We assess risk based on how threat actors actually operate against organisations in your sector — not based on what a vulnerability scanner reports. That distinction shapes every engagement we deliver, from penetration testing to board governance.
Based in Johannesburg. Delivering globally.
About UsSenior security leadership on a retained basis. Strategy, risk governance, and board reporting — structured around the hours your organisation requires.
Gap analysis, remediation planning, and ongoing compliance management for ISO 27001, NIS2, DORA, SOC 2, PCI DSS 4.0, and POPIA.
Adversarial testing and conformity assessment for LLM deployments, ML pipelines, and AI-driven systems. OWASP LLM Top 10 and EU AI Act aligned.
Intelligence-driven assessment that replicates how your organisation would actually be targeted. MITRE ATT&CK mapped. TIBER-EU and CBEST aligned.
Guaranteed response SLA, quarterly readiness exercises, and insurance-aligned engagement terms. Preparation before the breach, not after.
Risk quantification, board briefings, tabletop exercises, and NIS2/DORA management body training. Technical risk translated into business language.
Every engagement begins with a scoping conversation. No obligation, no sales pitch — a direct discussion about your environment and what you need.






