September 21, 2025
Updated: August 17, 2026
A transparent comparison of 20 local and Malaysia-serving pentest providers, with licence checks, accreditation evidence, buyer fit, and RFP questions.
Mohammed Khalil

Last updated: August 17, 2026
Malaysia has a strong mix of local penetration-testing specialists, regional cybersecurity firms, managed security providers, and cross-border PTaaS companies. There is no defensible universal “best” provider. Choose according to system location, current NACSA eligibility where applicable, technical fit, company-level accreditation, assigned-team experience, reporting, retesting, data handling, and delivery model.
This guide compares 20 providers using current service pages and issuer evidence. It explains how to interpret CREST and PTSP, compare like-for-like quotations, and score proposals consistently. The list is a procurement shortlist, not a regulator-endorsed ranking.
Publisher disclosure: DeepStrike publishes this guide and appears first as the publisher's selection. That placement is not an independent regulator or market ranking. The other providers are presented alphabetically. Accreditation and licence status can change, so verify the current NACSA licensing portal and relevant issuer directory before signing a contract.
Malaysia's security and assurance environment has changed materially since 2024.
The practical lesson is simple: a buyer needs both a technically capable testing team and evidence that the engagement is legally and contractually appropriate for the systems in scope.
The following rules keep the list useful without overstating what public evidence can prove:
Evidence was checked on August 17, 2026. This is a buyer's shortlist, not legal advice or a guarantee that a provider remains eligible for every future engagement.
| Provider | Malaysia basis | Core scope | Evidence signal checked | Best-fit buyer |
|---|---|---|---|---|
| DeepStrike | Cross-border; US and UAE company presence | Manual pentesting, PTaaS, web, mobile, cloud, infrastructure, red team | First-party service and pricing pages; no Malaysia issuer status used | Product and engineering teams wanting a live dashboard and long retest window |
| Across Verticals | Malaysia-based | Pentesting, red teaming, application security, GRC | Current CREST Marketplace penetration-testing profile | Enterprises wanting technical testing plus advisory |
| ASK Pentest | Kuala Lumpur | Security posture assessment, intelligence-led testing, red team, SOC | Current CREST Marketplace supplier profile | Regulated and public-sector buyers needing controlled adversary testing |
| Condition Zebra | Petaling Jaya | Web, mobile, network, social engineering, MDR | Current CREST Marketplace penetration-testing profile; company states NACSA status | Buyers combining local testing and managed defense |
| Cybernage | Malaysia-based | Web, mobile, network, red team, hardening | Current first-party service page; no issuer status used in this guide | Mid-market buyers needing a broad technical scope |
| EC-Council Global Services | Malaysia facility and regional delivery | Remote pentesting, vulnerability assessment, consulting, managed security | Current CREST Marketplace supplier profile | Regional organizations wanting consulting and testing under one group |
| Firmus | Malaysia-based | Network, web, mobile, cloud, red team, DFIR | Current CREST Marketplace penetration-testing profile | Buyers wanting assessment, response, and managed services |
| Flawtrack | Cyberjaya | Pentesting, CTEM, ASM, cloud, network, applications | Current first-party service and Malaysia pages; company displays NACSA evidence | Teams combining point-in-time testing with exposure management |
| LGMS / LE Global Services | Subang Jaya | Network, web, mobile, source review, red team | Current CREST Marketplace penetration, application, and mobile testing profiles | High-assurance, financial-sector, and complex enterprise scopes |
| NetAssist (M) | Malaysia-based | Web, mobile, API, network, infrastructure, MSSP | First-party service and certification pages; issuer status still requires live confirmation | Buyers wanting testing plus SOC and security consulting |
| Nexagate | Malaysia headquarters | Pentesting, red team, cloud, IoT/ICS, compromise assessment | Current CREST Marketplace penetration-testing profile | Regional enterprises and mixed IT/OT environments |
| Ofisgate | Malaysia-based | Network and application pentesting, audit, training | First-party service page; current CREST page is a training-provider profile, not used here as testing accreditation | Buyers wanting local delivery with training support |
| OrenG Academy | Malaysia-based | Internal/external, web, mobile, API, cloud, AD, source review | Current first-party service page; no issuer status used in this guide | Teams combining assessment, exercises, and skills development |
| Qumulo Sdn Bhd | Malaysia-based | Pentesting, red team, security assessments | Current CREST Marketplace supplier profile | Buyers seeking a focused local security-assessment firm |
| Secure Insight | Kuala Lumpur | External/internal/web pentest, red team, software assurance | Current first-party services and case studies; current PTSP status must be confirmed with issuer | Regulated, infrastructure, and assurance-heavy projects |
| Securelytics | Selangor | Pentesting, application testing, security lab, Common Criteria | Current first-party testing page; no issuer status used in this guide | Product, lab, and security-evaluation projects |
| Simply Data | Puchong | Web, mobile, network, cloud, red team, managed security | CREST Marketplace currently shows Vulnerability Assessment; company licence/PTSP claims require issuer confirmation | SMEs and enterprises combining assessment with managed services |
| SysArmy | Kuala Lumpur | Internal/external, web, mobile, database, host, SOC | Current CREST Marketplace penetration-testing profile | Buyers wanting infrastructure and application testing with monitoring |
| Vigilant Asia | Shah Alam | Network, wireless, API, web, mobile, intelligence-led testing, SOC | First-party site states CREST expertise; confirm current issuer scope before award | Organizations combining MSSP operations with offensive assurance |
| wizlynx group | Malaysia presence; Swiss-headquartered group | Web, mobile, network, cloud, IoT, red team | Current CREST Marketplace penetration-testing profile; Malaysia page states NACSA licence 20021-02 | Multinationals seeking regional delivery and standardized methodology |
“Evidence signal” is not the same as legal eligibility. Where Act 854 licensing applies, verify the provider's current licence, exact legal entity, service category, conditions, and expiry in the live NACSA portal.

