Offensive Security

Penetration Testing

Find out exactly how someone would break in — from a team you authorise, in writing, before a real attacker, an auditor, or a failed tender finds the gap for you.

Direct answer: A penetration test is an authorised, simulated attack on your systems by security engineers, run to find and prove exploitable weaknesses before criminals do. We test external, web and API, internal network and specialised industrial (OT/ICS) environments, then hand you a prioritised, plain-language report with the fixes — and retest to confirm they hold.
Book a Scoping Call Chat on WhatsApp

Quick definition

Penetration test: a controlled, authorised attempt to break into your systems the way a real attacker would — to find the holes while it's still cheap to close them.

Best for: any organisation that holds client, patient, financial or operational data, needs to win a tender or secure cyber-insurance, or runs systems that simply cannot fail.

You get: a prioritised report of real, proven weaknesses — ranked by business impact — with remediation steps and a retest to confirm they're fixed.

The Engagements

Choose the test that matches your risk.

One size does not fit a business. We scope to what you actually run and what you're actually exposed to — from a single web app to a full industrial plant.

External · Perimeter

External Perimeter Test

Everything an attacker can reach from the internet — your public IPs, exposed services, VPNs, mail and login portals — probed the way a real intruder would. The fastest way to see your front door the way a criminal sees it.

Web · API

Web & API Application Test

Your website, client portal or API tested against the OWASP Top 10 and beyond: broken access control, injection, authentication flaws and business-logic abuse that scanners never catch.

Internal · Active Directory

Internal Network & AD Assessment

What an attacker — or one compromised laptop — could actually do once inside: lateral movement, privilege escalation and the paths that lead to full domain takeover.

Our specialism OT · ICS · IEC 62443

OT / ICS Security Assessment

Operational technology and industrial control systems — PLCs, SCADA, building-management and plant networks — assessed against IEC 62443 by engineers who understand the machinery, not only the IT. Very few firms in South Africa can do this.

Rapid · Incident-Driven

Emergency Zero-Day Sweep

When a serious new vulnerability drops — the next Log4Shell or MOVEit — a rapid sweep of your estate that tells you within hours, not weeks, whether you're exposed.

Recurring · Monitoring

Continuous Attack-Surface Monitoring

Your internet-facing footprint watched continuously, so a new exposure is caught when it appears — not at next year's test. The affordable way to stay tested all year round.

People · Human Risk

Phishing & Human-Risk Programme

Realistic, POPIA-lawful phishing simulations paired with human-risk training — because people, not firewalls, are the most-exploited way into most South African businesses.

Goal-Driven · Advanced

Red-Team / Adversary Simulation

A full-scope simulation of a determined attacker across people, process and technology — built to test whether you'd actually detect and respond, not just to list bugs.

Not sure which you need? That's what the scoping call is for. Every engagement is a fixed written quote agreed before any work starts — no hourly surprises, and nothing is touched without your written authorisation.

Scanning vs Testing

Vulnerability scanning is where it starts — not where it ends.

Automated vulnerability scanning is fast, affordable and ideal for continuous coverage. But a scanner only lists what might be wrong — and buries you in false positives. Penetration testing services take it further: a human engineer verifies what's real, chains weaknesses together the way an attacker would, and proves genuine business impact.

We combine both, so nothing slips through:
  • Vulnerability scanning for breadth and continuous monitoring across your whole estate.
  • Manual penetration testing for depth — validating, exploiting and prioritising what actually matters.
  • One clean report that separates the scanner noise from the findings that could genuinely cost you money.

Why It Matters Who Tests You

Most testers know IT. We also know the machines.

Generic web and network testing is a crowded market — plenty of firms can run a scanner and format the output. Where almost no one in South Africa can follow is operational technology: the PLCs, SCADA systems, building-management controllers and plant networks that run factories, utilities, cold chains and mining. Test those the wrong way and you don't just find a bug — you can stop a production line.

ASi is an engineering consultancy first. Our engineers are Siemens-certified — SMSCP (Siemens Mechatronic Systems Certification Programme) and TIA-MICRO1 (TIA Portal / SIMATIC industrial automation) — with a mechatronics engineering background, working aligned to the IEC 62443 industrial-security standard and mapping every test to recognised frameworks like MITRE ATT&CK and the OWASP testing standards. That combination — real industrial engineering plus offensive security — is the reason a serious organisation should choose us over a pure-IT testing shop.

How A Test Runs

Authorised, controlled, and safe for your operations.

A penetration test is a serious, legally-bounded exercise. This is the discipline every ASi engagement follows — the same rigour that keeps it lawful and keeps your systems standing.

Scope & authorise A written scope with explicit inclusions and exclusions, agreed testing windows, a named escalation contact, and a signed authorisation letter — before anything is touched.
Test Recognised methodologies and industry tooling, mapped to MITRE ATT&CK and OWASP, run within the agreed windows and paused instantly if anything unexpected happens.
Verify & rank Every finding is validated by hand to strip out false positives, then ranked by real exploitability and business impact — not raw scanner severity.
Report & walk through A prioritised, plain-language report with reproduction steps and remediation, walked through with your team in person — not just emailed as a PDF.
Fix & retest Remediation support and a retest to prove the holes are actually closed — plus an optional continuous-monitoring plan so new gaps don't wait a year to surface.

