NACSA licence in progress
CREST-aligned · OSCP-certified consultants

Penetration testing
services Malaysia.

Web, API, mobile, cloud, network and red team scopes. Our consultants validate real business impact by hand, then deliver Bank Negara RMiT, PDPA, PCI DSS and ISO 27001-ready evidence.

CONSULTANT CERTIFICATIONS

CREST-alignedOSCPOSCEOSWECEHGPENGWAPTCISSP
Web Application Pentest — Final Report
NCR-2026-0714 · OWASP WSTG · CVSS 3.1
RETESTED
2 Critical5 High9 Medium14 Low
IDOR on /api/v2/statements — cross-tenant read9.1Fixed
JWT alg confusion → auth bypass9.8Fixed
Race condition in FPX payment callback8.2Fixed
Mapped to BNM RMiT Appendix 10 · PoC evidence attachedSample report →
9
Core testing scopes
RMiT
Evidence mapping
Manual
Exploit validation
90-day
Free remediation retest
CHOOSE A SCOPE

What to test, how long it takes, what you get

If you are comparing providers, the difference is not the scanner list. It is whether the team can prove exploitability and produce evidence your auditor, board and engineers can all use.

SCOPEBEST FORTYPICAL DURATIONDELIVERABLE
Web application pentestCustomer portals, SaaS apps, ecommerce, internet banking and admin panels.5–15 testing daysOWASP findings, exploit evidence, business logic review and retest letter.
API penetration testingREST, GraphQL, mobile backend and partner integration APIs.4–12 testing daysAuth bypass, object-level authorization, rate-limit and data exposure analysis.
Network and AD pentestInternal networks, VPN, cloud connectivity and Microsoft Active Directory.5–20 testing daysAttack-path mapping, privilege escalation proof and Tier 0 remediation plan.
Red team assessmentBanks, critical infrastructure and mature teams testing detection and response.3–8 weeksObjective-based attack narrative, detection gaps and board-level debrief.
EXPAND WITHOUT STARTING OVER

Start with SOC 2. Every other framework gets easier.

One control maps to many frameworks. Test and evidence it once, and the same work counts toward the next standard your buyers or regulator ask for.

SOCSTART HERE

SOC 2

The usual starting point for SaaS and platform teams. One programme covers roughly 70% of what the next framework asks for.

Controls in scope84
Pentest evidenceReusable
Readiness100%
BNM RMiT
Bank Negara Malaysia — Risk Management in Technology
PDPA Malaysia
Personal Data Protection Act 2010
NACSA / Act 854
Cyber Security Act 2024 and NACSA requirements for NCII entities
ISO 27001
ISO/IEC 27001:2022 — Information Security Management Systems
SOC 2
SOC 2 Type I and Type II
PCI DSS
PCI DSS 4.0

Indicative overlap based on shared control coverage · confirmed against your estate during scoping

NINE TESTING SCOPES

Comprehensive penetration testing

From web applications to embedded devices — manual-led testing across the whole estate, not just the parts a scanner reaches.

01

Web application

OWASP Top 10, business logic flaws, authentication bypass and session management testing.

OWASP Top 10 coverageBusiness logic testingAuthentication testing
Learn more
02

Mobile application

iOS and Android testing including static analysis, dynamic testing and reverse engineering.

iOS and AndroidReverse engineeringData storage analysis
Learn more
03

API security

REST, GraphQL, SOAP and gRPC testing for authentication, authorization and data exposure.

REST and GraphQLAuthentication bypassRate-limit assessment
Learn more
04

Cloud security

AWS, Azure and GCP assessments including misconfiguration and IAM analysis.

AWS, Azure, GCPMisconfiguration detectionIAM security analysis
Learn more
05

Network security

Internal and external network assessments including Active Directory and privilege escalation.

Internal and externalActive Directory testingPrivilege escalation
Learn more
06

Red team operations

Full adversary simulation combining physical, digital and social engineering attack paths.

Full attack simulationPhysical security testingThreat intelligence
Learn more
07

Wireless security

WiFi, Bluetooth and RF testing to identify vulnerabilities and rogue access points.

