Services

Offensive depth, and the assurance layer around it.

We don't sell every acronym in the market. We go deep on the things that actually breach you — and wrap them in the governance, response and training that make the findings stick. Every engagement is senior-led, fixed-fee, and mapped to MITRE ATT&CK.

Flagship · Offensive

Penetration Testing & Red Teaming

Senior-led VAPT that chains scanner output into the attack path a real adversary would walk — and finds the paths a scanner can't see at all. Proof-of-exploit, business-impact rating, and a validated retest of every Critical and High are included, not extra.

External & InternalWeb & MobileRed / Purple teamAssumed breachOWASP · PTES · OSSTMM
  • 01
    External & perimeter testingVPNs, gateways, public apps and APIs, exposed cloud footprint.
  • 02
    Internal & lateral movementActive Directory / Entra ID privilege paths, segmentation, EDR coverage.
  • 03
    Web, mobile & APIManual logic-flaw testing beyond automated scanner coverage.
  • 04
    Red & purple teamObjective-based adversary simulation with detection-and-response validation.
Continuous

Exposure Management (CTEM)

The interval between point-in-time tests is where most breaches are seeded. We run the Continuous Threat Exposure Management lifecycle so quiet weeks are quiet because nothing changed — not because nothing was checked.

Attack-surface monitoringBreach & attack simulationDeceptionQuarterly briefing
  • 01
    Continuous external attack-surface discoveryShadow assets, forgotten subdomains, certificate-transparency monitoring.
  • 02
    Breach-and-attack simulationAutomated, ATT&CK-mapped emulation against agreed high-value paths.
  • 03
    Prioritisation by real exploitabilityNot raw CVSS — what an attacker could actually chain, ranked.
  • 04
    Executive exposure briefingA one-page board read on risk trend, each cycle.
Core

Identity & Cloud Security

Attackers log in — so identity is a first-class scope, not an afterthought. We test the path from one valid credential to crown-jewel access, and the cloud posture that lets it happen.

Active Directory · Entra IDSSO & federationToken & sessionAWS · Azure · GCP
  • 01
    Identity-provider configuration reviewConditional access, MFA implementation, federation trust.
  • 02
    Privilege-path analysisKerberoasting, delegation abuse, hybrid-trust weaknesses.
  • 03
    Cloud posture & entitlement testingMisconfigurations, key sprawl, exposed serverless endpoints.
New for 2026

AI & Agentic Security Testing

As you deploy LLM and agentic systems, the attack surface now includes prompt injection, tool misuse, excessive agency and memory poisoning — risks with no equivalent in classical testing. We test them against the frameworks buyers now expect.

OWASP Top 10 for LLMsOWASP Agentic (ASI)NIST AI RMFMITRE ATLAS
  • 01
    LLM application testingPrompt injection, sensitive-information disclosure, output handling.
  • 02
    Agentic system testingGoal hijack, tool misuse, excessive agency, rogue-agent scenarios.
  • 03
    AI supply-chain & model integrityMapped to NIST AI RMF and MITRE ATLAS.
Respond

Digital Forensics & Incident Response

When something has already happened, the priority is a clean account of what, how far, and what now. We triage, evict and preserve evidence under documented chain-of-custody.

Breach triageContainment & evictionForensic imagingChain-of-custody
  • 01
    Incident triage & scopingWhat was reached, what was taken, and whether they're still in.
  • 02
    Forensic acquisition & analysisDefensible imaging and timeline reconstruction.
  • 03
    Post-incident hardeningClose the path that was used, and the ones beside it.
Assure

Governance, Risk & Compliance

Findings only matter if they survive the boardroom. We translate technical risk into the language of POPIA, King IV and the standards your auditors and regulators apply.

POPIAKing IVISO 27001PCI DSS
  • 01
    POPIA & privacy readinessIncluding breach-reportability assessment before the regulator decides for you.
  • 02
    King IV & board reportingRisk framed for the people who must fund and accept it.
  • 03
    ISO 27001 & PCI DSS alignmentControl gap analysis mapped to your obligations.
Strengthen

Security Training & Awareness

The human layer is part of the attack surface. We run measurable simulations and turn the results into training that actually moves the numbers.

Phishing simulationVishing & pretextRole-based trainingMetrics & reporting
  • 01
    Simulated social engineeringMeasurable click, submit and report rates — under written authorisation.
  • 02
    Awareness programmesLearning as a continuum: awareness, training, education.
  • 03
    Executive & developer tracksTargeted content for the roles attackers target most.
Engagement models

Priced as a programme, not per finding.

A fixed-fee subscription removes any incentive to inflate finding counts or stretch scope. Each tier builds on the one before it.

Foundational
Compliance & entry point
  • Four-week deep-dive VAPT cycle
  • External, internal, app, identity & human scope
  • Executive + technical reporting
  • Retest of every Critical & High
  • Live findings portal
Most chosen
Continuous
Ongoing exposure management
  • Everything in Foundational
  • Continuous attack-surface monitoring
  • Breach-and-attack simulation
  • Deception & early warning
  • Quarterly executive briefing
  • AI / agentic assessment included
Continuous Plus
Regulated & high-risk
  • Everything in Continuous
  • Incident-support retainer
  • Triage, eviction & handoff
  • Priority response window

Tell us what keeps you up at night.

A short scoping call, an opinion on what to test first, and a fixed commercial schedule within five working days.