Penetration Testing / Bangladesh
VAPT Services in Bangladesh
eNeoteric delivers VAPT (Vulnerability Assessment and Penetration Testing) services for organisations in Bangladesh, delivered remotely by our India-based team with on-site coordination available. For banks and NBFIs, engagements are scoped directly against Bangladesh Bank's Guideline on ICT Security for Banks and Non-Bank Financial Institutions, Version 4.0 (BRPD circular, June 19, 2023) — which explicitly requires regular vulnerability assessments and penetration testing "to conduct an in-depth evaluation of the security posture."
VAPT scoped to Bangladesh's regulatory environment
Bangladesh Bank's Guideline on ICT Security for Banks and Non-Bank Financial Institutions, Version 4.0, issued via BRPD circular on June 19, 2023, sets out one of the clearest, most explicit penetration-testing mandates in the region. It requires banks and NBFIs to carry out regular vulnerability assessments — both automated and manual, including web application testing for issues such as SQL injection and cross-site scripting — and explicitly requires institutions to "carry out penetration tests... to conduct an in-depth evaluation of the security posture." This is a binding, named requirement, not a general expectation, and we scope our banking and NBFI engagements to produce evidence directly against it.
On the data protection side, Bangladesh recently enacted the Personal Data Protection Act, 2026 (Law 63 of 2026), passed by Parliament in April 2026 after a fast legislative history — a draft in 2024, an Ordinance in November 2025, amendments in February 2026, and finally this Act. It is very new legislation, and some commentary describes its mandatory breach-notification and enforcement mechanisms as weaker than comparable regional data protection laws, with full enforcement mechanisms reportedly not activating until around May 2027. We treat the PDPA 2026 as a data protection law in early implementation rather than a fully enforced regime, and frame compliance-facing language accordingly.
On the cyber-law side, the Cyber Security Ordinance 2025 established the National Cyber Security Agency (NCSA) — Bangladesh's newly established national cybersecurity agency, formed in August 2025. As it was created by an interim-government ordinance, its long-term legal status depends on future parliamentary ratification. Bangladesh's designated national CERT, BGD e-GOV CIRT, operates under the Bangladesh Computer Council and was established following the 2016 Bangladesh Bank cyber heist — a formative event that shaped the country's focus on financial-sector cybersecurity. BGD e-GOV CIRT is a member of FIRST and APCERT.
- BRPD v4.0-aligned methodology — Vulnerability assessment and penetration testing scoped to satisfy Bangladesh Bank's explicit ICT Security Guideline v4.0 requirement for banks and NBFIs.
- Web application testing included — Automated and manual testing covering SQL injection, XSS, and other web application vulnerabilities named in the Guideline.
- PDPA 2026-aware reporting — Reporting language reflects the Act's early-implementation status rather than overstating its enforcement maturity.
- Full VAPT scope — Network infrastructure, web applications, mobile apps, and APIs, following the same methodology detailed on our penetration testing services page.
- Remote delivery, India-based team — Engagements delivered remotely by our India-based technical bench, with on-site coordination available where an engagement requires it.
Why Bangladesh organisations choose eNeoteric
- Banking & NBFI focus — Deep familiarity with Bangladesh Bank's ICT Security Guideline v4.0 penetration-testing mandate and how examiners expect findings to be documented.
- Certified engineers — OSCP, CEH, and OSWE certified testers with financial-services and enterprise engagement experience.
- Honest regulatory framing — We describe the PDPA 2026 and NCSA accurately as early-stage frameworks rather than overstating their current enforcement reach — your compliance team gets precise, defensible language for board and auditor reporting.
- Clean, structured reports — CVSS-scored findings, proof-of-concept evidence, and remediation guidance suitable for Bangladesh Bank-facing documentation.
- Re-test included — A complimentary re-test verifies every finding has been remediated.
Frequently asked questions
- Does Bangladesh Bank require penetration testing for banks and NBFIs?
- Yes — explicitly. Bangladesh Bank's Guideline on ICT Security for Banks and Non-Bank Financial Institutions, Version 4.0 (issued via BRPD circular, June 19, 2023) requires banks and NBFIs to carry out regular vulnerability assessments — automated and manual, including web application testing for issues like SQL injection and XSS — and explicitly requires institutions to "carry out penetration tests... to conduct an in-depth evaluation of the security posture." This is one of the clearest, most explicit binding pentest mandates in the region, and we scope engagements to produce evidence directly against it.
- What is the Personal Data Protection Act, 2026, and how mature is its enforcement?
- The PDPA 2026 (Law 63 of 2026) was passed by Parliament in April 2026 following a fast legislative history — a draft in 2024, an Ordinance in November 2025, and amendments in February 2026. It is very new legislation, and some commentary notes its mandatory breach-notification and enforcement mechanisms are weaker than comparable regional data protection laws, with full enforcement mechanisms reportedly not activating until around May 2027. We treat it as a law in early implementation and frame compliance reporting accordingly, rather than claiming strong guaranteed enforcement.
- Who regulates cybersecurity in Bangladesh, and how established is the NCSA?
- The Cyber Security Ordinance 2025 established the National Cyber Security Agency (NCSA), Bangladesh's newly established national cybersecurity agency, formed in August 2025. As it was created by an interim-government ordinance, its long-term legal status depends on future parliamentary ratification. Bangladesh's national CERT function is handled separately by BGD e-GOV CIRT, which operates under the Bangladesh Computer Council and is a member of FIRST and APCERT.
- Does eNeoteric have an office in Bangladesh?
- No — eNeoteric does not have a physical office in Bangladesh. VAPT engagements are delivered remotely by our India-based technical team, with on-site coordination available where an engagement requires it (for example, physical network access or in-person scoping meetings).
- How long does a typical VAPT engagement take in Bangladesh?
- Most single-application or network engagements run 7-12 business days from kickoff to draft report, depending on scope. Banking and NBFI engagements scoped against the Bangladesh Bank ICT Security Guideline may take longer depending on system count. Contact us with your requirements for an exact timeline.
Have more questions?
Book Free ConsultationExplore related VAPT services
All Penetration Testing VAPT Vendor Comparison View all Cybersecurity
Bangladesh VAPT Pricing
Transparent, scope-based pricing — know your investment before you start.
- Network + web app VAPT
- BRPD v4.0-aligned report
- CVSS-scored findings
- Complimentary re-test
- Web app + network VAPT
- CVSS-scored findings
- Complimentary re-test
* All prices are indicative in USD and vary by scope and system count. Contact us for a fixed-price proposal.
Get in touch
Request a Callback
Drop your details and we'll call you back within one business day — or reach our team directly on +91 91080 15170.