TRANSPARENT PRICING · ZAR · NO HIDDEN FEES

Choose Your
Security Plan

Professional penetration testing and security assurance. Every plan includes a retest. No surprises. Just results.

> All prices in South African Rand (ZAR) · USD rates available on request
NDA First
From first contact
Retest Included
Every plan
24hr Response
Consultation guaranteed
Fixed Scope
No scope-creep fees
Retest Only

Verification
Retest

R5,000

once-off · after your fixes

  • Verify all previous findings closed
  • Regression testing
  • Final certification report
  • Auditor & insurer suitable
  • NDA & confidentiality
  • New scope not included
  • No ongoing support
One-Time

Single
Assessment

R10,000

once-off · full test + report + retest

  • Full penetration test (web / network)
  • Executive summary report
  • Detailed technical findings
  • Prioritised remediation roadmap
  • One full retest included
  • 30-day remediation support
  • 2–3 week turnaround
  • NDA & confidentiality
Enterprise

Enterprise
Custom

Custom

scoped to your organisation

  • Everything in Annual Assurance
  • Monthly security assessments
  • 24/7 incident response on-call
  • Red team exercises
  • Security awareness training
  • Embedded security consultant
  • Board-level reporting

All prices in ZAR (incl. VAT where applicable). Scope variations may affect final pricing — confirmed in writing before engagement begins. USD equivalents available on request.

Full Feature Comparison

Everything you get — no fine print surprises.

Feature
RETEST
SINGLE
ANNUAL
ENTERPRISE
Penetration test
✓ ×4/yr
✓ Monthly
Executive report
Technical findings report
Remediation roadmap
Retest / verification
✓ ×1
Unlimited
Unlimited
Compliance support
✓ Custom
Dedicated advisor
Incident response support
✓ 24/7
Red team exercises
Security training
NDA & confidentiality
Price
R5k
R10k
R16k/yr
Custom

R10,000 vs
R10,000,000

The average data breach costs a South African organisation R10 million+ in downtime, legal fees, regulatory fines, and reputational damage (IBM CDR 2024). Our Single Assessment costs the same number — with three fewer zeroes.

And that's before you factor in that the average attacker is in your network 194 days before detection — racking up costs the entire time.

SEE YOUR BREACH COST TICK LIVE →
Avg. breach cost (SA, 2024) R 10M+
Annual Assurance plan R16K
Single Assessment R10K

The bars are to scale.

Your Breach Risk Calculator

See how your estimated breach exposure stacks up against the cost of protecting yourself. Takes 10 seconds.

COMPANY SIZE
INDUSTRY RISK LEVEL
MONTHLY REVENUE (ZAR)
R
ESTIMATED BREACH EXPOSURE
R4.5M
downtime · legal fees · reputational damage
Single Assessment cost R10,000
Annual Assurance cost R16,000/yr
Your Protection ROI 281x
breach exposure ÷ Annual Assurance cost

Frequently Asked

Our tests include passive and active reconnaissance, vulnerability scanning, manual exploitation attempts, privilege escalation testing, lateral movement simulation, and post-exploitation analysis. Every test concludes with a comprehensive report that maps findings to business risk — not just CVE IDs — with a clear remediation priority order.

A Single Assessment typically takes 2–3 weeks from signed scope to final report delivery. This includes the active testing window (usually 5–10 business days depending on scope), report writing, and an initial findings briefing. Timeline varies based on scope complexity and number of systems in scope. We confirm everything in writing before starting.

Yes — all reports are structured to support compliance requirements. We produce findings mapped to HIPAA, PCI DSS, SOC 2 Type II, ISO 27001, POPIA, and NIST CSF as required. For the Annual Assurance and Enterprise tiers, we include quarterly compliance posture updates and a compliance roadmap as part of the engagement.

The retest verifies that every vulnerability identified in the original assessment has been genuinely closed — not just documented as patched. We re-exploit each finding category to confirm it's no longer accessible. We also perform regression testing to check that fixes haven't introduced new vulnerabilities. You receive a final certification report confirming the remediated state, suitable for auditors, board members, and insurers.

Always. We sign NDA before any technical discussion, before receiving any documentation, and certainly before any active testing begins. Client confidentiality is foundational to how we operate — we have never disclosed a client name, finding, or engagement detail without explicit written permission. You can request our standard NDA template before even booking a consultation.

Absolutely. These tiers are starting points — the real scope of every engagement is defined in a written Statement of Work agreed before anything begins. Whether you need a single API tested, a specific compliance scope, red team exercises, or a multi-phase engagement across a large environment, we'll scope it accurately and quote it in writing. No scope creep, no surprise invoices.

Automated scanners find what they're programmed to find — usually the obvious stuff. They don't chain vulnerabilities together, they can't social-engineer your staff, they miss business logic flaws, they generate enormous false-positive noise, and they produce reports that mean nothing to a board or insurer. Real attackers are human. Our testers think like humans. A scanner has never found SQL injection hidden behind a custom authentication layer. We have.

Still Have Questions?

Let's talk through your specific security needs. Free consultation — no commitment, no hard sell. We'll tell you honestly what you need and what you don't.

We respond within 24 hours · All inquiries strictly confidential · NDA from first contact