Quick definition
Penetration test: a controlled, authorised attempt to break into your systems the way a real attacker would — to find the holes while it's still cheap to close them.
Best for: any organisation that holds client, patient, financial or operational data, needs to win a tender or secure cyber-insurance, or runs systems that simply cannot fail.
You get: a prioritised report of real, proven weaknesses — ranked by business impact — with remediation steps and a retest to confirm they're fixed.
The Engagements
Choose the test that matches your risk.
One size does not fit a business. We scope to what you actually run and what you're actually exposed to — from a single web app to a full industrial plant.
External Perimeter Test
Everything an attacker can reach from the internet — your public IPs, exposed services, VPNs, mail and login portals — probed the way a real intruder would. The fastest way to see your front door the way a criminal sees it.
Web & API Application Test
Your website, client portal or API tested against the OWASP Top 10 and beyond: broken access control, injection, authentication flaws and business-logic abuse that scanners never catch.
Internal Network & AD Assessment
What an attacker — or one compromised laptop — could actually do once inside: lateral movement, privilege escalation and the paths that lead to full domain takeover.
OT / ICS Security Assessment
Operational technology and industrial control systems — PLCs, SCADA, building-management and plant networks — assessed against IEC 62443 by engineers who understand the machinery, not only the IT. Very few firms in South Africa can do this.
Emergency Zero-Day Sweep
When a serious new vulnerability drops — the next Log4Shell or MOVEit — a rapid sweep of your estate that tells you within hours, not weeks, whether you're exposed.
Continuous Attack-Surface Monitoring
Your internet-facing footprint watched continuously, so a new exposure is caught when it appears — not at next year's test. The affordable way to stay tested all year round.
Phishing & Human-Risk Programme
Realistic, POPIA-lawful phishing simulations paired with human-risk training — because people, not firewalls, are the most-exploited way into most South African businesses.
Red-Team / Adversary Simulation
A full-scope simulation of a determined attacker across people, process and technology — built to test whether you'd actually detect and respond, not just to list bugs.
Not sure which you need? That's what the scoping call is for. Every engagement is a fixed written quote agreed before any work starts — no hourly surprises, and nothing is touched without your written authorisation.
Scanning vs Testing
Vulnerability scanning is where it starts — not where it ends.
Automated vulnerability scanning is fast, affordable and ideal for continuous coverage. But a scanner only lists what might be wrong — and buries you in false positives. Penetration testing services take it further: a human engineer verifies what's real, chains weaknesses together the way an attacker would, and proves genuine business impact.
- Vulnerability scanning for breadth and continuous monitoring across your whole estate.
- Manual penetration testing for depth — validating, exploiting and prioritising what actually matters.
- One clean report that separates the scanner noise from the findings that could genuinely cost you money.
Why It Matters Who Tests You
Most testers know IT. We also know the machines.
Generic web and network testing is a crowded market — plenty of firms can run a scanner and format the output. Where almost no one in South Africa can follow is operational technology: the PLCs, SCADA systems, building-management controllers and plant networks that run factories, utilities, cold chains and mining. Test those the wrong way and you don't just find a bug — you can stop a production line.
ASi is an engineering consultancy first. Our engineers are Siemens-certified — SMSCP (Siemens Mechatronic Systems Certification Programme) and TIA-MICRO1 (TIA Portal / SIMATIC industrial automation) — with a mechatronics engineering background, working aligned to the IEC 62443 industrial-security standard and mapping every test to recognised frameworks like MITRE ATT&CK and the OWASP testing standards. That combination — real industrial engineering plus offensive security — is the reason a serious organisation should choose us over a pure-IT testing shop.
How A Test Runs
Authorised, controlled, and safe for your operations.
A penetration test is a serious, legally-bounded exercise. This is the discipline every ASi engagement follows — the same rigour that keeps it lawful and keeps your systems standing.
Lawful by design. Testing a system without written authorisation is a criminal offence under South Africa's Cybercrimes Act — never a grey area, and never something we skip. Every engagement runs on a signed authorisation and a defined scope, and phishing programmes run only on a documented lawful basis under POPIA. Our discipline is your protection as much as ours.
The Deliverable
A report you can act on — and hand over.
- A prioritised findings report — every weakness proven, then ranked by how likely and how damaging it really is.
- Clear reproduction and remediation steps your team or ours can act on immediately, in plain language.
- An executive summary written for a board, an insurer or a tender evaluator — not just for engineers.
- A retest after remediation to confirm the fixes hold, and evidence you can show that you closed them.
- An optional continuous-monitoring plan so your exposure is watched between tests, not just once a year.
What It Costs
Priced for your size — not a one-size invoice.
Small businesses and clearly-defined scopes get published, honest ranges. Corporate, multi-site and critical-infrastructure work is bespoke and quoted on RFQ. Either way, you approve a fixed number before anything starts.
Published ranges
On RFQ
Bespoke by nature. Send an RFQ or book a scoping call and we return a fixed written proposal — typically within one to two business days.
Submit an RFQRanges are indicative, benchmarked to typical South African scopes and quoted ex-VAT. Your final price is always a fixed written quote after a short scoping call — no hourly surprises, and nothing is touched without your written authorisation.
When You Need One
The reasons clients call us.
In this market, a pentest is rarely a nice-to-have. Something concrete is usually driving it — and it usually has a deadline attached.
Dealing with a live incident right now? Go straight to Data Breach Response — there's a legally-mandated 72-hour reporting clock, so speed matters.
Common Questions
Straight answers.
Is penetration testing legal, and is it safe for our systems?
Yes — when it's authorised. We only ever test against a signed authorisation letter and a written scope, within windows you agree, with a named contact to escalate to if anything unexpected happens. Testing without that authorisation is a criminal offence under the Cybercrimes Act, which is exactly why we never operate without it. Anything potentially disruptive is agreed with you in advance and run in a controlled way.
What's the difference between a vulnerability scan and a penetration test?
A scan is an automated tool that lists possible issues — and a lot of false positives. A penetration test uses that as a starting point, then a human engineer actually tries to exploit the weaknesses, chains them together the way a real attacker would, and proves what's genuinely dangerous. A scan tells you what might be open; a pentest shows you what someone could actually do with it.
Do you test operational technology (OT/ICS), not just office IT?
Yes — it's our specialism. Industrial control systems, PLCs, SCADA and building-management networks need engineers who understand both the security and the machinery, because a careless test can disrupt live operations. Our engineering background and IEC 62443 alignment are precisely what that work requires, and very few firms in South Africa offer it.
What do we actually receive at the end?
A prioritised findings report with each weakness proven and ranked by real business impact, plain-language remediation and reproduction steps, an executive summary suitable for a board, insurer or tender, and a retest after you've remediated. It's built to be acted on and handed over — not filed away.
How is this different from your Cybersecurity Assessment?
Our cybersecurity assessment is a broad health-check of your overall posture — controls, backups, email security, patching and more. A penetration test goes deep on a defined target and actively tries to break in to prove exploitable paths. Many clients start with the assessment to see the whole picture, then commission a focused pentest on their highest-risk systems.
Authorities & Trusted Sources
The standards and frameworks our testing maps to — verify them at source, then let us handle the work. See our full Trusted Sources directory.