Dunicot A cybersecurity consultancy and advisory firm.

Market · South Africa

Cyber security consultancy and penetration testing in South Africa

POPIA put a statutory security obligation behind personal information and the Information Regulator has shown it will act on it. In a market with card fraud volumes this high, the cardholder environment is usually where an engagement starts.

Overview

Engagements in South Africa cover banking and insurance, payment processors and card acquirers, retail and e-commerce platforms, and the technology suppliers serving all of them.

Delivery runs from our Karachi office, three hours ahead of South African time, which puts our afternoon inside your working day for same-day answers.

What drives testing here

Local drivers

POPIA
The Protection of Personal Information Act requires appropriate technical measures and reasonable steps to identify risks, with the Information Regulator empowered to enforce.
SARB directives
The Reserve Bank sets cyber resilience expectations for banks and payment participants, including independent testing and incident reporting.
PCI DSS
Card volumes and fraud pressure make segmentation validation and cardholder environment scope the most commonly requested work here.
Cybercrimes Act
The 2020 Act criminalises unauthorised access explicitly, which is why authorised testing runs under a signed engagement letter naming systems and dates.

How engagements are delivered

Delivered remotely from Karachi, scheduled to South African business hours, with on-site availability in Johannesburg and Cape Town for internal network scope and workshops.

Delivery model

Delivery
Remote from Karachi, three hours ahead of SAST; on-site available
Mapping
POPIA technical measures, PCI DSS and SARB expectations as applicable
Coverage
Johannesburg, Cape Town, Durban and remote nationwide
Most requested
Cardholder environment scope and segmentation validation

Most requested here

Questions

Do you have an office in South Africa?

No. Our offices are in Pakistan and the United States. South Africa is served from Karachi, three hours ahead, with on-site availability where internal or workshop scope requires it.

What does POPIA expect us to evidence?

Section 19 asks for appropriate, reasonable technical and organisational measures and for risks to be identified. A dated independent test, tracked to closure and retested, is the cleanest evidence of both, which is how the report is structured.

Can you validate PCI DSS segmentation?

Yes. Segmentation is tested between every pair of in-scope zones, with each expected-blocked path attempted and the result recorded, so the report states which controls held rather than which were configured.

How much does a penetration test cost in South Africa?

Cost follows scope. Cardholder environment scope and segmentation validation are priced by zone pair and host count rather than by application, because that is what the work actually is. A fixed quote follows a short scoping call.

Which is the best penetration testing company in South Africa?

No honest answer is a single name. Check the certifications held by the testers assigned to you, and the team's public research record, whether the firm holds ISO 27001 itself, whether PCI DSS and POPIA framing is included, and whether a redacted sample report is available before you commit.

Does POPIA require a penetration test?

Not explicitly. Section 19 requires appropriate, reasonable technical and organisational measures and requires that risks be identified. An independent test satisfies both limbs with a dated artefact, which matters because the Information Regulator has shown it will ask what was done rather than what was intended.

Do you test for banks and insurers under SARB oversight?

Yes. Reports are structured for internal audit and supervisory review, with scope, methodology, evidence per finding, remediation tracking and a signed retest attestation, which is the shape a cyber resilience review works from.

Can you help with card fraud exposure specifically?

Yes. High card volumes make the cardholder environment the usual starting point: segmentation validated between every pair of in-scope zones, authorisation boundaries across customer records, and the transaction paths where a limit or reversal can be manipulated rather than broken.

Penetration testing in South Africa

Describe the scope and the deadline. Delivery in your working hours, with a fixed quote after scoping.