Founded by a practitioner with over 35 years in the field — penetration testing, DFIR, SOC management, and executive security leadership. No juniors, no fluff.
CYSMIQ was founded by a practitioner with over 35 years of hands-on security experience spanning penetration testing, ethical hacking, security assessments, governance audits, security operations, and SOC management.
That depth of experience shapes everything we do — from the way we scope engagements to the way we write reports. We don't send junior consultants with a framework and a hope. We bring operators who've seen real adversaries, real breaches, and real consequences.
Based in Johannesburg, we work directly with clients and as a subcontractor for MSPs across South Africa and internationally. Our model is lean by design — low overhead, senior hands on every engagement, and no padding with unnecessary process.
Findings that business leaders and technical teams can both act on — same report, different sections.
Every engagement is staffed by experienced practitioners, not graduates learning on your time.
We prioritise your real risk over box-ticking. Compliance is a byproduct of good security, not a goal.
We're not a one-and-done shop. We think in terms of ongoing partnerships and shared risk ownership.
Our team carries decades of hands-on engagement history. We've broken the things we help you defend — and we know the difference between a finding and a real risk.
Every scope is written from scratch. Your environment, your threat model, your industry — not a recycled checklist that looks like every other report.
We operate cleanly as a subcontractor under your brand. Deliverables, reporting, and client interfacing — on your terms.
Whether you need a 3am incident handler or a boardroom risk narrative — CYSMIQ scales to where the conversation is happening.
No-obligation scoping call. Senior practitioners on every engagement. Johannesburg-based, globally capable.