0 add-ons selected
TRANSPARENT PRICING · ZAR · NO HIDDEN FEES

ChooseYour
SecurityPlan

Professional penetration testing and security assurance. Every plan includes a retest. No surprises. Just results.

> All prices in South African Rand (ZAR) · USD rates available on request
NDA First
From first contact
Retest Included
Every plan
24hr Response
Consultation guaranteed
Fixed Scope
No scope-creep fees
⚡ BEST STARTING POINT
Entry Level

PULSE
Is My Practice Exposed?

R9,500

once-off · automated scan, human-verified · know where you stand

  • Nessus Pro authenticated scan — up to 20 devices
  • Automated scan, human-verified — no false-positive noise
  • 1-page Executive Summary in plain language
  • POPIA-relevant findings highlighted
  • Top 10 remediation priorities by breach impact
  • NDA signed before any work begins
  • Want us to actually exploit what we find? Upgrade to SHIELD
Professional

SHIELD
Prove It's Actually Secure.

R24,000

once-off · manual pentest + retest · compliance-ready

  • Everything in PULSE
  • 1× Full retest of remediated findings — included
  • Human testers chain vulnerabilities — like real attackers
  • Burp Suite Pro exploitation across web apps & APIs
  • Screen recordings your board can actually follow
  • Executive summary + fix-by-fix remediation roadmap
  • POPIA compliance notes; PCI DSS findings referenced
Enterprise

PHANTOM
Full Red Team + Retainer

POA

custom scope · red team · enterprise coverage

Typically R180k – R350k / yr

  • Everything in GUARDIAN
  • Full red team — people, process & technology tested together
  • Social engineering & phishing simulations
  • Priority incident response support with agreed SLA
  • Monthly continuous assessments
  • Custom SLA & compliance framework

Enhance Your Package

Add-ons are gated to the package that makes them meaningful. Select your base package — watch what unlocks.

Select a package in the quote builder to see available add-ons
OFFENSIVE TESTING
POPULAR SHIELD+
REQUIRES SHIELD+
Click to upgrade

Web App Deep Dive

Extended Burp Pro testing, full OWASP Top 10 coverage, business logic flaws, auth bypass attempts.

R8,000
SHIELD+
REQUIRES SHIELD+
Click to upgrade

API Security Testing

REST/GraphQL endpoint testing, authentication flaws, rate limiting, injection, BOLA/IDOR vulnerabilities.

R6,000
SHIELD+
REQUIRES SHIELD+
Click to upgrade

Wireless Assessment

WiFi security audit, rogue AP detection, WPA2/WPA3 testing, guest network isolation verification.

R5,000
SHIELD+
REQUIRES SHIELD+
Click to upgrade

Cloud Security Review

AWS/Azure/GCP configuration audit, IAM review, S3/blob exposure, security group analysis.

R10,000
SOCIAL ENGINEERING
POPULAR ALL TIERS
REQUIRES SHIELD+
Click to upgrade

Phishing Simulation

Custom phishing campaign targeting up to 50 employees with tracking, credential capture, and detailed report.

R3,500
ALL TIERS
REQUIRES SHIELD+
Click to upgrade

Vishing Test

Voice/phone social engineering test. Pretexting calls to reception, IT helpdesk, or specified targets.

R4,000
ADVANCED SHIELD+
REQUIRES SHIELD+
Click to upgrade

Evilginx2 MFA Bypass Simulation

Adversary-in-the-middle phishing simulation that bypasses MFA. Tests whether your staff — and your authentication controls — can withstand real credential-harvesting attacks that standard phishing tests don't catch.

R7,500
TRAINING & AWARENESS
POPULAR ALL TIERS
REQUIRES SHIELD+
Click to upgrade

Staff Security Training

2-hour interactive session for up to 20 staff. Covers phishing, passwords, social engineering, safe browsing.

R3,500
SHIELD+
REQUIRES SHIELD+
Click to upgrade

Executive Briefing

1-hour board/C-suite presentation. Risk landscape, findings summary, strategic recommendations.

R5,000
COMPLIANCE & CONTINUITY
SHIELD+
REQUIRES SHIELD+
Click to upgrade

POPIA Compliance Pack

Gap analysis, documentation review, compliance roadmap, and Information Officer support guidance.

R8,000
ALL TIERS
REQUIRES SHIELD+
Click to upgrade

Backup & DR Validation

Test your backup restoration, RTO/RPO verification, ransomware resilience check.

R4,500
SHIELD+
REQUIRES SHIELD+
Click to upgrade

Dark Web Monitoring

12-month credential leak monitoring for your domain. Instant alerts when employee data appears.

R6,000/yr
SHIELD+
REQUIRES SHIELD+
Click to upgrade

IR Plan Development

Custom incident response plan, escalation procedures, communication templates, tabletop exercise.

R7,500
LIVE QUOTE BUILDER
Select base package:
GUARDIAN Package R84,000
ESTIMATED TOTAL R84,000
You save vs. ad-hoc

Final pricing confirmed in written scope of work

Full Feature Comparison

Everything you get — no fine print surprises.

