04IS Audit & Assurance
Independent assurance before the auditor or buyer arrives
A failed audit or a stalled vendor review costs time, money and credibility. Our senior auditors assess you exactly as a certification body, regulator or enterprise customer would, so the surprises happen in a private report and not in front of the people whose trust you need.

What you get
- Readiness assessmentA structured gap review against ISO 27001, SOC 2, PCI DSS or your target framework.
- Internal auditIndependent internal audits that meet ISO requirements and keep certifications healthy.
- SOC 2 readinessControl design, evidence collection and auditor liaison for Type 1 and Type 2 reports.
- PCI DSS assessmentScoping, segmentation review and gap assessment against PCI DSS v4.0.
- IT general controlsITGC reviews to support financial audits and SOX-style requirements.
- Vendor riskThird-party risk assessments and a repeatable process for reviewing your suppliers.
How an engagement runs
- Agree the standard, scope and evidence period.
- Fieldwork: interviews, sampling and evidence review.
- Findings report with severity, root cause and owners.
- Follow-up review to confirm gaps are closed.
Typical timeline
Readiness reviews in 2 to 4 weeks; internal audits in 1 to 3 weeks depending on scope.
Who does the work
Our 5 senior auditors, including ISO 27001 lead auditors and CISA holders.
Proof
ISO 27001 in 4 months with zero major non-conformitiesIS Audit: common questions
Can Coditing issue our ISO 27001 certificate?
No. Certificates are issued by accredited certification bodies. We prepare you, run internal audits and support you through the certification audit, which keeps our assessment independent of the final decision.
What is the difference between SOC 2 Type 1 and Type 2?
Type 1 reports on whether controls are designed correctly at a point in time. Type 2 tests whether they operated effectively over a period, usually three to twelve months, and carries more weight with enterprise buyers.
Do you audit against Indian banking regulations?
Yes. We assess against RBI and SEBI cybersecurity requirements, as well as GCC frameworks such as SAMA and NCA, and EU rules such as DORA.
05AI Security & Governance
Use AI boldly, with controls your customers can trust
AI creates new ways for data to leak and for systems to be manipulated, and new rules such as the EU AI Act and ISO/IEC 42001 are raising the bar. We help you decide where AI adds value, put governance around it and test your AI features against the attacks that target them.

What you get
- AI strategy and use casesA shortlist of high-value AI use cases with the data, risk and controls each one needs.
- AI risk assessmentImpact and risk assessment of AI systems, covering data, bias, security and accountability.
- ISO 42001 AI management systemDesign and implementation of an AI management system ready for certification.
- LLM red teamingAdversarial testing of models, prompts, retrieval pipelines and agent tools.
- Shadow AI discoveryA view of which AI tools staff use, what data goes into them, and a policy to match.
- GenAI solutionsDesign and build of GenAI features with guardrails built in from the start.
How an engagement runs
- Inventory of AI use, both built and bought.
- Risk and impact assessment for each AI system.
- Governance, policies and technical controls.
- Testing, monitoring and readiness for certification or regulation.
Typical timeline
Shadow AI discovery in about 2 weeks; ISO 42001 programmes over 4 to 6 months.
Who does the work
Security specialists and compliance analysts with ISO 42001 implementation experience.
Proof
An ISO 42001 AI management system in 5 monthsAI Security: common questions
What is ISO/IEC 42001?
ISO/IEC 42001 is the international standard for AI management systems. It sets requirements for governing AI responsibly, from risk and impact assessment to monitoring, and organisations can be certified against it.
Does the EU AI Act affect companies outside Europe?
It can. The Act applies to providers and deployers whose AI systems are placed on the EU market or whose outputs are used in the EU, regardless of where the company is based.
What does LLM red teaming test?
It tests how a model-powered feature behaves under attack: prompt injection, jailbreaks, leakage of system prompts or customer data, unsafe tool use by agents and abuse of connected systems.
06Training & Awareness
Training that changes behaviour, not just completion rates
Most breaches still involve a human decision: a click, a password, a misconfigured setting. Our trainers build sessions around real incidents and the findings from our own engagements, so boards make better risk decisions, developers write safer code and every employee knows what to do when something looks wrong.

What you get
- Board and executive workshopsCyber and AI risk explained for decision-makers, including their legal responsibilities.
- Secure coding labsHands-on labs where developers exploit and then fix common vulnerabilities.
- Security awarenessPractical awareness programmes with phishing simulations and short, relevant modules.
- Incident response tabletopsRealistic scenarios that test how leaders and teams respond under pressure.
- AI literacySafe and productive use of AI tools for non-technical teams.
- Certification preparationStructured preparation for CISSP, CISM, CISA and CIPP exams.
How an engagement runs
- Training needs analysis based on your risks and roles.
- Programme design with your examples and systems.
- Delivery on-site or online, with hands-on exercises.
- Measurement and refresher plan.
Typical timeline
Workshops from half a day; awareness programmes run all year.
Who does the work
Our 3 dedicated trainers, supported by practising testers and auditors.
Proof
How training fits our C+A+T methodTraining: common questions
Can training be delivered online?
Yes. Workshops, labs and tabletop exercises can run on-site, online or as a mix, for teams in any of the regions we serve.
Do you provide certificates of completion?
Yes. Participants can receive completion certificates, which are useful evidence of training for ISO 27001, SOC 2 and regulatory audits.
Can sessions be tailored to our industry?
Every programme uses scenarios from your sector, such as payment fraud for fintech or patient data for healthcare, so the lessons feel real.
Combine practices, keep one contact.
Most programmes draw on two or three practices. A single engagement lead coordinates them, so you get one plan, one report and one team accountable for results.
