EncryptSec
Company Portfolio · 2025
Enterprise Cybersecurity

Built by Hackers.
Trusted by Enterprises.

Enterprise-grade offensive security, Zero Trust architecture, and 24/7 SOC operations for organizations in Nepal, US, UK, Japan, Korea, and beyond.

The Offensive Security Partner Enterprises Need.

EncryptSec was founded by offensive security practitioners who got tired of watching enterprises fail at the same preventable attacks. We built the firm we wished existed.

Most security firms sell confidence. We sell clarity — about what's broken, what's exposed, and what you need to do about it. Our team comes from red teams, SOCs, and incident response backgrounds across the US, UK, Japan, Korea, and Nepal.

We've cleaned up after ransomware gangs, nation-state APTs, and opportunistic threat actors alike. That experience is what we bring to every engagement — not slide decks or copy-pasted frameworks, but real-world adversarial thinking applied to your specific environment.

We operate on one assumption: you're already breached. This mindset forces us to design defenses that actually work, not just look good on paper.

Mission & Vision

Make enterprise-grade cybersecurity accessible, actionable, and effective — from Kathmandu to San Francisco, London to Seoul. Become the most trusted offensive security and Zero Trust partner across APAC, Europe, and North America.

01

Assume Breach

We design security programs as if adversaries already have a foothold.

02

Attacker Mindset

Our defenders think like attackers. Understanding breakage is prerequisite to protection.

03

Radical Transparency

We tell you what's wrong, even when uncomfortable. Real risk posture drives better decisions.

04

Speed Matters

We optimize detection, response, and remediation for speed.

05

Market-Native Expertise

We understand the regulatory and threat landscape of each market we serve.

06

Real Practitioners

Every engagement is led by certified professionals with hands-on experience.

500+
Engagements Completed
5+
Global Markets Served
1hr
Incident Response SLA
0
Client Breaches Post-Engagement

Twelve Specialized Cybersecurity Services.

From proactive testing to continuous defense — a full-stack security practice for modern enterprise infrastructure.

Penetration Testing & VAPT

OSCP/CEH-certified ethical hackers simulate real-world attacks across web apps, APIs, networks, and cloud.

WebAPINetwork
Zero Trust Implementation

Full Zero Trust architecture based on NIST SP 800-207: identity, device health, and microsegmentation.

IAMZTNA
Threat Hunting

Hypothesis-driven investigations using MITRE ATT&CK to find TTPs automated tools miss.

MITREAPT
SOC / MDR

24/7/365 security operations with SIEM, EDR, and human analyst triage.

24/7SIEMEDR
Cloud Security

CSPM, CNAPP, and workload protection for AWS, Azure, and GCP with IAM hardening.

AWSAzureGCP
Compliance & Auditing

ISO 27001, SOC 2, GDPR, NIS2, APPI, PIPA — multi-framework gap analysis and audit support.

ISOSOC2NIS2
Identity & Access Management

PAM, SSO, phishing-resistant MFA, and least-privilege policies to eliminate credential attacks.

PAMSSOMFA
AI Security

LLM red-teaming, prompt injection testing, model security audits, and AI governance.

LLMRed Team
OT / IoT Security

SCADA, ICS, and PLC security for manufacturing and critical infrastructure.

SCADAIEC 62443
Ransomware Protection & IR

Prevention, detection, and rapid recovery with 1-hour IR SLA and recovery playbooks.

ReadinessDFIR
Incident Response

Rapid containment, forensics, evidence preservation, and regulatory notification.

1hr SLAForensics
Attack Surface Management

Continuous discovery, monitoring, and risk scoring of external assets, shadow IT, and exposed services.

ReconMonitoring

Global Markets, One Standard.

We deliver the same rigorous security standard across primary markets, with local expertise in regulatory and threat landscapes.

🇺🇸United StatesPrimary

Fortune 500 to mid-market enterprises. CISA Zero Trust, SOC 2, HIPAA, FedRAMP.

