//About
Small by design.
Theosec exists because the offensive security I wanted to buy was hard to find: qualified people who stay with the engagement, say what they actually think, and write a report you can hand to an engineer without translation.

01Daniel Scragg
Founder & Principal Consultant
- OSCP · OSEP · CRTO · eWPTX · CREST CRT
- BSc (Hons) Computer Science
- 4+ years offensive security operations
I have spent the last four years doing penetration testing and red team work across a wide range of environments — web applications and APIs, corporate networks, cloud estates, and the people who operate all of it.
The certifications behind that work — OSCP, OSEP, CRTO, eWPTX and CREST CRT — share a useful property: every one of them requires compromising real systems under examination conditions. None can be passed by recognising the right answer on a multiple-choice paper. That distinction matters when you are choosing who to let near your infrastructure.
Theosec is deliberately small. A larger firm can offer you more people; it cannot offer you more attention. As the practice grows I am bringing on and training junior consultants — but the model does not change: a principal leads every engagement, reviews every finding, and is the person you speak to from first call to retest.
I would rather do a small number of engagements properly than a large number adequately.
02How I work
Four commitments.
Senior-led, start to finish
A principal consultant scopes your engagement, leads the testing, and signs off every finding before it reaches you. Where colleagues support the work, their output is reviewed line by line — the accountability never moves.
Reports people can act on
Written in plain language, ordered by real business risk, and specific about remediation. If your engineers cannot reproduce a finding from the report, the report is not finished.
Scoped honestly
If a smaller engagement answers your question, I will propose the smaller engagement. Overselling works once and destroys the referrals that a practice this size depends on.
Confidential by default
Mutual NDA before scoping. I do not name clients, publish logos, or use your findings as marketing material — including anonymised.
03The company
Details, for the people who need them.
- Legal entity
- Theosec (Pty) Ltd, registered in South Africa
- Delivery
- Remote-first, worldwide
- Insurance & contracts
- Professional indemnity details and standard terms available on request during procurement
- Confidentiality
- Mutual NDA signed before any scoping discussion
- Authorisation
- Written authorisation to test required before any engagement begins, without exception
→Next step
Find out what an attacker already knows.
Every engagement starts with a conversation and a mutual NDA — not a sales pipeline. Tell me what you are worried about and I will tell you honestly whether I can help.
daniel@theosec.com · +27 63 484 1051