DeepStrike's penetration testing service combines manual testing with a customer dashboard, Slack collaboration, Jira and ServiceNow integration, reporting, remediation guidance, and retesting. Its pricing-plan page describes one-shot and continuous models and states that Basic engagements include free remediation retesting for 12 months. DeepStrike also publishes a results-based pricing model under which a pre-agreed project price is waived if no meaningful vulnerabilities are found.
DeepStrike should be considered a cross-border provider, not a Malaysian local firm. Its public footer identifies United States and UAE entities. A Malaysian buyer should therefore determine whether the intended systems, services, and delivery model fall within Act 854 licensing requirements or an exemption, and should obtain the relevant current evidence before contracting.
Best for: SaaS, fintech, e-commerce, and engineering teams that want manual-first testing, real-time findings, integrations, and extended retesting.

Across Verticals describes itself as a Malaysian boutique cybersecurity consulting firm covering penetration testing, security research, compliance, incident response, and training. The current CREST Marketplace profile lists penetration testing and describes experience in application, infrastructure, red-team, and regulatory work.
Best for: Enterprises that want a technically focused testing team with broader security advisory support.

ASK Pentest offers security posture assessment with social-engineering and intelligence-led options and has a Kuala Lumpur contact address. Its CREST Marketplace profile describes controlled use of real-world attacker tools and techniques.
Best for: Financial, public-sector, and enterprise buyers seeking intelligence-led or adversary-style exercises alongside conventional assessment.

Condition Zebra offers network, application, mobile, social-engineering, and related testing from Petaling Jaya. The CREST Marketplace currently lists the company for penetration testing. The company also states that it holds NACSA licences, but buyers should confirm the legal entity and current service category in the NACSA portal.
Best for: Organizations wanting local penetration testing plus managed detection, incident response, or security training.

