Loading...
Loading...
Vulnerability assessment, manual penetration testing and control review in a single engagement, reported against RMiT, NACSA or ISO/IEC 27001 — packaged the way Malaysian public-sector tenders ask for it.
Most Malaysian organisations that need this work describe it internally as “a pentest”. Procurement, however, rarely buys it under that name. In our own review of federal award records, Security Posture Assessment is the dominant title for engagements of this shape, while standalone “penetration testing” awards are comparatively rare. The scope is largely the same work — the difference is packaging, framework mapping and the evidence an evaluator is looking for.
That gap has a practical cost. A capability statement written entirely around penetration testing does not score well against an SPA evaluation matrix, even when the underlying technical capability is identical. If you are preparing a submission, or evaluating one, the vocabulary is part of the deliverable.
If your requirement really is depth-first against one target, a penetration test is the cheaper and more appropriate purchase. If you need an organisation-wide position statement your auditor and your board will both accept, that is an SPA.
Agree the estate boundary, the systems that warrant manual testing, and the framework the report will be measured against — RMiT, NACSA or ISO/IEC 27001:2022. Rules of engagement, testing windows and escalation contacts are signed before any traffic is generated.
Authenticated and unauthenticated scanning across in-scope hosts, applications and network ranges. Output is triaged by hand — automated severity is a starting point, not the finding. False positives are removed before they ever reach your team.
OSCP-certified consultants test the systems that carry the most risk, chaining findings the way an attacker would. This is where a posture assessment earns its value over a scan: exploitability is demonstrated, not assumed.
Findings mapped to the agreed framework, gaps rated by business impact, remediation sequenced by effort against risk reduction. Executive summary, technical register, roadmap. Critical and high findings are retested after remediation.
The same control evidence is presented against whichever framework governs you. For licensed financial institutions that is BNM RMiT, where paragraph 10 covers logging, monitoring and penetration testing obligations. For entities in scope of the Cyber Security Act 2024 it is the NACSA control expectations, including NCII obligations where the entity has been designated. For organisations working toward certification we map to ISO/IEC 27001:2022 Annex A.
Agencies handling citizen data should read this alongside PDPA obligations — the 2024 amendments introduced mandatory breach notification and a data protection officer requirement, both of which an SPA is expected to evidence readiness for.
Typical effort is around 40 consultant-days across roughly 45 elapsed days. See pricing for how we scope, or public sector cybersecurity for sector context.
A Security Posture Assessment (SPA) is a combined engagement: vulnerability assessment across the in-scope estate, manual penetration testing of the systems that matter most, and a control review measured against a named framework. It answers a broader question than a pentest alone — not just "can this system be broken into", but "how strong is this organisation's overall security position, and what should be fixed first". It is the title Malaysian public-sector procurement uses for this scope of work.
A penetration test is depth-first against a defined target: one application, one network segment, one API. An SPA is breadth-plus-depth. It includes penetration testing, but wraps it in an estate-wide vulnerability assessment and a control-maturity review, then reports against a framework rather than only as a findings list. If you are buying under a tender that names "Security Posture Assessment", a standalone pentest quote will usually not satisfy the evaluation criteria.
It matters because evaluators match submissions to the tender title. In our own review of Malaysian federal award records, "Security Posture Assessment" is overwhelmingly the title used for this scope, while "penetration testing" as a standalone award title is rare. A provider whose proposal, capability statement and past-performance references are all framed as "penetration testing" is describing the same work in language the evaluation matrix does not credit.
We map findings to the framework the engagement is being bought against. For financial-sector bodies that is normally BNM RMiT. For agencies operating under the Cyber Security Act 2024 it is the NACSA control expectations and, where the entity is designated NCII, the sector lead's requirements. For organisations building toward certification we map to ISO/IEC 27001:2022 Annex A. Multiple mappings in a single report are standard — the control evidence is the same, only the presentation differs.
An executive summary written for a board or audit committee, a full technical findings register with CVSS ratings, a control gap analysis against the agreed framework, a prioritised remediation roadmap, and a retest of every critical and high finding once your team has remediated. The retest is included in the engagement, not billed separately.
A typical SPA runs about 40 consultant-days of effort across roughly 45 elapsed days, which allows for access provisioning, testing windows and the remediation gap before retest. Pricing depends on estate size, number of applications in scope and the framework being reported against; most engagements land in the RM 90,000 to RM 150,000 band. Larger multi-entity estates are scoped individually. We fix the price after a scoping call rather than quoting a day rate.
Complementary services Malaysian buyers commonly pair with security posture assessment (spa).
Discovery calls take 30 minutes. We will scope to a fixed price and, where you are responding to a tender, map our capability statement to the evaluation criteria.
Get a ScopeTell us what needs testing and we come back with a fixed fee within 48 hours — no hourly estimates.