WiFi security testingRogue AP detectionWPA2 / WPA3 testing
Learn more
08

Social engineering

Phishing campaigns, vishing, pretexting and physical security testing.

Phishing campaignsVishing and pretextingAwareness validation
Learn more
09

IoT security

Device and embedded system testing including firmware analysis and protocol testing.

Firmware analysisProtocol testingHardware security
Learn more
METHODOLOGY

PTES, OWASP and NIST 800-115 — every engagement, same discipline

MITRE ATT&CK for adversary technique coverage, OWASP MASVS for mobile, CIS Benchmarks for cloud. Aligning to recognised standards means findings translate into the control frameworks your auditors already use.

01

Scoping and planning

Define objectives, rules of engagement and timeline. Gather target information and obtain authorisations.

02

Reconnaissance

Passive and active information gathering to understand the attack surface and identify entry points.

03

Vulnerability analysis

Identify and validate weaknesses using automated tooling plus manual testing techniques.

04

Exploitation

Safely exploit vulnerabilities to demonstrate real-world impact and assess exploitability.

05

Post-exploitation

Assess the access gained, lateral movement potential and possible data exposure.

06

Reporting

Deliver findings with risk ratings, proof of concept and remediation guidance.

DELIVERABLES

What lands at the end of the engagement

A structured pack, not a scanner export. We walk your technical team through the findings on a debrief call so the fixes are understood, not just documented.

Board-ready executive summary
What was tested, what an attacker could achieve, and what it means commercially.
Technical report with CVSS-scored findings
Reproduction steps for every finding so engineers can confirm the issue themselves.
Proof-of-concept evidence captures
Screenshots and request/response evidence, with personal data masked.
Prioritised remediation guide
Written for the engineering team and ordered by exploitability, not page number.
Attestation letter
Suitable for customers, procurement and regulators.
Retest report
Free verification after fixes deploy, typically scheduled 30–60 days after the final report.

Why teams pick nCrypt

CREST-aligned, OSCP-certified

Engagements follow CREST-style scoping, evidence and reporting discipline; consultants hold OSCP, OSCE and OSWE.

BNM RMiT evidence mapping

Financial-sector findings map into RMiT remediation and board-reporting workflows.

Reports engineers can act on

Clear risk ratings, reproduction steps and remediation, not a scanner export.

Retest included

Free verification testing after remediation, so fixes are proven rather than assumed.

ACCREDITATIONS & TECHNOLOGY PARTNERS

CREST-aligned methodologyCEH certifiedPCI DSSCrowdStrikePalo Alto NetworksFortinetTenableCyberArk
ALL TESTING SCOPES

Penetration testing services by scope

Web application penetration testing
OWASP Top 10, auth, APIs and business logic
Mobile application penetration testing
iOS, Android, API traffic and device storage
API penetration testing
REST, GraphQL, auth flows and data exposure
Cloud penetration testing
AWS, Azure, GCP and cloud control-plane risk
Network penetration testing
Internal, external, segmentation and privilege paths
Red team operations
Adversary simulation and executive evidence
Wireless penetration testing
Corporate Wi-Fi, rogue AP and WPA enterprise risk
Social engineering testing
Phishing, vishing and awareness validation
IoT penetration testing
Embedded devices, firmware and exposed services
CREST-aligned penetration testing
Assurance format for regulated procurement
Intelligence-led penetration testing
Threat-led scopes for higher-risk environments

Questions buyers ask

nCrypt Malaysia company logo

Tell us the scope.
Proposal within 48 hours.

A free 15-minute scoping call, mutual NDA, then a written proposal covering scope, methodology, testing window, consultant credentials and commercials. Kickoff is typically 5–10 business days after signing.

sales@ncrypt.com.my · Mon–Fri 9AM–6PM MYT · Reply within 1 business day

Rough it out firstNO OBLIGATION

Pick what's in scope. We'll confirm the exact fee after the scoping call.

Targets selected2
Indicative testing days3–5 days
Report + retestIncluded

Typical for this shape: one window, findings raised as they're confirmed, retest 30–60 days after sign-off.

Send this scope

Not sure what you need?

Tell us what needs testing and we come back with a fixed fee within 48 hours — no hourly estimates.