Cybernage advertises web-application, mobile-application, system, and network penetration testing, plus red teaming, forensics, hardening, and compliance consulting in Malaysia. This guide found current first-party service evidence but does not use an issuer-backed company accreditation to rank it.
Best for: Mid-market buyers that need common application and infrastructure scopes from one local provider.

EC-Council Global Services operates a cyber-defense facility in Malaysia and offers consulting, remote penetration testing, vulnerability assessment, incident response, and managed services. Its CREST Marketplace profile is current and describes the group's penetration-testing methodology.
Best for: Regional or multinational organizations that prefer a broad consulting and managed-security group with a Malaysia delivery base.

Firmus offers penetration testing across networks, web applications, cloud environments, and internal systems, with incident response and managed security services. The CREST Marketplace profile lists network, web, mobile, red-team, source-code, physical, and social-engineering capabilities.
Best for: Buyers looking for a local provider that can support assessment, response, and longer-term security operations.

Flawtrack's Malaysia penetration-testing page combines expert-led testing with attack-surface and continuous-exposure services. Its site identifies a Cyberjaya headquarters and displays NACSA licensing evidence. Because a company page is not the final issuer record, buyers should still verify the current licence, legal entity, scope, and conditions in the NACSA portal.
Best for: Security teams that want penetration testing connected to continuous attack-surface or exposure management.

LGMS is a Malaysian pure-play cybersecurity assessment firm offering network, application, mobile, source-code, social-engineering, red-team, and related services. The current CREST Marketplace entry for LE Global Services lists penetration testing plus application and mobile testing specialisms.
Best for: Financial institutions, regulated organizations, and complex enterprises seeking a mature assessment-led firm.

NetAssist offers penetration testing for web applications, mobile applications, APIs, networks, and infrastructure, alongside security audits and managed services. Its certification page displays CREST, penetration-test licence, and PTSP claims. Buyers should confirm each current issuer record and the exact contracting entity rather than relying on logos alone.
Best for: Organizations that want a Malaysian MSSP to combine penetration testing, SOC coverage, and security consulting.

Nexagate offers penetration testing, cloud and IoT/ICS assessment, compromise assessment, and red teaming from a Malaysia headquarters. Its CREST Marketplace profile currently lists penetration testing.
Best for: Regional enterprises with mixed application, cloud, infrastructure, and industrial or connected-device scope.

Ofisgate offers application and infrastructure penetration testing, remediation guidance, audit, and training in Malaysia. A current CREST page for Ofisgate is labeled as a training-provider profile, so this guide does not present it as evidence of firm-level CREST penetration-testing accreditation. Buyers should verify current NACSA and PTSP evidence directly with the relevant issuers.
Best for: Buyers that value local testing, audit, and training from the same provider.

OrenG Academy publishes a broad VAPT scope covering internal and external infrastructure, web and mobile applications, APIs, cloud, Active Directory, databases, hosts, and source-code review. It also offers cybersecurity training and simulation. No issuer-backed company penetration-testing accreditation is used for ranking in this guide.
Best for: Organizations that want technical assessment and internal capability development in the same engagement.

Qumulo offers penetration testing, red teaming, security assessment, and related security solutions in Malaysia. Its current CREST Marketplace profile lists the company as a focused security-assessment firm.
Best for: Buyers seeking a focused local provider with current CREST marketplace evidence.

Secure Insight offers external, internal, and web-application penetration testing, red teaming, software assurance, threat intelligence, and security operations from Kuala Lumpur. Its public case studies include financial, government, telecommunications, and infrastructure scenarios. Confirm current PTSP and any NACSA status with the issuing bodies before award.
Best for: Regulated, infrastructure, and assurance-heavy projects requiring black-box, white-box, or software-assurance work.

