Offensive depth, and the assurance layer around it.
We don't sell every acronym in the market. We go deep on the things that actually breach you — and wrap them in the governance, response and training that make the findings stick. Every engagement is senior-led, fixed-fee, and mapped to MITRE ATT&CK.
Penetration Testing & Red Teaming
Senior-led VAPT that chains scanner output into the attack path a real adversary would walk — and finds the paths a scanner can't see at all. Proof-of-exploit, business-impact rating, and a validated retest of every Critical and High are included, not extra.
- 01External & perimeter testingVPNs, gateways, public apps and APIs, exposed cloud footprint.
- 02Internal & lateral movementActive Directory / Entra ID privilege paths, segmentation, EDR coverage.
- 03Web, mobile & APIManual logic-flaw testing beyond automated scanner coverage.
- 04Red & purple teamObjective-based adversary simulation with detection-and-response validation.
Exposure Management (CTEM)
The interval between point-in-time tests is where most breaches are seeded. We run the Continuous Threat Exposure Management lifecycle so quiet weeks are quiet because nothing changed — not because nothing was checked.
- 01Continuous external attack-surface discoveryShadow assets, forgotten subdomains, certificate-transparency monitoring.
- 02Breach-and-attack simulationAutomated, ATT&CK-mapped emulation against agreed high-value paths.
- 03Prioritisation by real exploitabilityNot raw CVSS — what an attacker could actually chain, ranked.
- 04Executive exposure briefingA one-page board read on risk trend, each cycle.
Identity & Cloud Security
Attackers log in — so identity is a first-class scope, not an afterthought. We test the path from one valid credential to crown-jewel access, and the cloud posture that lets it happen.
- 01Identity-provider configuration reviewConditional access, MFA implementation, federation trust.
- 02Privilege-path analysisKerberoasting, delegation abuse, hybrid-trust weaknesses.
- 03Cloud posture & entitlement testingMisconfigurations, key sprawl, exposed serverless endpoints.
AI & Agentic Security Testing
As you deploy LLM and agentic systems, the attack surface now includes prompt injection, tool misuse, excessive agency and memory poisoning — risks with no equivalent in classical testing. We test them against the frameworks buyers now expect.
- 01LLM application testingPrompt injection, sensitive-information disclosure, output handling.
- 02Agentic system testingGoal hijack, tool misuse, excessive agency, rogue-agent scenarios.
- 03AI supply-chain & model integrityMapped to NIST AI RMF and MITRE ATLAS.
Digital Forensics & Incident Response
When something has already happened, the priority is a clean account of what, how far, and what now. We triage, evict and preserve evidence under documented chain-of-custody.
- 01Incident triage & scopingWhat was reached, what was taken, and whether they're still in.
- 02Forensic acquisition & analysisDefensible imaging and timeline reconstruction.
- 03Post-incident hardeningClose the path that was used, and the ones beside it.
Governance, Risk & Compliance
Findings only matter if they survive the boardroom. We translate technical risk into the language of POPIA, King IV and the standards your auditors and regulators apply.
- 01POPIA & privacy readinessIncluding breach-reportability assessment before the regulator decides for you.
- 02King IV & board reportingRisk framed for the people who must fund and accept it.
- 03ISO 27001 & PCI DSS alignmentControl gap analysis mapped to your obligations.
Security Training & Awareness
The human layer is part of the attack surface. We run measurable simulations and turn the results into training that actually moves the numbers.
- 01Simulated social engineeringMeasurable click, submit and report rates — under written authorisation.
- 02Awareness programmesLearning as a continuum: awareness, training, education.
- 03Executive & developer tracksTargeted content for the roles attackers target most.
Priced as a programme, not per finding.
A fixed-fee subscription removes any incentive to inflate finding counts or stretch scope. Each tier builds on the one before it.
- ✓ Four-week deep-dive VAPT cycle
- ✓ External, internal, app, identity & human scope
- ✓ Executive + technical reporting
- ✓ Retest of every Critical & High
- ✓ Live findings portal
- ✓ Everything in Foundational
- ✓ Continuous attack-surface monitoring
- ✓ Breach-and-attack simulation
- ✓ Deception & early warning
- ✓ Quarterly executive briefing
- ✓ AI / agentic assessment included
- ✓ Everything in Continuous
- ✓ Incident-support retainer
- ✓ Triage, eviction & handoff
- ✓ Priority response window