SOC 2HIPAAFedRAMP
🇬🇧United KingdomPrimary

Financial services, NHS supply chain, critical infrastructure. NIS2 and Cyber Essentials.

NIS2GDPR
🇯🇵JapanGrowth

Automotive, manufacturing, financial sectors. OT/ICS expertise and APPI compliance.

APPIIEC 62443
🇰🇷South KoreaGrowth

Semiconductor, fintech, e-commerce. Defending against DPRK-linked APTs.

PIPAISMS-P
🇳🇵NepalHQ

Kathmandu HQ serving enterprises, fintech, edtech, government. Local IR and NRB alignment.

NRBIT Act
🌐Global & RemoteWorldwide

Remote delivery for SaaS, CPaaS, and e-commerce across MENA, APAC, Europe, North America.

RemoteSaaS

Enterprises & Teams That Bet On Security.

From Nepali startups to global CPaaS platforms — organizations trust us to protect their data, reputation, and operations.

Skill Shikshya
Vrit Technologies
SanitizeEmail
TheAuthorized Partner
CloudEdu
AbroadSathi
Everest Thrills
CEQUENS
Floorz Supplies
IDS
IDS Fintech
+ more

SaaS & Technology

  • Vrit Technologies · Nepal
  • SanitizeEmail · Global
  • Signal Layer · Global
  • TheAuthorized Partner · Nepal

Fintech & Insurance

  • IDS Fintech · Lebanon
  • Comin Insurance · Global
  • Floorz Supplies · Global
  • CEQUENS · MENA

EdTech & Travel

  • Skill Shikshya · Nepal
  • CloudEdu.com.au · Nepal
  • AbroadSathi · Nepal
  • Everest Thrills · Nepal

Organizations We've Successfully Secured.

From global streaming platforms to Nepali government bodies and high-traffic commerce.

Netflix
Netflix
State of California
State of California
Government of Nepal
Government of Nepal
QFX Cinemas
QFX Cinemas
WorldLink
WorldLink
Foodmandu
Foodmandu
Mero Kirana
Mero Kirana
Smart Doko
Smart Doko
Hukut
Hukut
Kumari Job
Kumari Job
ITTI
ITTI
Your org next?

Recognized by the World's Biggest Names

Our researchers have responsibly disclosed vulnerabilities to leading global organizations.

Apple
Amazon
Zomato
Netflix
California
Google
Tesla
Okta
HubSpot
Comcast
Lenovo
Perplexity
ClickUp
Ola
inDrive
Responsible Disclosure

Proven Impact Across Industries.

Engagements where our work directly changed a client's risk posture and business outcome.

GlobalFinX Technologies
🇺🇸 Financial Services · USA

The Challenge

A $2B fintech processing 12M daily transactions had grown through 4 acquisitions, leaving a fragmented network with 23 separate identity systems and flat architecture enabling lateral movement.

What We Did

Deployed Zero Trust across all entities, consolidated identities into one IAM platform with phishing-resistant MFA, microsegmented payment infrastructure, and stood up 24/7 SOC.

78%
Attack Surface ↓
3
Critical Vulns Fixed
0
Breaches Since
NipponAuto Parts
🇯🇵 Manufacturing / OT · Japan

The Challenge

An automotive parts manufacturer detected anomalous traffic on their OT network. A suspected state-sponsored APT was dormant in the ICS environment for ~4 months near CNC controllers.

What We Did

Emergency IR contained the threat in 6 hours. Full forensic investigation, IEC 62443-compliant OT monitoring across 8 facilities, and APPI breach notification within 72 hours.

6hr
Containment
¥0
Downtime
8
Facilities Secured
Meridian Capital UK
🇬🇧 Financial Services · UK

The Challenge

A £4B AUM investment firm faced a NIS2 deadline with 47 high-risk AWS misconfigurations and no formal cloud security program. Regulators had flagged the firm.

