About JTech
JTech is a cybersecurity consulting firm based in Johannesburg, delivering security assessment, governance, and incident response services to organisations across the UK, EU, Middle East, and Africa. We operate as a focused practice — not a generalist IT services company that added a security line to its catalogue.
Our engagements are intelligence-driven. We assess risk based on how threat actors actually operate against organisations in your sector, not based on what a vulnerability scanner reports. That distinction shapes everything we deliver: from the way we scope penetration tests to the metrics we present to boards.
How We Work
Every engagement starts with a defined scope, a clear set of deliverables, and a timeline. We do not sell hours without outcomes. Whether the engagement is a two-day AI threat model or a twelve-month vCISO retainer, the client knows what they will receive before work begins.
Methodology-Driven, Not Tool-Driven
Tools change. Methodologies endure. Our assessments follow established frameworks — PTES for penetration testing, MITRE ATT&CK for threat mapping, FAIR for risk quantification, TIBER-EU for regulatory-mandated testing — because frameworks create reproducible, auditable results. When we map a finding to ATT&CK technique T1078 (Valid Accounts), that mapping means the same thing to your SOC team, your auditor, and your insurer.
Evidence Over Opinion
Our reports present evidence. An attack path we document includes the exact steps taken, the tools used, the controls that failed, and the controls that held. A risk quantification includes the data sources, the assumptions, and the confidence interval. We show our working because the value of a finding depends on the rigour behind it.
Business Language, Not Just Technical Language
A critical vulnerability on a development server with no production access is not a critical business risk. We translate technical findings into the operational and financial impact that decision-makers need to allocate resources. Every executive summary we deliver answers the question boards actually ask: “What does this mean for our business, and what should we do about it?”
Credentials and Frameworks
Our consultants hold professional certifications from ISC2, Offensive Security, and EC-Council. We maintain active competency in the frameworks and standards relevant to our service areas. Certifications matter as evidence of verified competence — but they are a baseline, not a differentiator. What separates useful security consulting from compliance theatre is the experience to apply these frameworks to real environments under real constraints.
Frameworks We Apply
- Assessment: PTES, OWASP Testing Guide, OWASP LLM Top 10, MITRE ATT&CK, MITRE ATLAS
- Governance: ISO 27001:2022, NIST CSF 2.0, COBIT 2019, King V
- Compliance: NIS2, DORA, EU AI Act, PCI DSS 4.0, SOC 2, POPIA, GDPR
- Risk: FAIR (Factor Analysis of Information Risk), ISO 27005, ISO 31000
- Testing: TIBER-EU, CBEST, STAR-FS, CREST methodologies
- Intelligence: F3EAD cycle, Diamond Model, STIX/TAXII
Global Delivery
We are based in Johannesburg (GMT+2), which provides near-complete business hours overlap with the UK, European Union, and Middle Eastern markets we serve. The majority of our engagements are delivered remotely — this has been our standard operating model, not an adaptation.
Remote delivery does not mean reduced capability. Security assessments, compliance readiness, vCISO governance, and incident response coordination are all conducted effectively through secure remote channels. Where an engagement requires on-site presence — forensic evidence collection, physical security testing, or board presentations that benefit from direct interaction — we arrange it.
For organisations subject to data handling regulations, we operate under Standard Contractual Clauses (SCCs) for EU engagements and comply with POPIA requirements domestically. Data sovereignty and secure handling practices are defined during scoping, before any engagement begins.
What We Do Not Do
Clarity about scope matters as much as capability. We are not a managed security services provider. We do not sell or resell security products. We do not operate SOCs or manage firewalls. We do not compete with your existing vendors or internal team.
We assess, advise, test, and govern. When an engagement concludes, the client retains every deliverable, every finding, and every recommendation — with no dependency on our platform, our tooling, or continued engagement to access their own security data.






