Services
Fixed-scope engagements.
Each engagement below is a defined piece of work with defined deliverables and an indicative duration. We quote a fixed price against a fixed scope — so the number you approve is the number you pay, and a finding that turns out to be more work than expected is our problem, not a change order.
Penetration testing
Mobile-Money Application Penetration Test
Scope and deliverables
A grey-box penetration test of the mobile-money application (mobile client, USSD flows and their supporting APIs), covering authentication, transaction integrity, fraud controls and the OWASP MASVS/ASVS areas relevant to a payment app. Deliverables: a findings report with severity-rated issues and remediation guidance, and a retest of critical/high findings once fixed.
Indicative duration 2–3 weeks
Core-Banking Network Penetration Test
Scope and deliverables
An internal network penetration test of the core-banking environment: segmentation between the corporate and card/payment zones, privilege escalation paths, service hardening and lateral-movement resistance. Deliverables: a prioritized findings report and a retest of critical/high findings.
Indicative duration 3–4 weeks
Web Application Penetration Test
Scope and deliverables
A penetration test of a web application against the OWASP Top 10 and ASVS, covering authentication, access control, injection, business-logic abuse and session management. Deliverables: a findings report with remediation guidance and a retest of critical/high findings.
Indicative duration 2 weeks
External Perimeter Penetration Test
Scope and deliverables
A penetration test of the internet-facing perimeter: exposed services, VPN and remote-access endpoints, email/DNS hygiene and externally reachable web assets. Deliverables: a findings report ranked by exploitability and a retest of critical/high findings.
Indicative duration 1–2 weeks
Awareness
Phishing Simulation Campaign
Scope and deliverables
A single authorised phishing simulation against an agreed population of staff, using a pretext reviewed with you in advance. We measure delivery, click and report rates in AGGREGATE — no individual employee is named to you or recorded by us — and deliver a debrief with the rates, the pretext used, and awareness recommendations. No credential is ever captured: a simulated submission is counted, never stored.
Indicative duration 1 week
Quarterly Phishing Awareness Programme
Scope and deliverables
Four authorised phishing simulations over twelve months, with escalating difficulty and a debrief after each. Deliverables: per-campaign aggregate rates, the twelve-month trend, and a board-ready summary evidencing that an awareness programme is OPERATING — the form regulators and correspondent banks ask to see, which a single campaign cannot demonstrate. Aggregate only; no employee is named. No credential is ever captured.
Indicative duration 4 campaigns over 12 months
Regulatory readiness
SWIFT CSP Readiness Assessment
Scope and deliverables
A gap assessment of the institution against the SWIFT Customer Security Programme (CSP) mandatory and advisory controls, ahead of the annual KYC-SA attestation. Deliverables: a control-by-control gap analysis, a prioritized remediation plan, and evidence-readiness guidance for the self-attestation.
Indicative duration 2–3 weeks
ANTIC Audit-Readiness Assessment
Scope and deliverables
A readiness assessment against the security domains of Cameroon’s ANTIC annual audit mandate: governance, access control, network and application security, data protection and incident response. Deliverables: a domain-by-domain gap analysis and a prioritized remediation plan to enter the audit prepared.
Indicative duration 2–3 weeks
Why there is no price list here
Scope drives price, and a bank with three times the estate should not pay a number set for someone else. Publishing a figure would anchor every conversation to the wrong institution — so tell us what you need assessed and we will quote a fixed price against a fixed scope.