Securelytics combines penetration testing and application-security assessment with laboratory and Common Criteria work. This mix can be relevant when a buyer needs both system testing and product-evaluation capabilities. This guide found current first-party testing evidence but does not use an issuer record to state a current penetration-testing accreditation.
Best for: Product vendors and enterprises that need testing alongside laboratory or security-evaluation services.

Simply Data offers web, mobile, network, cloud, social-engineering, and red-team services from Puchong. Its current CREST Marketplace profile shows a Vulnerability Assessment specialism, not a penetration-testing badge. The company also publishes NACSA and PTSP claims; buyers should confirm both issuer records and avoid treating vulnerability-assessment accreditation as automatically identical to penetration-testing accreditation.
Best for: SMEs and enterprises looking to combine assessment work with monitoring or managed-security support.

SysArmy offers security assessment and penetration testing alongside monitoring and technology-risk services in Kuala Lumpur. Its CREST Marketplace profile lists internal and external, web, mobile, database, host, and network-appliance assessment capabilities.
Best for: Buyers needing infrastructure and application testing with an option for ongoing monitoring.

Vigilant Asia offers network, wireless, application, API, web, mobile, firewall, social-engineering, and intelligence-led penetration testing from Shah Alam, alongside managed-security services. Its site describes CREST-accredited expertise. Buyers should confirm the current issuer record, exact service accreditation, and NACSA status before relying on those signals in procurement.
Best for: Organizations that want offensive testing integrated with a 24/7 managed-security relationship.

