Cyber security
Find the gaps before an attacker does.
Penetration testing in South Africa: internal and external testing, vulnerability assessment, hardening and remediation — delivered with reports your board can actually read.
What a penetration test is — and what it is not
A penetration test is an authorised, scoped attempt to break into your environment the way an attacker would, followed by a written account of what worked. It is not a vulnerability scan with a logo on it, and it is not a compliance tick.
The distinction matters commercially. A scanner tells you a port is open and a version is outdated. A test tells you whether that actually gets someone to your data, which of your controls stopped them, and what to fix first. Most of the value is in the second half of that sentence — a finding nobody can act on is not a finding.
We conduct internal and external penetration tests that simulate real-world attacks against your environment, identify exploitable vulnerabilities, and give you actionable, prioritised remediation steps.
Scope options
Scope is agreed before anything starts, in writing, and it determines both the price and the length of the engagement. The scopes we run:
- External penetration testing — your internet-facing attack surface, tested from outside as an unauthenticated attacker would see it
- Internal penetration testing — what an attacker can reach once inside, whether through a compromised workstation, a supplier connection or physical access
- Microsoft 365 and identity configuration review — conditional access, privileged roles, legacy authentication and tenant hardening
- Firewall and network segmentation review — whether the boundaries you believe exist actually hold
How an engagement runs
Scoping comes first: what is in, what is out, what the rules of engagement are, and who to call if something goes wrong at two in the morning. Nothing is touched before that is signed.
Testing then runs against the agreed scope, with findings recorded as they are confirmed rather than saved for a reveal at the end. Anything critical is raised immediately — you should not learn about a live, exploitable hole three weeks later because it was scheduled into a report.
The engagement closes with the two documents below, a walkthrough with your team, and — where it is in scope — a retest once you have made the fixes, so you have evidence the hole is actually closed rather than an assurance that it should be.
What you receive
Every engagement ends in deliverables you can act on — not a scanner dump.
- Executive summary written for management: what the risk is, what it costs to fix, and what happens if you do not
- Technical findings register your engineers can work from
- Prioritised risk rating per finding
- Evidence screenshots where appropriate
- Clear remediation guidance
- Optional remediation support — we fix what we find, or work with your team
- Retest after fixes, where agreed in scope
What a penetration test costs
External penetration testing starts at R25,000 excluding VAT. The final figure is priced on scope, and scope is agreed in writing before any testing begins, so the number does not move mid-engagement.
Nobody else in this market publishes a price, which is why the question keeps getting asked and keeps going unanswered. We would rather you knew the starting point before you called.
What moves the number from there: how many external IP addresses and hosts are in scope; how many applications, and whether they are authenticated; whether internal testing is included alongside external; whether a retest after remediation is included; and whether any of the work needs to happen on site rather than remotely.
Penetration testing and POPIA section 19
POPIA section 19 requires a responsible party to secure the integrity and confidentiality of personal information through "appropriate, reasonable technical and organisational measures". The Act does not enumerate those measures, which is exactly what makes the obligation hard to evidence.
A penetration test is one of the few things that produces evidence rather than assertion: a dated, scoped record of what was tested, what was found, what was fixed and what was retested. Where a breach does occur, section 22 notification is considerably easier to handle when you can show what you had already done.
The technical reading of section 19 is set out on our POPIA page, alongside what the eight conditions and section 22 actually require of an IT environment.
Hardening and ongoing protection
Systeque provides a continued service using a multi-layered IT security approach, so your cyber security is managed proactively: patching, endpoint protection, gateway security, access reviews and backup verification as a managed service rather than a once-off project.
Testing is scoped and delivered from our Sandton office at Block 4, Fountain Grove, 5 2nd Rd, Hyde Park, Sandton, 2196, for clients in Johannesburg, Gauteng and nationally.
Common questions
- How much does a penetration test cost in South Africa?
-
Systeque external penetration testing starts at R25,000 excluding VAT, priced on scope.
The variables that move the number are the count of external IP addresses and hosts in scope, the number of applications and whether they are authenticated, whether internal testing is included alongside external, whether a retest after remediation is included, and whether any work must happen on site rather than remotely.
Scope is agreed and priced in writing before any testing begins, so the figure does not move mid-engagement.
- What is the difference between a vulnerability scan and a penetration test?
-
A scan reports that a port is open or software is outdated. A test establishes whether that is actually exploitable in your environment, what an attacker reaches from there, and which of your existing controls stopped them. Systeque runs both — scanning is part of the attack-surface review, testing is a separate scoped engagement.
- Does a penetration test help with POPIA compliance?
-
POPIA section 19 requires appropriate, reasonable technical and organisational measures to secure personal information, without listing what those are. A scoped test produces a dated record of what was tested, found, fixed and retested, which is evidence of those measures rather than an assertion of them.
- Will testing disrupt our live environment?
-
Rules of engagement are agreed in writing during scoping, including what is out of bounds and who to contact if something behaves unexpectedly. Anything critical found mid-engagement is raised immediately rather than held for the final report.
Related
- POPIA and your IT environment — section 19 read as infrastructure rather than as law.
- External attack surface monitoring — continuous watch on what is exposed, between tests.
- IT company in Johannesburg — who we are, where we are, and how fast we get there.
Penetration testing clients
Tested by other security firms.
A national security and compliance company engages Systeque to perform penetration tests for them and for their clients. Quoted verbatim from a signed reference letter.
Systeque has provided thorough and reliable penetration testing that has significantly improved the security posture of our clients.
Read full reference + Collapse −
“Systeque has provided thorough and reliable penetration testing that has significantly improved the security posture of our clients. The detailed reports they provide are comprehensive and easy to understand, enabling our clients to take informed steps toward enhancing their cybersecurity.”
Want to check? Read the signed reference letters.
Scope a penetration test.
Book a 45-minute pentest scoping call, or start lighter with a free security assessment of your environment.