//Offensive security · Est. South Africa
Find your weaknesses
before attackers do.
Theosec is a boutique offensive security practice. We break into organisations the way real adversaries do — then show you exactly how it was done and what to fix first.
Complimentary · By application · Limited places each quarter
- Certifications
- OSCPOSEPCRTOeWPTXCREST CRT
- Experience
- 4+ years offensive operations
- Engagement model
- Principal-led throughout
- Confidentiality
- Mutual NDA before scoping
- Coverage
- Worldwide · Remote-first
Certified
- OSCP
- OSEP
- CRTO
- eWPTX
- CREST CRT
Every one of these required compromising live systems under examination conditions.
Methodology
- OWASP
- PTES
- NIST SP 800-115
- MITRE ATT&CK
- CVSS
Recognised frameworks provide coverage. Judgement provides the findings that matter.
01The premise
A scanner finds what is known. An adversary finds what is forgotten.
Most security testing is a compliance exercise. A tool is pointed at a range, a report is generated, a box is ticked, and the organisation learns almost nothing about how it would actually be compromised.
Real intrusions rarely begin with a critical CVE. They begin with a forgotten subdomain, a credential in an old breach dump, a helpdesk process that trusts a confident voice on the phone. Those are the things we look for — because those are the things being used against you.
You get a senior-led team, working by hand, telling you the truth about your exposure.
02Capabilities
Five ways to find out where you stand.
Every engagement is scoped to your environment and your risk. Nothing here is a package with a fixed number of hours stapled to it.
Reconnaissance Briefing
By application · Limited each quarter
A full day of manual red team reconnaissance against your external attack surface, presented back to you in a private debrief. No cost, no obligation — we select a small number of organisations each quarter.
- External attack surface mapping
- OSINT & credential exposure review
- Human risk profile
- Private debrief call + written summary
Managed Red Team
Six-month engagement · Continuous
A standing adversary for your organisation. Continuous offensive testing across your technology and your people, with executive reporting every month.
- Baseline assessment in month one
- Weekly external testing & OSINT monitoring
- Three social engineering campaigns monthly
- Executive reporting with trend analysis
Penetration Testing
Real-world attack simulation across applications, networks, cloud and devices.
Learn more03Phishing Simulations
Multi-channel social engineering written by hand — never from a template library.
Learn more04Security Awareness Training
Live sessions where your team watches real attacks unfold — demonstrations, not slideshows.
Learn more03How an engagement runs
Four phases. No surprises.
- 01
Scope
A conversation under NDA to establish what matters, what is in bounds and what a successful outcome looks like.
- 02
Recon
Mapping your real attack surface — the assets, exposures and people an adversary would find before touching anything.
- 03
Exploit
Controlled exploitation to prove genuine impact, because an unproven finding is only a theory about risk.
- 04
Report
A written report, a live walkthrough with your technical team, and a retest once the fixes land.
04Why Theosec
Small practice. Deliberately.
A larger firm will sell you more people. It will not sell you more attention.
A lightweight team
Small enough that a principal consultant leads your engagement personally and reviews every finding before it reaches you. No account managers, no anonymous hand-off once the contract is signed.
Reports for humans
Findings written in plain language with real business context and a prioritised order of work — not a raw scanner export with a logo on the front.
Real attacker tradecraft
Manual testing using the techniques actually being used against organisations like yours. Automated tooling supports the work; it never substitutes for it.
Absolute discretion
Mutual NDA before scoping. Your vulnerabilities, your data and the fact that we work together are all treated as confidential by default.
Credentialed, not self-certified
OSCP, OSEP, CRTO, eWPTX, CREST CRT — qualifications that require demonstrating exploitation under examination conditions, not a multiple-choice paper.
Global delivery
Registered in South Africa, engaged worldwide. Remote-first delivery means the same standard of work regardless of where your offices are.

05The practitioner
Daniel Scragg
Founder & Principal Consultant
I founded Theosec to do offensive security the way I always wanted it done: a small team that knows your environment, stays with the engagement from scoping to retest, and writes a report you can actually act on.
Four years of hands-on penetration testing and red team operations across a broad range of environments, backed by certifications that required proving exploitation under exam conditions rather than answering questions about it.
→Next step
Find out what an attacker already knows.
Every engagement starts with a conversation and a mutual NDA — not a sales pipeline. Tell me what you are worried about and I will tell you honestly whether I can help.
daniel@theosec.com · +27 63 484 1051