Ethical hacking — penetration testing performed under explicit authorisation — is the single most direct way to verify whether security controls hold under pressure. The discipline is well established globally; in South Africa, it operates under specific legal constraints (the Cybercrimes Act, the ECT Act, sector regulations) and benefits from access to globally recognised certifications. This article walks through how credible ethical hacking is delivered locally and what buyers should expect.
The short answer
Ethical hacking in South Africa is delivered as black-, white-, or grey-box penetration testing, aligned with OWASP PTES and NIST SP 800-115, by Certified Ethical Hackers operating under written authorisation. Tooling combines automated discovery (Nessus, Burp Suite, Nmap) with manual exploitation. The legal framework is the Cybercrimes Act — testing without authorisation is a criminal offence.
Penetration testing increasingly supports procurement assurance, cyber insurance requirements, compliance readiness, and executive visibility into operational security exposure.
Black, white, and grey box — three different questions
Black-box testing simulates an external attacker with no prior knowledge — the closest to a real-world attacker scenario. White box testing assumes full knowledge of the infrastructure, including source code, and focuses on targeted component testing. Grey box testing combines elements of both — some knowledge, a hybrid automated and manual approach. Choosing the right approach depends on the question the test needs to answer.
Mature organisations increasingly run penetration testing as a continuous assurance programme rather than a once-a-year compliance exercise.
OWASP PTES — the methodology buyers should ask for
Credible ethical hacking aligns to recognised methodology — OWASP Penetration Testing Execution Standard (PTES), NIST SP 800-115, OWASP Top 10 and OWASP API Top 10 for application work, and MITRE ATT&CK for adversary technique coverage. Buyers should ask which methodology the tester follows, how findings map to MITRE ATT&CK, and how the deliverables structure the executive summary, risk matrix, technical detail, and remediation.
The tooling landscape — automated discovery, manual exploitation
Tooling combines breadth (automated discovery) with depth (manual exploitation). Common discovery tooling includes Nmap, Nessus, OpenVAS, Nikto, and Burp Suite for web. Manual exploitation uses Metasploit, Cobalt Strike (in authorised engagements), BloodHound and CrackMapExec for Active Directory, and custom scripting where the situation demands. The tester’s judgment matters more than the tool — automated scans cannot reproduce business logic exploitation.
The South African legal framework — Cybercrimes Act and authorisation
The Cybercrimes Act 19 of 2020 criminalises unauthorised access, interception, and interference with computer systems. Ethical hacking operates lawfully only under written authorisation that defines scope, rules of engagement, permitted techniques, and emergency contact protocols. Buyers should expect — and providers should insist on — a signed engagement letter and rules-of-engagement document before any test traffic is generated.
Certifications and what they actually mean
Certified Ethical Hacker (CEH), OSCP, CREST CRT, and GPEN are the certifications most commonly held by practitioners. Of these, OSCP and CREST CRT are the most hands-on, practical assessments rather than multiple-choice. CEH is widely held but less hands-on as a standalone credential. For buyers, the right question is not which certification the tester holds but how recent it is and how active the tester is in practical engagements.
Key Takeaways
- Black, white, and grey box approaches answer different questions — choose by question, not by default.
- Credible engagements align to OWASP PTES, NIST SP 800-115, OWASP Top 10, and MITRE ATT&CK.
- Tooling combines automated discovery with manual exploitation — the judgment matters more than the tool.
- Ethical hacking is lawful in South Africa only under written authorisation under the Cybercrimes Act.
- OSCP and CREST CRT are the most hands-on certifications; CEH is widely held but less practical as a standalone.
How Cyber Resilience Can Help
Cyber Resilience helps organisations validate security controls through structured penetration testing, breach simulation, and remediation-focused security assessments aligned to recognised methodologies.
Speak with our team to arrange a penetration testing scoping discussion.