Feature
PULSE
SHIELD
GUARDIAN
PHANTOM
Nessus Pro vulnerability scan
✓ ×4/yr
✓ Monthly
Manual penetration testing
✓ ×4/yr
✓ Monthly
Burp Suite Pro exploitation
CVSS-scored findings report
Executive summary
✓ 1-page
Technical findings + PoC evidence
Remediation roadmap
Top 10
Retest / verification
✓ ×1
✓ ×4/yr
✓ Per test
POPIA-relevant findings flagged
✓ Full
✓ Custom
Guest WiFi assessment
+Add-on
+Add-on
+Add-on
✓ Incl.
Dedicated security advisor
Incident response support
✓ 24/7
Phishing & social engineering
+Add-on
+Add-on
+Add-on
✓ Incl.
Security awareness training
+Add-on
+Add-on
+Add-on
✓ Incl.
NDA & confidentiality
Price
R9,500
R24,000
R84,000/yr
POA
Included
+Add-on Available — see add-ons
Not available

R24,000 vs
R10,000,000

The average data breach costs a South African organisation R10 million+ in downtime, legal fees, regulatory fines, and reputational damage (IBM CDR 2024). Our SHIELD pentest costs the same number — with three fewer zeroes.

And that's before you factor in that the average attacker is in your network 194 days before detection — racking up costs the entire time.

SEE YOUR BREACH COST TICK LIVE →
Avg. breach cost (SA, 2024)R 10M+
GUARDIAN Quarterly RetainerR84,000/yr
SHIELD Full PentestR24,000

The bars are to scale.

Your Breach Risk Calculator

See how your estimated breach exposure stacks up against the cost of protecting yourself.

COMPANY SIZE
INDUSTRY RISK LEVEL
MONTHLY REVENUE (ZAR)
R
ESTIMATED BREACH EXPOSURE
R4.5M
downtime · legal fees · reputational damage
SHIELD pentest cost R24,000
GUARDIAN annual cost R84,000/yr
Your Protection ROI 118x
breach exposure ÷ GUARDIAN annual cost

Frequently Asked

Our tests include passive and active reconnaissance, vulnerability scanning, manual exploitation attempts, privilege escalation testing, lateral movement simulation, and post-exploitation analysis. Every test concludes with a comprehensive report that maps findings to business risk — not just CVE IDs — with a clear remediation priority order.

A Single Assessment typically takes 2–3 weeks from signed scope to final report delivery. This includes the active testing window (usually 5–10 business days depending on scope), report writing, and an initial findings briefing. Timeline varies based on scope complexity. We confirm everything in writing before starting.

Yes — all reports are structured to support compliance requirements. We produce findings mapped to PCI DSS, SOC 2 Type II, ISO 27001, POPIA, and NIST CSF as required. For GUARDIAN and PHANTOM tiers, we include quarterly compliance posture updates and a compliance roadmap as part of the engagement.

The retest verifies that every vulnerability identified in the original assessment has been genuinely closed — not just documented as patched. We re-exploit each finding category to confirm it's no longer accessible, and perform regression testing to check that fixes haven't introduced new vulnerabilities. You receive a final certification report suitable for auditors, board members, and insurers.

Always. We sign NDA before any technical discussion, before receiving any documentation, and certainly before any active testing begins. Client confidentiality is foundational to how we operate — we have never disclosed a client name, finding, or engagement detail without explicit written permission.

Absolutely. These tiers are starting points — the real scope of every engagement is defined in a written Statement of Work agreed before anything begins. Whether you need a single API tested, a red team exercise, or a multi-phase engagement, we'll scope it accurately and quote it in writing. No scope creep, no surprise invoices.

Automated scanners find what they're programmed to find — usually the obvious stuff. They don't chain vulnerabilities together, miss business logic flaws, generate enormous false-positive noise, and produce reports that mean nothing to a board or insurer. Real attackers are human. Our testers think like humans. A scanner has never found SQL injection hidden behind a custom authentication layer. We have.

How It Works

From first contact to final report — here's exactly what happens, in order. No surprises, no upsells after you've signed.

01
FREE CONSULTATION
30-minute call — you describe your environment, we tell you exactly what we'd test and what we'd expect to find. Zero obligation, zero hard sell.
02
WRITTEN SCOPE & NDA
We issue a Statement of Work with a fixed price, explicit scope boundaries, rules of engagement, and timeline. You sign the NDA. Nothing starts until you approve both in writing.
03
ENGAGEMENT BEGINS
Testing runs to the agreed schedule. You receive a full report, a live debrief, and a retest once your team has addressed the findings. Final invoice on completion.
RESPONSE TIME
Within 24 hours
PAYMENT
50% deposit · 50% on delivery
CONFIDENTIALITY
NDA before any info shared

Still Have Questions?

Let's talk through your specific security needs. Free consultation — no commitment, no hard sell. We'll tell you honestly what you need and what you don't.

We respond within 24 hours · All inquiries strictly confidential · NDA from first contact

FREE SECURITY ARSENAL

31 Free Templates, Policies & Frameworks

IRPs, pentest checklists, POPIA compliance tools, NDAs, SOWs, and more — battle-tested by real security teams. No login required.

OPEN ARSENAL