South Africa has a genuinely strong security industry, from long-established consultancies to newer platform providers. The hard part is not finding one. It is working out which model fits what you actually need, and asking the questions that separate a real test from a scan with a cover page.
We build one of these products, so treat this as an informed but interested source. The questions below are the ones we would want asked of us.
Most providers are a variation on one of these. Each has a real trade-off.
A team of testers scopes and runs a fixed engagement, usually annually or before an audit. Deep, human-led, and the right answer for complex business logic, chained exploitation and red-team work.
Trade-off: Priced per engagement (commonly R50 000 to R150 000), booked weeks out, and accurate for the date it ran. Your next release is untested until the next engagement.
Testing runs continuously from a platform you start on demand, with findings tracked between runs. Suits teams shipping regularly who need a current answer rather than an annual snapshot.
Trade-off: Automated depth is excellent on well-understood classes and weaker on novel business logic. Ask what the platform does NOT test, and whether human testing is available alongside it.
Individual testers or a crowd, paid per engagement or per finding. Can surface creative findings a methodology misses, and the economics are attractive at small scale.
Trade-off: Coverage is not guaranteed and reporting quality varies. Rarely sufficient on its own where an auditor or a customer questionnaire expects a structured, dated report.
Ask every shortlisted provider the same six and compare the answers. The differences that matter rarely appear on a pricing page.
Get the target list in writing: domains, IP ranges, APIs, cloud accounts. Ambiguous scope is the most common cause of a disappointing report.
Most real risk sits behind a login. A test that only sees the logged-out surface will miss access-control flaws entirely, which are the findings that matter most.
Proving that user A can reach user B's data requires two accounts. Without a second identity, cross-user authorization simply cannot be assessed, and a report that stays silent on it is not the same as a clean result.
Ask how evidence is graded and what a report row actually contains. A list of possible issues with no evidence attached is a scan, whatever it is called.
Ask about retesting: is it included, does it cost extra, and how long do you have. A finding is not closed until someone has confirmed the fix.
Findings describe your weaknesses, so the report is sensitive. Under POPIA you need to know where it lives, who can read it, and when it is deleted.
A penetration test report is a catalogue of your weaknesses, and often contains personal information encountered during testing. Under POPIA that makes it sensitive in its own right. Ask where findings are stored, who inside the provider can read them, how long they are retained, and whether any of it leaves South Africa. A provider who has not thought about the security of their own report storage is telling you something.
Penetration testing and POPIAWe are the platform model. Testing runs on demand across web, API, network, cloud, email and VoIP, findings are graded by the strength of the evidence behind them, reports arrive the same day, and pricing is published in Rand rather than quoted. Our team holds OSCP and CEH certifications, and manual engagements are available where a scope needs a human tester.
A traditional consultancy engagement typically runs R50 000 to R150 000 for a single assessment, depending on scope and depth. Platform subscriptions are lower and continuous: PentestMe plans start at R3 449 a month for two pentests. See our cost breakdown for the full comparison.
OSCP is the most widely recognised hands-on qualification; CEH is common and more theoretical; CREST is an organisational accreditation some enterprise and government buyers require. Ask which certifications the people testing your systems actually hold, not just what the company website lists.
POPIA does not name penetration testing specifically. It requires appropriate, reasonable technical and organisational measures to secure personal information, and expects them to be kept current. Testing is the usual way an organisation demonstrates it has identified and addressed risks to that information.
A consultancy engagement usually runs one to three weeks of testing plus a reporting period, and is booked in advance. Platform-based tests typically complete the same day they are started.
Yes. Ask each the same scope and evidence questions and compare the answers rather than the brochures. The differences that matter — authenticated testing, multiple identities, how evidence is graded, whether retesting is included — rarely appear on a pricing page.
Run a real, validated pentest on your own target before you pay anything, and compare what comes back against anyone else you are considering. No credit card.
Start your free pentest