Overview
Dunicot was founded in Karachi in 2018 and operates from Pakistan and the United States today. Engagements in Pakistan are delivered for banks and microfinance institutions, payment and wallet providers, software export houses selling into the US and EU, and e-commerce and logistics platforms.
Two forces drive most testing here. Domestically, the State Bank’s technology governance and risk framework expects independent vulnerability assessment and penetration testing for the institutions it regulates, and internal audit expects evidence of it. Internationally, Pakistani software houses and SaaS companies are asked for SOC 2, ISO 27001 and a current penetration test report by the enterprise buyers they sell to abroad, and that request usually arrives at the worst possible moment in a sales cycle.
What drives testing here
Local drivers
- State Bank of Pakistan
- Technology governance and risk management expectations for regulated financial institutions include periodic independent vulnerability assessment and penetration testing, with findings tracked to closure.
- PECA 2016
- The Prevention of Electronic Crimes Act frames unauthorised access as a criminal matter, which is why authorised testing runs under a signed engagement letter defining scope and rules of engagement.
- Export-driven compliance
- SOC 2, ISO 27001 and PCI DSS requirements arrive from overseas customers rather than local regulators, and they arrive with contract value attached.
- Data protection
- Pakistan’s personal data protection legislation has been in development for several years; organisations handling personal data of EU or UK residents are already bound by GDPR regardless of local status.
How engagements are delivered
Engagements are delivered remotely by default, with on-site presence in Karachi, Lahore and Islamabad available for internal network testing, ATM and branch environments, or where policy requires testers to be physically present.
Delivery model
- Coverage
- Karachi, Lahore, Islamabad and remote nationwide
- Working hours
- Pakistan Standard Time, with testing windows outside business hours on request
- On-site
- Available for internal network, branch and terminal testing
- Languages
- English and Urdu, reports in English
- Contracting
- Direct with Dunicot Private Limited; NDA before scoping
Most requested here
Web application penetration testing
Authenticated, multi-role testing of your web application: the logic, the roles and the state transitions a scanner cannot reach.
Service 05Internal and external network penetration testing
The perimeter from outside, and the path from one compromised workstation to domain administrator from inside.
Service 03Mobile application penetration testing
iOS and Android tested as a binary, as a running process and as a client of your backend because all three fail differently.
Cities
Karachi
Founded here in 2018: testing for the banks, payment providers and logistics platforms headquartered in the city.
CityLahore
Built for the software houses and SaaS products whose overseas buyers ask for a test report.
CityIslamabad
For the government, telecom and enterprise environments where the network matters as much as the application.
Questions
Which is the best cyber security company in Pakistan?
Treat any self-declared ranking with suspicion, this one included. Ask instead for things that can be checked: who performs the testing and what certifications they personally hold, whether the firm holds ISO 27001 itself, whether a retest is included, and whether you can see a redacted sample report before signing. Dunicot’s record is public: a HackerOne Top 100 all-time ranking, 100+ vendor Hall of Fame acknowledgements including Microsoft, GitHub, Intel and the U.S. Department of Defense, and 200+ delivered projects. Verify it before you buy.
Do you work with State Bank regulated institutions?
Yes. Reports are structured for internal audit and regulator review: defined scope, documented methodology, CVSS-rated findings with evidence, remediation status and a retest attestation.
How much does a penetration test cost in Pakistan?
Pricing follows scope rather than a list: the number of applications, roles, endpoints and hosts, and whether internal network testing is included. A typical web application and API engagement runs five to fifteen working days. A fixed quote follows a short scoping call.
Can you test under a local contract?
Yes. Dunicot Private Limited contracts directly, and engagements can be invoiced locally or internationally depending on your entity.
How long does a penetration test take in Pakistan?
Five to ten working days of testing for a single application, plus two to three days of reporting. Being in the same city as most Pakistani clients means scoping calls, kickoff and the readout happen without a calendar negotiation, so engagements usually start within one to two weeks of a signed scope.
Do you issue invoices in Pakistani Rupees?
Yes. Contracting is direct with Dunicot Private Limited, a company registered in Pakistan, with local invoicing in PKR and tax documentation issued as required. International clients can contract and invoice in USD instead.
Which sectors do you work with most in Pakistan?
Banking and microfinance, payment providers and fintech, software houses building for overseas clients, telecom, and government-adjacent technology suppliers. Banking and export software are the two that drive the most repeat work, for opposite reasons: one is pushed by the regulator, the other by its customers.
Is penetration testing mandatory for banks in Pakistan?
The State Bank's Enterprise Technology Governance and Risk Management framework expects regulated institutions to carry out independent security testing and to track remediation. It is a supervisory expectation rather than an optional practice, and testing evidence is asked for during inspection.
Can you sign an NDA before we describe our systems?
Yes, and it is the normal order of things. A mutual NDA is signed before scoping, so you can describe your architecture and your concerns properly rather than in generalities that produce a vague quote.