About
Attackers by trade. Accountable by contract.
Phalandwa is an offensive security practice. We think and work like the adversaries targeting the organisations building what comes next, then hand over everything we found and exactly how we did it.
The name
Phalandwa — the one who overcomes.
The mark is three ribbons woven into a hexagon. Follow any one of them and it passes over the next, then under the one after that. No single ribbon holds the shape; the interlock does.
That is the whole argument of this practice. Breaches are almost never one catastrophic hole. They are four dull findings that nobody thought to connect, and the work is seeing the connection before somebody else does.
How we work
Four things we commit to in writing.
These are in the engagement letter, not just on the website.
A named operator, not a queue
You get the name of the person testing your estate before the engagement starts, and they stay on it until the findings are closed. No handover to a junior at the reporting stage.
Tooling assists, it never decides
Scanners run, because they are good at breadth. Every finding that reaches your report was reached and proven by a person who can explain exactly how.
Criticals reach you the same day
If we get domain admin on a Tuesday morning you hear about it on Tuesday morning, by phone. Nothing severe waits for the report.
We say when you don't need us
If a scoping call makes clear that a pentest is the wrong spend right now, we say so and tell you what to do instead. It costs us a sale and earns the next three.
Credentials
Certified, and held to it.
Our practitioners hold the accreditations auditors and regulators ask about. We also certify our own practice to the frameworks we advise on.
Frameworks we work to
- ISO/IEC 27001 & 27701
- NIST Cybersecurity Framework 2.0
- POPIA & the Joint Standard 2 of 2024
- PCI DSS v4.0
- MITRE ATT&CK & CIS Controls v8
- OWASP ASVS, WSTG & MASVS
Practitioner certifications
- CISSP · CISM · CISA
- OSCP
- CCSP · AWS & Azure security specialties
- CIPP/E · CIPM (privacy)
- ISO 27001 Lead Auditor & Lead Implementer
Independently assessed

AICPA SOC 2 Type II
Independently audited

ISO/IEC 27001
Certified

CREST
Member
- 1 business day
- Response to every enquiry
- 24/7
- Regional detection & response
- 3
- African markets served
Start here
Tell us what you're protecting.
A scoping call takes half an hour. You will leave it knowing what we would test first and roughly what it costs.

