01Six-month engagement · Continuous
A standing adversary,
on retainer.
An annual penetration test tells you about one week of the year. This is a six-month engagement where someone is continuously trying to get into your organisation — through your infrastructure and through your people — and telling you exactly how it went every month.
- Baseline assessment in month one
- Weekly external testing & OSINT monitoring
- Three social engineering campaigns monthly
- Executive reporting with trend analysis
//The problem with annual testing
Your attack surface does not hold still for twelve months.
A point-in-time test is a photograph. It is genuinely useful, and it is out of date the moment someone deploys a service, opens a firewall rule, or onboards a supplier with access to your systems.
Meanwhile the people actually targeting you are not working to an annual schedule. They are watching continuously, waiting for the window that opens between your tests.
This engagement closes that window by keeping someone in it.
01The cadence
What actually happens, month by month.
Baseline
A full external penetration test to establish where you actually stand, plus complete attack surface mapping and a prioritised remediation roadmap. Everything that follows is measured against this.
- Full external network penetration test
- Attack surface inventory
- Prioritised remediation roadmap
Offensive operations
One day every week spent testing your perimeter as it changes. New services, new exposures and newly disclosed vulnerabilities get caught in days rather than at the next annual test.
- One day of external testing per week
- Continuous OSINT and exposure monitoring
- Validation of newly disclosed CVEs
Social engineering
Three campaigns each month: two broad campaigns across the organisation, and one highly targeted operation against executives, finance, or a specific business process.
- Two organisation-wide campaigns
- One targeted high-value operation
- Multi-channel: email, SMS, voice, social
Executive reporting
A written report and an optional live presentation. Written so a board can follow the risk narrative and an engineer can act on the detail, without either audience being patronised.
- Executive summary with trend analysis
- Full technical findings
- Optional live walkthrough and Q&A
02Who this is for
This is a serious commitment. It is not for everyone.
Six months of continuous offensive testing is the right answer for some organisations and overkill for others. If a scoped penetration test would serve you better, we will tell you so.
Fast-changing attack surface
If you ship weekly, acquire companies, or spin up infrastructure constantly, an annual test is measuring a system that no longer exists.
Regulated industries
Financial services, healthcare and similar sectors where continuous assurance and documented testing cadence are expected rather than optional.
Genuinely targeted organisations
If you are a plausible target for organised crime or a state-aligned actor, point-in-time testing is not a proportionate response.
Post-incident assurance
After a breach, leadership needs ongoing evidence that the problem is contained — not one clean report and silence for twelve months.
Security teams without a red team
You have capable defenders but nobody whose full-time job is attacking you. This provides that function without a headcount request.
Boards that want visibility
Monthly reporting gives leadership a defensible, documented view of security posture that improves measurably over time.
03Practicalities
The commercial shape.
- Term
- Six months. Long enough to establish a baseline, drive measurable improvement, and prove the trend.
- Billing
- A fixed monthly fee. No hourly billing, no variable scope creep, and a number your finance team can plan around.
- Continuity
- The same team throughout. Value compounds because we learn your environment rather than re-learning it each engagement.
- Rules of engagement
- Agreed in writing before anything starts, including out-of-bounds systems, testing windows and an escalation path.
- Critical findings
- Anything genuinely severe is reported the day it is found. You never wait for the monthly report to learn about a live risk.
→Next step
Let's work out whether this is proportionate.
A short conversation is usually enough to tell whether a managed engagement is right for you or whether something smaller would serve you better. We have no interest in selling you six months you do not need.
daniel@theosec.com · +27 63 484 1051