We run seven interlocking practices, from board strategy to a 24/7 SOC. This is the one that proves the rest: a real attack path, four findings every tool rated low or ignored, and the twenty-six minutes they cost.
Engagement excerpt — one path, five steps
Composite. Names, addresses and timings changed.
- ExposedLowExposedLow
- LeakedLowLeakedLow
- ValidMediumValidMedium
- EscalateHighEscalateHigh
- OwnedCriticalOwnedCritical
The pipeline deploys to production
Change the build definition and the runner executes it holding deploy credentials. Twenty-six minutes from the first DNS lookup to code running in the production estate.
Evidence
deploy-role → * · 26m elapsed
Automated scan
Not reported
A scanner saw step one and filed it as informational. It had no reason to try the key, and no way to know the bucket it opened held the build definitions. Five findings is a list. This is a path.
§ 01 — Conviction
An automated scan tells you what is unpatched. Only an operator tells you what is reachable — how three dull findings chain into a breach, and what somebody walks out with.
- 20+
- Engagements delivered
- 100%
- Testing executed right
- R0
- Charged for remediation retests
§ 02 — The practice
Seven interlocking practices, one orchestrated defence.
Data protection sits at the core; the other six protect, govern and enable it. Engage one capability or the whole system.
- 01Cyber Strategy & TransformationArchitect a security posture that scales with ambition — from board-level strategy to operating model design.
- 02Managed Defence Services24/7 detection and response from our regional SOC. Threats answered in minutes, not days.
- 03Risk, Compliance & ResilienceNavigate POPIA, the Joint Standard and global frameworks with pragmatic, audit-ready controls.
- 04Data Protection & PrivacyGovern data across its lifecycle — classify, secure, and prove it, end to end.
- 05Identity & Privileged AccessZero-trust identity for people, machines and partners. Frictionless yet uncompromising.
- 06Architecture & Operational TechnologySecure cloud, OT and emerging technology by design — from blueprint to brownfield.
- 07Technical Security AssessmentsVAPT, red team, purple team and adversary simulation — pressure-tested by operators who think like attackers.
Most clients start with one practice and add others as the estate and the obligations grow.
How they interlock
§ 03 — Testing
Inside assessments: seven testing disciplines.
Practice 07 in detail. Each discipline is executed by a senior tester against a threat model built for your estate, proven by exploitation, and retested free once you have fixed it.
- ApplicationWeb Application & API TestingManual, exploit-led testing of the applications and APIs your business runs on.
- InfrastructureNetwork & Infrastructure TestingExternal and internal intrusion testing that proves how far an attacker really gets.
- CloudCloud & Kubernetes TestingAWS, Azure, GCP and container estates attacked the way real operators attack them.
- ApplicationMobile Application TestingiOS and Android binaries, storage and backends pulled apart on real devices.
- Full scopeRed Team & Adversary SimulationObjective-driven, multi-vector campaigns run against your live defences.
- HumanSocial Engineering & PhishingPhishing, vishing and physical intrusion that test the human perimeter safely.
- ProgrammeContinuous Pentesting (PTaaS)Testing that keeps pace with your releases, with findings streamed as they're found.
§ 04 — How an engagement runs
Five steps, in this order, every time.
No engagement starts without a signed authorisation letter and an agreed blast radius. Nothing about the process is improvised.
- 01
Scope
Targets, roles and rules of engagement agreed in writing. Fixed price, named lead tester, signed authorisation before anything is touched.
- 02
Map
We enumerate what you actually expose, which is routinely more than the asset register says, and build the threat model the testing runs against.
- 03
Exploit
Manual attack execution and chaining. Criticals reach you the day we find them, by phone, not in a report six weeks later.
- 04
Report
Reproduction steps, evidence, business impact and a remediation order of play. Written to be handed straight to your engineers.
- 05
Retest
You fix, we verify, at no extra cost. Closes with an attestation letter your auditors and enterprise customers accept.
§ 05 — What you get
Four things land on your desk.
A pentest is only worth what your team can do with it on the Monday after.
A report an engineer can act on
Every finding carries the exact request, the payload, the evidence and the fix. No screenshots of a scanner dashboard.
A readout for the people who fund it
A separate executive summary in plain language, plus a walkthrough call with whoever needs to hear it.
A free retest
Fix the findings and we verify them at no charge, then reissue the report with the closures recorded.
An attestation letter
Formatted for SOC 2, ISO 27001, PCI DSS and customer due-diligence questionnaires. A redacted shareable version on request.
§ 06 — Sectors
Threat-modelled for your industry.
Adversaries, regulators and downtime tolerance differ by sector. So do the rules of engagement we write.
Financial Services
Payment rails, open banking APIs and core platforms tested the way fraudsters test them.
Government & Public Sector
Citizen-facing portals and legacy estates probed before a hostile actor gets there.
Healthcare & Medical Schemes
Patient platforms, claims systems and clinical networks tested without disrupting care.
Mining, Energy & Utilities
IT-to-OT attack paths proven safely, before an incident stops production.
Telecommunications & Technology
Continuous testing that keeps pace with the rate you ship.
Retail & Consumer
Checkout, loyalty and store systems attacked before peak trade does it for you.
§ 07 — Start
Send us the scope. We'll tell you what we'd attack.
A fixed-price proposal, a named lead tester and a start date, within one business day. If we think you need something other than a pentest, we'll say so.

