Johannesburg · South Africa, UK and Europe

We find what your estate is actually exposed to, then fix it.

Most security firms hand over a findings report and leave. We write the report, then ship the remediation as infrastructure code your team reviews and merges.

16 years
Security assessment and incident response
~200
Investigations led, single host to multinational
70 → 90%
AWS Security Hub score, taken there and held

Who we are

A two-person consultancy. Every engagement is delivered by the people you meet, so there is no pyramid, no junior bench and no handover after the sale.

We pair sixteen years of security assessment and incident response across Europe, the Middle East, Africa and Asia Pacific with a decade of production platform engineering at AWS, BMW, Absa and Discovery. One of us has run the assessment. The other has run the estate being assessed.

What our consultants hold

CISSP
Certified Information Systems Security Professional
GCFA
GIAC Certified Forensic Analyst
PCI QSA
Qualified Security Assessor, and PCI Professional
CREST CRT
Registered Penetration Tester
AWS SAA
Certified Solutions Architect
MSc / BSc
Information Security and Risk; Digital Forensics (Hons)

Members of the IITPSA and (ISC)². These are held by our individual consultants. SNS Labs is not itself a CREST member company or a PCI SSC Qualified Security Assessor Company.

What we do

Four engagements, each fixed in scope and fixed in price.

The list is short on purpose. These are the four we can deliver to the standard we would want applied to our own systems.

CIS Benchmarks · AWS FSBP

Cloud & Kubernetes Security Posture Review

A two-week review of your AWS, Azure or Kubernetes estate through read-only access. Evidence-driven rather than interview-driven, so it runs without occupying your team.

  • AWS, Azure and GCP estates
  • EKS, OpenShift and self-managed Kubernetes
  • Terraform, IAM and CI/CD pipeline review
  • Findings ranked by exploitability, not scanner severity

Optional hardening sprint: we ship the fixes as pull requests.

PCI DSS v4.0.1

PCI Readiness & Remediation

The future-dated requirements became mandatory on 31 March 2025, and the ones causing most pain are engineering problems rather than policy ones. We assess the gap and build the controls that close it.

  • 6.4.3 · payment page script inventory and authorisation
  • 11.6.1 · payment page tamper and change detection
  • 11.3.1.2 · authenticated internal vulnerability scanning
  • 12.3.1 · targeted risk analyses
  • SAQ facilitation and evidence preparation

We deliver readiness assessment and remediation. Formal ROC sign-off is carried out by a partner QSA Company.

Delivered on site or remote

Security Training & Executive Tabletops

Practitioner-led sessions built from live incident casework and current production engineering, using code and breaches we have actually worked on.

  • Secure development for engineering teams
  • Cloud and Kubernetes security for platform teams
  • Executive incident-response tabletop exercises
  • Gauteng on site, or remote across EMEA

POPIA · ISO 27001 · NIST CSF

Compliance Gap Assessment

Where you actually stand against the standard that applies to you, and a sequenced plan to close the distance.

  • POPIA readiness and operator obligations
  • ISO 27001 / 27002 and NIST CSF control mapping
  • Risk register and remediation roadmap
  • Reporting written for a board, not for an auditor

How it runs

A findings report is half a job.

We stay on for the half that actually changes your risk.

  1. Assess

    Read-only access, evidence over interviews, findings ranked by what an attacker could actually reach. Mapped to whichever standard you are held to.

    • Fixed scope agreed before we start
    • No scanner output pasted into a PDF
    • Written for engineers and for the board
  2. Remediate

    The part most consultancies leave to you. We implement the fixes ourselves as reviewable infrastructure code, inside your pipeline and your change process.

    • Terraform, Helm and CI/CD pipeline changes
    • Delivered as pull requests your team approves
    • Tooling built where a control needs automating
  3. Sustain

    Posture drifts back within months unless something holds it. We re-review on a cadence and train the team that owns the estate day to day.

    • Scheduled re-review against the original baseline
    • Secure development and cloud security training
    • Incident-response tabletops for the exec team

How we work

Fixed scope and a fixed fee, agreed in writing before anything starts. Senior people on every engagement, because there are only senior people.

Two clients at a time, so nobody waits behind somebody else’s deadline. We work across South Africa and remotely into the UK and Europe, where our consultants spent the first decade of their careers. And we will tell you when the honest answer is that you don’t need us yet.

Get in touch

Tell us what you are protecting and what is forcing the timeline.

If we are not the right fit we will say so, and point you at someone who is.

info@snslabs.io
Based in
Sandton, Johannesburg
Working across
South Africa, UK and Europe
Response
Within one business day