Skip to content

About

Attackers by trade. Accountable by contract.

Phalandwa is an offensive security practice. We think and work like the adversaries targeting the organisations building what comes next, then hand over everything we found and exactly how we did it.

The name

Phalandwa — the one who overcomes.

The mark is three ribbons woven into a hexagon. Follow any one of them and it passes over the next, then under the one after that. No single ribbon holds the shape; the interlock does.

That is the whole argument of this practice. Breaches are almost never one catastrophic hole. They are four dull findings that nobody thought to connect, and the work is seeing the connection before somebody else does.

How we work

Four things we commit to in writing.

These are in the engagement letter, not just on the website.

A named operator, not a queue

You get the name of the person testing your estate before the engagement starts, and they stay on it until the findings are closed. No handover to a junior at the reporting stage.

Tooling assists, it never decides

Scanners run, because they are good at breadth. Every finding that reaches your report was reached and proven by a person who can explain exactly how.

Criticals reach you the same day

If we get domain admin on a Tuesday morning you hear about it on Tuesday morning, by phone. Nothing severe waits for the report.

We say when you don't need us

If a scoping call makes clear that a pentest is the wrong spend right now, we say so and tell you what to do instead. It costs us a sale and earns the next three.

Credentials

Certified, and held to it.

Our practitioners hold the accreditations auditors and regulators ask about. We also certify our own practice to the frameworks we advise on.

Frameworks we work to

  • ISO/IEC 27001 & 27701
  • NIST Cybersecurity Framework 2.0
  • POPIA & the Joint Standard 2 of 2024
  • PCI DSS v4.0
  • MITRE ATT&CK & CIS Controls v8
  • OWASP ASVS, WSTG & MASVS

Practitioner certifications

  • CISSP · CISM · CISA
  • OSCP
  • CCSP · AWS & Azure security specialties
  • CIPP/E · CIPM (privacy)
  • ISO 27001 Lead Auditor & Lead Implementer

Independently assessed

  • AICPA SOC 2 Type II

    AICPA SOC 2 Type II

    Independently audited

  • ISO/IEC 27001

    ISO/IEC 27001

    Certified

  • CREST

    CREST

    Member

1 business day
Response to every enquiry
24/7
Regional detection & response
3
African markets served

Start here

Tell us what you're protecting.

A scoping call takes half an hour. You will leave it knowing what we would test first and roughly what it costs.