What We Did

Deployed CSPM across the full AWS estate, remediated all 47 misconfigs in 3 weeks, conducted VAPT on 12 apps, and built complete NIS2 documentation.

47
Misconfigs Fixed
3wk
Remediation
NIS2 Certified
Vrit Technologies
🇳🇵 SaaS · Nepal

The Challenge

A fast-growing SaaS builder ran four public-facing products with APIs exposed to the internet and no formal secure-SDLC or vulnerability management process.

What We Did

End-to-end VAPT of all four platforms, API security review, secure coding training, and ongoing retainer-based security support for the engineering team.

4
Products Secured
100%
API Coverage
0
Critical Post-Remediate

Practitioners, Not Consultants.

Our founding team is built from Nepali and international offensive security researchers with real-world disclosures and hands-on certifications.

SG
Shubham Gupta
Security Researcher & Pentester

OSCP+ certified. Web, mobile, API, and Web3 security. Hall of Fame at Apple, Amazon, and Zomato.

OSCP+Web3MobileAPI
VG
Veshraj Ghimire
Senior Penetration Tester

OSCP, CREST CRT, CRTP. Deep expertise in Active Directory, web apps, and infrastructure exploitation.

OSCPCREST CRTCRTPeWPTxv2CEH
PK
Pankaj Kumar Yadav
Security Engineer

CEH supporting Kathmandu operations. Focuses on vulnerability assessment, security ops, and client engagement.

CEHVAPTSecurity Ops

Aligned With Frameworks That Matter

Our methodologies map to internationally recognized security standards.

OSCP / CEH

Offensive Security Certified Professionals lead every penetration test.

CISSP / CISA

Senior consultants hold enterprise security and auditing certifications.

CREST

Internationally recognized offensive and defensive security standards.

IEC 62443

Industrial cybersecurity framework for OT/ICS environments.

NIST 800-207

Zero Trust architecture foundation for identity and network design.

MITRE ATT&CK

Threat hunting and detection engineering mapped to adversary TTPs.

ISO 27001

Information security management system implementation and audit support.

SOC 2 / GDPR

Trust services and data protection compliance for SaaS and global clients.

Trusted by Teams Across Kathmandu.

Feedback from the Nepali startups, edtech platforms, SaaS companies, and travel businesses we protect.

"We teach cybersecurity to hundreds of students — so we can't afford a weak security posture ourselves. EncryptSec's VAPT was thorough, their findings were real, and the remediation guidance was practical."

Ashok ThapaHead of Operations, Skill Shikshya · Kathmandu

"We run 4 SaaS products simultaneously with APIs exposed to the internet. EncryptSec did a thorough pentest, found real vulnerabilities, and helped us build a security-first culture across the entire engineering team."

Umesh SubediCo-Founder, Vrit Technologies · Kathmandu

"International travelers book with us using credit cards and passport details. EncryptSec found serious gaps in our payment infrastructure we didn't know existed. Now it's a platform we're proud to stand behind."

Amir ShresthaCo-Founder & Operations Lead, Everest Thrills · Kathmandu

"We had a security incident that exposed user data on our education platform. EncryptSec contained it within hours and rebuilt our entire security architecture in weeks. Our users' trust was fully restored."

Ronish DhakalFounder & CEO, College Info Nepal · Kathmandu

"We handle passport scans and financial records for thousands of students. EncryptSec gave us genuine confidence our platform is actually safe — not just ticking compliance boxes."

CloudEdu.com.auEducation & Visa Consultancy · Nepal

"Our vendor credentials and client data are our most critical assets. EncryptSec's zero trust framework gave us absolute confidence in our access controls. Professional, fast, genuinely expert."

Anish GautamManaging Director, TheAuthorized Partner · Nepal

Ready to Move From
Assumed to Assured?

Book a free 30-minute security consultation. We'll identify your top three risk areas and outline a practical remediation roadmap.

Get In Touch

hello@encryptsec.com encryptsec.com +977-9861601174

Kathmandu, Nepal · Serving US, UK, Japan, Korea & beyond