Offensive Security · CTEM · Johannesburg, ZA

Attackers log in.
They don't break in.

Decode is a senior-led, identity-first offensive-security practice. We test the way real adversaries actually operate — exfiltration-led and round-the-clock — then hand you the attack path and the proof it's closed. Not a scan. Not a PDF you file and forget.

Live · identity-first attack path T+00:00 · valid credential acquired
Stolen / phished credential
Initial Access
MFA fatigue · token theft
Credential Access
Legitimate remote tools
Lateral Movement
Identity-provider abuse
Priv. Escalation
Dominance · exfiltration
Impact

No exploit fired at any step — every move rides valid access and trusted tools. We test whether your controls would notice.

The threat reality

The clock is the product now.

Adversaries no longer break in — they log in, and they move faster than an annual test can see. The numbers that should set your testing cadence:

90min
Observed time from a public perimeter exploit to encryption-ready privilege.
11×
Year-on-year growth in data-only extortion.
88
Active ransomware brands tracked in H1 2025 — over a third entirely new.

A once-a-year penetration test assumes a timeline that no longer exists. Decode runs continuously — so quiet weeks are quiet because nothing changed, not because nothing was checked.

How we work

A programme, not a PDF.

Five principles separate this from a commodity scan. Every engagement operationalises Continuous Threat Exposure Management (CTEM) and maps to MITRE ATT&CK.

01

Manual-led, AI-accelerated

Automation is the floor of the assessment, never the ceiling. AI speeds discovery; a senior analyst verifies every exploited finding.

02

Identity-first

SSO, federation, conditional access, tokens and the path from one valid credential to crown-jewel access — tested as a first-class scope.

03

Outcome-defined

We agree the outcomes a real attacker would pursue, then prove whether each is reachable — domain dominance, fraud, exfiltration.

04

Continuous (CTEM)

Between deep-dive cycles we run attack-surface monitoring, breach-and-attack simulation and deception against the assets attackers probe.

Where we work

Built for high-stakes environments.

An internationally recognised African information-security practice, trusted where a breach is a board-level and regulatory event.

01 Telecommunications
02 Financial Services
03 Public Sector & Regulators
04 Critical Infrastructure
05 Education & Skills (SETAs)
06 Professional Services
Why Decode

Niche by choice. Deep by design.

A

Senior-led, every engagement

No juniors cutting their teeth on your network. Work is run by senior practitioners holding OSCP, OSEP, CREST, CEH and CISSP.

B

Vendor-independent

Findings are reported on their technical merit — never to position a tooling sale. The deliverable is risk reduction, not a shopping list.

C

Fixed-fee, retest included

Priced as a subscription, not per finding — so there's no incentive to inflate counts. Every Critical and High is retested to closure.

D

Written for people who act on it

An executive read on one page and a reproducible technical report for the engineer who has to close the finding.

Ready to uncover the truth?

Start with a short scoping conversation. We bring an opinion on what to test first; you bring the constraints. You'll have an engagement plan and fixed commercial schedule within five working days.