wizlynx's Malaysia service page offers manual and automated testing for applications, networks, cloud, mobile, and other environments and states NACSA licence number 20021-02. The CREST Marketplace profile currently lists penetration testing. The NACSA number should still be checked in the live portal before contract award.
Best for: Multinational and regulated organizations wanting a global methodology with Malaysia delivery capability.
| Framework | Who it affects | Current 2026 position | What to require from a provider |
|---|---|---|---|
| Cyber Security Act 2024 (Act 854) | Providers and customers where the statutory service and system-location rules apply; NCII entities have additional duties | Act in force since August 26, 2024. Specified services are licensed, subject to regulations, exemptions, conditions, and current NACSA directives. | Current licence evidence for the exact legal entity and service, or documented exemption analysis; confirm in live portal. |
| BNM RMiT, November 2025 | Financial institutions within the policy's applicability | Quarterly VA for internal/external network components supporting critical systems; annual intelligence-led pentests of infrastructure, critical systems, and digital services; pre-introduction testing for new systems; suitably accredited testers; documented escalation. | RMiT-mapped scope, threat scenarios, tester/provider accreditation, safe oversight, evidence handling, executive report, remediation tracking, and retest. |
| PDPA and 2024 amendment | Organizations processing personal data within the Act's scope | Amendment provisions commenced in phases on January 1, April 1, and June 1, 2025. PDPA supports security and breach-governance duties but is not a blanket annual-pentest rule for every organization. | Scope systems processing personal data; define test-data handling, access, retention, deletion, incident escalation, and breach-response support. |
| PCI DSS v4.0.1 | Entities that store, process, transmit, or can affect payment-account data environments | PCI DSS v4.0.1 is the current PCI SSC version. Requirement 11.4 contains penetration-testing controls for in-scope environments. | Confirm CDE scope, segmentation testing, tester independence and competence, methodology, frequency, change triggers, and evidence required by the assessor. |
Under Section 27(5), providing a licence-required cybersecurity service without a licence can result in a fine of up to RM500,000, imprisonment for up to ten years, or both. Check the official Act and commencement page, the current NACSA legal and directives page, and the operational licensing portal. A secondary legal analysis by Mayer Brown independently identifies the same Section 27(5) maximum.
For financial institutions, use the current RMiT policy PDF, not the superseded June 2023 version. For privacy timing, the official PDPA commencement gazette shows the three 2025 commencement dates.
| Signal | What it generally tells a buyer | What it does not prove |
|---|---|---|
| NACSA licence | The named legal entity is licensed for a specified regulated cybersecurity service, subject to current terms, scope, and validity. | That every tester is equally skilled, that every engagement is high quality, or that a different group entity is covered. |
| CREST company accreditation | The company has been independently assessed for the service shown in its current CREST profile. | A Malaysian statutory licence, accreditation for services not shown, or automatic coverage of every subsidiary. |
| CyberSecurity Malaysia PTSP certification | A locally owned provider has met the PTSP scheme's certification criteria and is listed by the scheme when current. | A substitute for a NACSA licence where statutory licensing applies. |
| Individual certifications such as OSCP, CREST, GIAC, or CISSP | A named person passed a particular knowledge or practical assessment. | Company-level accreditation, relevant experience for the buyer's exact stack, or guaranteed assignment of that person. |
| ISO/IEC 27001 certificate | The certified organization operates an information-security management system within the certificate's defined scope. | Penetration-testing skill or a licence to provide a regulated service. |
The CyberSecurity Malaysia PTSP scheme and the CREST Marketplace are useful independent sources, but buyers should read the exact scope instead of counting logos.
There is no defensible universal average because quotations depend on the asset count, complexity, access model, environment, compliance requirements, testing depth, timeline, retest terms, and deliverables. One Malaysia-based provider publishes a broad planning envelope of roughly RM5,000 to more than RM150,000 across different engagement sizes. Treat that as a provider-published range, not a verified market average.
The best way to compare price is to send the same scope and deliverable requirements to at least three eligible providers.
| Scope | Main cost drivers | The quotation should state |
|---|---|---|
| Web application and API | Roles, endpoints, business logic, integrations, authentication, source access, test accounts | Applications and APIs included, access model, manual coverage, business-logic testing, retest, report formats |
| Mobile application | iOS/Android coverage, backend APIs, certificate pinning, device requirements, code access | Platforms/builds, API inclusion, device/emulator assumptions, storage and transport testing, retest |
| External or internal network | IP count, segmentation, Active Directory, VPN access, locations, safe exploitation limits | Exact ranges, internal/external boundaries, credential level, excluded systems, outage safeguards |
| Cloud environment | AWS/Azure/GCP accounts, services, identities, regions, Kubernetes, serverless, IaC | Accounts and services, permissions, provider policy constraints, identity paths, evidence handling |
| Red team or intelligence-led test | Objectives, threat model, social engineering, physical scope, duration, detection testing | Objectives, assumed breach conditions, approvals, deconfliction, stop conditions, reporting and replay |
| Continuous PTaaS | Number of releases, recurring test windows, scanner component, integration, service level | Manual versus automated coverage, response times, included retests, dashboard access, annual deliverables |
