If you are shortlisting providers for penetration testing in Singapore, you have a problem most people do not envy. The range is wide. Global consultancies that charge enterprise rates. Local boutiques that know the regulatory landscape. Product companies with a services arm bolted on.
This list covers ten firms with a confirmed Singapore presence and real penetration testing capabilities. Whether you need a pentest Singapore provider for MAS TRM compliance, ISO 27001 certification, or a customer security questionnaire, these are the firms that actually do the work.
One disclosure upfront: Bravix Infosecurity is my company. It is on this list because it belongs here, but I have applied the same criteria to every entry. Take the ranking as a starting point, not a verdict.
1. Bravix Infosecurity
Bravix is a CREST-certified consultancy based in Singapore with coverage across the APAC region. The team comes from red teaming and bug bounty backgrounds. Every finding is hand-verified, no scanner dumps dressed up as a report.
Their offensive scope covers web, mobile, network, cloud, API, OT/ICS, and AI/LLM security. They also run GRC and vCISO work. Every engagement maps to ISO 27001, PCI DSS, and MAS TRM requirements, so a single assessment covers technical findings and compliance evidence without a separate gap assessment.
As a VAPT company, Bravix covers the full scope Singapore procurement teams expect: web and API penetration testing, mobile application penetration testing (iOS, Android, hybrid frameworks), network and wireless penetration testing, cloud configuration review, and System Security Acceptance Testing (SSAT) for government systems under IM8.
Best for: Government, semi-government, and medium to large enterprises looking for CREST-certified penetration testing, red teaming, cloud and application security with APAC coverage.
2. Ensign InfoSecurity
Ensign InfoSecurity is the largest pure-play cybersecurity firm in Southeast Asia. Formed as a joint venture between Temasek and StarHub in 2018, they've grown to over 500 cybersecurity professionals with a deep presence in Singapore. If you're a large enterprise that needs scale, Ensign has it.
Their offensive security practice covers penetration testing, red teaming, and attack simulation across web, mobile, network, cloud, and OT environments. Because of their size, they can field multiple concurrent engagement teams and sustain long-running red team exercises that smaller firms can't staff. They also run a 24/7 defence centre, threat intelligence platform, and managed detection and response service.
Where Ensign shines is breadth. They're one of the few firms in the region that can run a full-scope enterprise security program: offensive, defensive, and advisory under one roof. The trade-off is that you're paying for that scale. For a focused single-scope pentest, boutiques will give you more individual tester attention per dollar.
Best for: Large enterprises and government agencies that need scale, multi-team engagements, and a vendor with established public-sector credentials.
3. Deloitte (Southeast Asia Cyber Risk)
Deloitte's Southeast Asia cyber risk practice is headquartered in Singapore and is the most regulatory-savvy Big Four option for penetration testing. If you're dealing with MAS TRM, PDPA compliance, or a major audit and need someone who speaks both security and governance fluently, Deloitte has the people and the methodologies.
On the technical testing side, they offer penetration testing and vulnerability management, but it's wrapped in a consulting framework. You'll get structured deliverables, clear remediation roadmaps, and executives who can present to a board. You won't necessarily get the most aggressive tester. Different tool for a different job.
Best for: Regulated industries (banking, insurance, healthcare) that need audit-ready security testing with strong governance and compliance reporting.
4. PwC (Singapore Cybersecurity)
PwC's Singapore cybersecurity practice sits within their broader consulting arm. They focus on cyber strategy and transformation, security operations, cloud security, and data privacy. Their threat and vulnerability management service covers penetration testing, though it's positioned as part of a wider risk program rather than a standalone engagement.
If you're already using PwC for audit or advisory work, extending to penetration testing is the path of least resistance. Strong on governance, compliance, and board-level reporting. Less specialised on hands-on offensive work than the boutiques higher up this list.
Best for: Existing PwC clients who want to consolidate vendors and value governance integration.
5. EY (Singapore Cybersecurity)
EY's Singapore cybersecurity practice focuses on resilience, risk management, and digital transformation security. Their Cyber Incident Resilience and Response solution bridges the gap between proactive testing and incident preparedness, which is useful if you want both from the same vendor.
Like the other Big Four firms, EY delivers penetration testing as part of a broader consulting engagement. The strength is in structured methodology, risk framing, and executive communication. For technical depth at the exploit level, the boutiques on this list will give you more per dollar.
Best for: Organisations that want cyber resilience and incident response planning alongside vulnerability assessment, from a Big Four framework.
6. wizlynx group
wizlynx group is a Swiss cybersecurity firm with a Singapore office at Robinson Road. They've held CREST accreditation since 2017, which puts them in a small group of globally accredited providers operating in Singapore. Their SG practice focuses on VAPT, red teaming, and social engineering assessments for clients across regulated sectors.
What distinguishes wizlynx from the Big Four on this list is that penetration testing is their core service, not an add-on to a consulting practice. They run a dedicated "Cyber SWAT" incident response team and offer managed security services alongside their offensive testing. If you want a firm that leads with offensive security but has European roots and CREST-level assurance, wizlynx is a solid mid-market option.
Best for: Organisations that want a CREST-accredited pentest specialist with an established SG presence and European governance standards.
7. Insyghts Security
Insyghts Security is a Singapore-based consultancy covering penetration testing alongside a broader security management practice. Their pentest capabilities span web applications, network infrastructure, and cloud environments. They're a practical option for organisations that want testing bundled with ongoing security leadership.