Lawful by design. Testing a system without written authorisation is a criminal offence under South Africa's Cybercrimes Act — never a grey area, and never something we skip. Every engagement runs on a signed authorisation and a defined scope, and phishing programmes run only on a documented lawful basis under POPIA. Our discipline is your protection as much as ours.

The Deliverable

A report you can act on — and hand over.

What you actually get:
  • A prioritised findings report — every weakness proven, then ranked by how likely and how damaging it really is.
  • Clear reproduction and remediation steps your team or ours can act on immediately, in plain language.
  • An executive summary written for a board, an insurer or a tender evaluator — not just for engineers.
  • A retest after remediation to confirm the fixes hold, and evidence you can show that you closed them.
  • An optional continuous-monitoring plan so your exposure is watched between tests, not just once a year.

What It Costs

Priced for your size — not a one-size invoice.

Small businesses and clearly-defined scopes get published, honest ranges. Corporate, multi-site and critical-infrastructure work is bespoke and quoted on RFQ. Either way, you approve a fixed number before anything starts.

Small Business & Defined Scopes

Published ranges

External Perimeter TestR15k–R45k
Web / API Test (single app)R25k–R65k
Emergency Zero-Day SweepR12k–R35k
Continuous Attack-Surface Monitoringfrom R6.5k/mo
Phishing & Human-Risk ProgrammeR12k–R45k
Get a fixed quote

Ranges are indicative, benchmarked to typical South African scopes and quoted ex-VAT. Your final price is always a fixed written quote after a short scoping call — no hourly surprises, and nothing is touched without your written authorisation.

When You Need One

The reasons clients call us.

In this market, a pentest is rarely a nice-to-have. Something concrete is usually driving it — and it usually has a deadline attached.

A tender or contract requires itMore RFPs, banks and enterprise buyers now demand evidence of a recent, independent penetration test before they'll sign.
Cyber-insuranceInsurers increasingly require proof of testing to grant or renew a policy — and to pay out if the worst happens.
POPIA & the Cybercrimes ActPOPIA requires "reasonable security safeguards." An independent test is how you demonstrate you actually have them.
A client security questionnaireVendor due-diligence and supply-chain reviews routinely ask when you were last tested. "Never" loses deals.
A new system or major changeA new portal, app, integration or migration is exactly when fresh, exploitable gaps get introduced.
After — or to prevent — a breachWhether you've just been hit or want to make sure you never are, testing tells you where you actually stand.

Dealing with a live incident right now? Go straight to Data Breach Response — there's a legally-mandated 72-hour reporting clock, so speed matters.

Common Questions

Straight answers.

Is penetration testing legal, and is it safe for our systems?

Yes — when it's authorised. We only ever test against a signed authorisation letter and a written scope, within windows you agree, with a named contact to escalate to if anything unexpected happens. Testing without that authorisation is a criminal offence under the Cybercrimes Act, which is exactly why we never operate without it. Anything potentially disruptive is agreed with you in advance and run in a controlled way.

What's the difference between a vulnerability scan and a penetration test?

A scan is an automated tool that lists possible issues — and a lot of false positives. A penetration test uses that as a starting point, then a human engineer actually tries to exploit the weaknesses, chains them together the way a real attacker would, and proves what's genuinely dangerous. A scan tells you what might be open; a pentest shows you what someone could actually do with it.

Do you test operational technology (OT/ICS), not just office IT?

Yes — it's our specialism. Industrial control systems, PLCs, SCADA and building-management networks need engineers who understand both the security and the machinery, because a careless test can disrupt live operations. Our engineering background and IEC 62443 alignment are precisely what that work requires, and very few firms in South Africa offer it.

What do we actually receive at the end?

A prioritised findings report with each weakness proven and ranked by real business impact, plain-language remediation and reproduction steps, an executive summary suitable for a board, insurer or tender, and a retest after you've remediated. It's built to be acted on and handed over — not filed away.

How is this different from your Cybersecurity Assessment?

Our cybersecurity assessment is a broad health-check of your overall posture — controls, backups, email security, patching and more. A penetration test goes deep on a defined target and actively tries to break in to prove exploitable paths. Many clients start with the assessment to see the whole picture, then commission a focused pentest on their highest-risk systems.

Authorities & Trusted Sources

The standards and frameworks our testing maps to — verify them at source, then let us handle the work. See our full Trusted Sources directory.

MITRE ATT&CK ↗ OWASP Top 10 ↗ CISA Known Exploited Vulns ↗ All Trusted Sources →
ASi
Written by the ASi Engineering Team

ASi Imperium is a South African engineering consultancy specialising in cybersecurity, POPIA compliance and custom digital infrastructure for professional and industrial clients.

Approach: offensive security backed by real industrial-automation engineering — Siemens-certified (SMSCP, TIA-MICRO1), aligned to IEC 62443, OWASP and MITRE ATT&CK, with CSI cybersecurity training.