Do not compare a vulnerability scan with a human-led penetration test as if they are equivalent products. A lower quote can reflect a narrower asset list, fewer tester days, less manual validation, no remediation workshop, or a limited retest window.
Useful scope-specific references are available for buyers comparing:
Score every proposal against the same evidence. A provider that fails a mandatory legal or safety condition should be excluded before weighted scoring.
| Criterion | Weight | Evidence to request |
|---|---|---|
| Legal eligibility and contracting entity | 20 | Current licence or documented exemption basis, legal name, service category, validity, insurance, subcontractor disclosure |
| Technical scope fit | 20 | Relevant application, API, cloud, network, mobile, OT, or red-team examples; exact inclusions and exclusions |
| Testing methodology and depth | 15 | Manual versus automated work, standards used, attack paths, business-logic coverage, validation rules |
| Assigned team evidence | 10 | Named lead, relevant experience and certifications, local/remote location, language, availability |
| Reporting quality | 10 | Redacted sample, executive summary, technical evidence, root cause, severity rationale, remediation guidance |
| Retesting and remediation support | 10 | Number and timing of retests, closure evidence, engineering workshop, unresolved-risk handling |
| Data handling and operational safety | 10 | Rules of engagement, encryption, access control, storage, retention, deletion, logging, incident and stop procedures |
| Commercial terms | 5 | Fixed assumptions, change-control rates, taxes, payment terms, schedule, cancellation and delay terms |
| Total | 100 | Use the same scorecard and scope for every bidder. |
Suggested scoring scale: 0 means no evidence; 1 means materially inadequate; 3 means acceptable; 5 means excellent and independently supported. Multiply each criterion's normalized score by its weight. Keep written reasons for procurement and audit review.
| Provider model | Strongest fit | Watch for |
|---|---|---|
| Local pure-play pentest firm | High-assurance testing, local regulatory context, on-site work | Capacity, specialist availability, and peak-period lead time |
| Regional or global consultancy | Multi-country programs, standardized governance, broad specialist bench | Higher overhead, team substitutions, and subcontracting |
| MSSP with pentesting | One relationship for testing, monitoring, and response | Independence, separation of duties, and whether testing is a core capability |
| PTaaS provider | Product teams needing dashboards, integrations, recurring testing, and rapid collaboration | Local licence applicability, data location, and the balance of manual versus automated work |
| CTEM or ASM-led provider | Continuous discovery and prioritization around a changing external attack surface | Whether the quoted “pentest” includes deep manual exploitation and business-logic work |
| Training-led provider | Organizations building internal capability alongside assessment | Current company accreditation, assigned testing team, and separation between training and assurance scopes |
There is no universal best provider. Build a shortlist based on legal eligibility, relevant technical scope, current company-level accreditation, assigned-team experience, methodology, reporting, data handling, retesting, and price. Use the same RFP and 100-point scorecard for every bidder.
Act 854 creates licensing requirements for specified cybersecurity services, including penetration testing, subject to the regulations, exemptions, system location, current directives, and the facts of the engagement. Verify the exact provider entity and service in NACSA's live portal and obtain legal advice for ambiguous cases.
Public provider pages show a very broad range, from roughly RM5,000 for narrow scopes to more than RM150,000 for complex work, but this is not a verified market average. Asset count, complexity, access, manual depth, compliance, timeline, deliverables, and retesting determine the final quote.
A NACSA licence is a Malaysian statutory permission for the named regulated service and entity. CREST is an independent company and individual accreditation ecosystem. PTSP is a CyberSecurity Malaysia certification scheme for qualifying local providers. None of these signals automatically replaces the others.
Frequency should follow risk, material change, contracts, and applicable regulation. The current BNM RMiT policy requires covered financial institutions to conduct annual intelligence-led penetration tests and quarterly vulnerability assessments for specified critical-system components, plus testing before introducing new systems.
Remote or cross-border delivery may be possible, but eligibility depends on the service, the systems' location, the contracting and delivery entities, applicable exemptions, sector rules, and current NACSA requirements. Do not assume that overseas incorporation removes Malaysian licensing or data-handling obligations.
The right provider is not the company with the longest badge row or the lowest initial quote. It is the eligible team that understands the exact environment, tests deeply and safely, produces evidence engineers can use, protects sensitive data, and verifies remediation.
Shortlist three providers, confirm the current issuer records, and give each the same assets, objectives, constraints, deliverables, and retest requirements. Then score the proposals with the 100-point model above.
DeepStrike is one option for teams that want manual penetration testing, live collaboration, a results dashboard, and extended retesting. For Malaysian systems, confirm the engagement's licensing and data-handling requirements before award. If that delivery model fits your scope, request a scoped proposal.
Mohammed Khalil is a Cybersecurity Architect at DeepStrike, specializing in advanced penetration testing and offensive security operations. With certifications including CISSP, OSCP, and OSWE, he has led numerous red team engagements for Fortune 500 companies, focusing on cloud security, application vulnerabilities, and adversary emulation. His work involves dissecting complex attack chains and developing resilient defense strategies for clients in the finance, healthcare, and technology sectors.

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today
Contact Us