Beyond offensive testing, Insyghts runs a 24/7 security operations centre for threat detection and response, supported by SIEM, XDR, and threat intelligence platforms. Their CISO-as-a-Service helps organisations achieve CSA Cyber Essential, Cyber Trust, and ISO 27001 certification. Their security engineering team handles cloud architecture across AWS, Azure, and hybrid environments.
Best for: Organisations that want penetration testing paired with vCISO leadership and continuous monitoring under one roof.
8. Accenture (Singapore Cybersecurity)
Accenture's Singapore cybersecurity practice sits within their global security division. They're strong on the strategy and transformation side: security operations centre build-outs, zero trust architecture, identity management, and increasingly Gen AI security. Their annual State of Cybersecurity Resilience report is worth reading if you're benchmarking your program.
For hands-on penetration testing, they're competent but not specialised. You're paying for the Accenture machine: project management, methodology, global threat intelligence. That suits some organisations fine, particularly those that need a vendor their procurement team already trusts.
Best for: Large organisations that need security transformation programs (SOC, zero trust, identity) alongside assessment work, and want a single vendor for all of it.
accenture.com/sg-en/services/cybersecurity
9. Horangi (now Bitdefender)
Horangi was a Singapore-founded cybersecurity startup that built a strong reputation for cloud security and pentest services in the APAC region. They were acquired by Bitdefender in 2024, and their capabilities are now integrated into Bitdefender's enterprise business. The original Horangi team's pentest methodology and cloud security expertise still inform the service.
If you're already in the Bitdefender ecosystem for endpoint protection or XDR, extending to penetration testing through the same vendor is practical. The Horangi heritage means the cloud security testing capabilities are real, not just a marketing line. Worth considering if you want cloud-native security testing tied to a broader platform play.
Best for: Organisations already using Bitdefender products or looking for cloud-native security testing with APAC context.
10. KPMG (Singapore Cybersecurity)
KPMG's Singapore cyber security practice operates under their risk consulting division. They cover cyber strategy, security operations, cloud security, and data privacy. Their SG website has a dedicated cyber insights section, and they're active in the local regulatory conversation around MAS TRM and PDPA.
Similar profile to PwC and EY: strong on governance and risk, competent on technical testing but not as a core specialisation. If you're an existing KPMG client, they're a practical choice for consolidating your security assessments with your broader audit and advisory relationship.
Best for: Existing KPMG clients in regulated industries who want cybersecurity testing integrated with their audit and risk advisory program.
How to choose a penetration testing provider in Singapore
Before you sign anything, ask these questions. They apply whether you are hiring a penetration testing Singapore firm for the first time or switching providers:
- Who's actually doing the testing? Some firms sell the engagement then hand it to a junior consultant. Ask for the lead tester's certifications and experience. CREST CRT or OSCP is the minimum. If they can't tell you who's on the team, that's a red flag.
- Manual testing or scanner output? A real pentest involves manual exploitation, business logic testing, and chaining vulnerabilities together. A vulnerability scan run by a human is not a pentest. Ask how much of the engagement is manual.
- Do you understand Singapore's regulatory landscape? MAS TRM, PDPA, CSA guidelines, and the Cybersecurity Act all have specific testing requirements. Your provider should know which framework you're testing against without you explaining it.
- What does the report look like? Ask for a sample report (redacted). You should see: an executive summary your board can read, technical findings with proof-of-concept steps, and remediation guidance your engineers can act on. If the sample is 200 pages of Nessus output, walk away.
- What happens after the report? Good providers offer remediation support, retesting, and are available for questions after delivery. Bad ones hand you a PDF and disappear.
How much does penetration testing cost in Singapore?
Rough ranges for pentest Singapore engagements based on what we see in the market:
- Web application pentest -- SGD 8,000 to SGD 25,000 depending on size and complexity
- Network infrastructure pentest -- SGD 10,000 to SGD 30,000 for an internal/external combo
- Mobile application pentest -- SGD 8,000 to SGD 20,000 per platform (iOS, Android)
- Red team engagement -- SGD 30,000 to SGD 80,000+ for a multi-week, full-scope exercise
- AI/LLM security assessment -- SGD 15,000 to SGD 40,000 depending on model complexity and deployment architecture
Prices vary based on scope, provider tier, and how quickly you need it done. The cheapest option is rarely the best value. A SGD 5,000 pentest that misses a critical vulnerability costs you more than a SGD 20,000 pentest that finds it.
Common questions
How often should we do penetration testing?
MAS-regulated financial institutions must test at least annually per MAS TRM requirements. For everyone else: annually for external-facing assets, after major architectural changes, and before any compliance audit. Some organisations run continuous testing with quarterly engagements. If you're unsure, your specific regulatory framework will tell you the minimum.
What's the difference between VAPT and penetration testing?
VAPT combines vulnerability assessment (automated scanning) with penetration testing (manual exploitation). Penetration testing is the manual part. A proper engagement includes both: scanning finds weaknesses, manual testing confirms which ones real attackers could exploit. For more detail, read our VAPT guide.
Do we need CREST certification from our provider?
For MAS-regulated entities, CREST is effectively expected. For government tenders in Singapore, it's often required. For private sector work, it's not mandatory but it's the strongest signal of technical competence. CREST accreditation means the firm and its testers have been independently assessed. Anyone can hold an OSCP. Not anyone can pass CREST's organisational review.
Looking for a penetration testing provider in Singapore?
Bravix Infosecurity is a CREST-certified cybersecurity consultancy. Manual testing, AI security specialisation, and reports your engineers can actually use. See our assessment services or get in touch.
