Penetration Testing Providers in Singapore

APAC

Singapore-based penetration testing providers serving the Southeast Asian market.

Singapore is a major financial centre with strict cybersecurity requirements from the Monetary Authority of Singapore (MAS).

Singapore providers serve the broader ASEAN region from a market shaped by MAS TRM guidelines for financial institutions and CSA Cybersecurity Act obligations for critical information infrastructure. Engagements routinely span Singapore, Indonesia, Malaysia, and the Philippines, with providers offering multilingual reporting and regional threat-intelligence context.

Most relevant: ISO 27001 pen testing providers.

12
Providers
7
CREST Accredited
2-3 weeks
Avg Response

Featured Local Specialists

Providers headquartered in Singapore, ranked by overall score. These local firms often bring deeper market context and language coverage than global competitors.

Top Accreditations in Singapore

ISO 2700111CREST7SOC 26FedRAMP 3PAO3PCI QSA2

Editor’s Pick

Top-ranked in Singapore

Horangi Cyber Security

Singapore-headquartered cybersecurity firm acquired by Bitdefender. CREST-accredited pen testing paired with the Warden CSPM platform. MAS TRM, OJK, and PDPA specialism.

CRESTISO 27001
View Profile
12 providers
CREST CertifiedAdversary Simulation
SECFORCE logo

SECFORCE

Canary Wharf-based adversary simulation and CBEST-aligned penetration testing consultancy, delivering CREST-accredited offensive security to UK financial services and other organisations with the most demanding requirements.

London, United KingdomPremium
Web ApplicationNetworkMobile App+10
CRESTCBESTSTAR+3
Verified Jun 2026
Horangi Cyber Security logo

Horangi Cyber Security

Singapore-headquartered cybersecurity firm acquired by Bitdefender. CREST-accredited pen testing paired with the Warden CSPM platform. MAS TRM, OJK, and PDPA specialism.

Singapore
Web ApplicationNetworkMobile App+4
CRESTISO 27001
Verified Jun 2026
Swarmnetics logo

Swarmnetics

Singapore CREST-accredited and CSA-licensed offensive security boutique. Manual, senior-led testing with strong MAS TRM and PDPA expertise.

Singapore
Web ApplicationMobile AppAPI+3
CRESTOSCP Employer
Verified Jun 2026
Aon Cyber Solutions logo

Aon Cyber Solutions

Cybersecurity consulting division of global insurance leader Aon, uniquely combining penetration testing with cyber risk quantification and insurance expertise.

London, United KingdomEnterprise
Web ApplicationNetworkCloud+5
ISO 27001SOC 2
Verified Apr 2026
HackerOne logo

HackerOne

World's largest ethical hacker platform with over one million researchers, offering bug bounties and structured penetration testing to the US DoD and Fortune 500.

San Francisco, California, United StatesPremium
Web ApplicationAPIMobile App+3
SOC 2ISO 27001FedRAMP 3PAO
Verified Apr 2026
IR-Led PentestingGlobal Incident Responders
Kroll logo

Kroll

Global risk advisory firm with a 400+ person cyber practice. IR-led penetration testing that feeds active breach intelligence straight into test scoping.

New York, United StatesEnterprise
Web ApplicationNetworkCloud+9
PCI QSAISO 27001SOC 2
Verified Apr 2026
APT Intelligence LeaderTIBER-EU Specialist
Mandiant logo

Mandiant

World-renowned cybersecurity firm now part of Google Cloud, delivering threat intelligence-led penetration testing and red teaming informed by front-line incident response experience.

Reston, Virginia, United StatesEnterprise
Red TeamingPurple TeamingNetwork+6
SOC 2ISO 27001FedRAMP 3PAO
Verified Apr 2026
SEC Consult logo

SEC Consult

Vienna-headquartered Austrian cybersecurity consultancy with a prolific Vulnerability Lab research program and deep expertise in IoT and embedded systems security across the DACH region.

Vienna, AustriaPremium
Web ApplicationNetworkMobile App+7
ISO 27001
Verified May 2026
Global Defence PlayerANSSI-Qualified
Thales Cyber Solutions logo

Thales Cyber Solutions

Cybersecurity division of the Thales Group, with ANSSI, CREST, FedRAMP 3PAO, and NATO-cleared personnel. Defence, government, and critical infrastructure penetration testing worldwide.

Paris, FranceEnterprise
Web ApplicationNetworkCloud+9
CRESTFedRAMP 3PAOISO 27001+1
Verified Apr 2026
Trustwave logo

Trustwave

Global managed security provider with the elite SpiderLabs penetration testing team and deep PCI DSS compliance expertise.

Chicago, Illinois, United StatesEnterprise
Web ApplicationNetworkMobile App+7
PCI QSAISO 27001SOC 2+1
Verified Apr 2026
WithSecure logo

WithSecure

Helsinki-headquartered Finnish cybersecurity firm with roots dating to 1988, offering CREST-accredited penetration testing and deep expertise in EU regulatory compliance including GDPR, NIS 2, and TIBER-EU.

Helsinki, FinlandEnterprise
Web ApplicationNetworkCloud+7
CRESTISO 27001
Verified May 2026
Wizlynx Group logo

Wizlynx Group

Swiss cybersecurity firm with major Singapore operation. CREST accredited, CSA-licensed in Singapore. Manual exploitation focus with the proprietary MAD reporting platform.

Zurich, Switzerland
Web ApplicationNetworkMobile App+5
CRESTISO 27001
Verified Jun 2026

Penetration Testing in Singapore, FAQs

How do I find a penetration testing provider in Singapore?+

We currently list 12 penetration testing providers serving Singapore. You can filter by service type, accreditation, compliance expertise, and pricing to find the best fit for your requirements. Each provider profile includes verified accreditations, service details, and independent scores based on our transparent methodology.

What accreditations should I look for in Singapore?+

Of the 12 providers listed for Singapore, 7 hold CREST accreditation, the most widely recognised standard for penetration testing quality in the APAC region. Other valuable accreditations include CHECK (for UK government work), ISO 27001, and SOC 2. The right accreditations depend on your industry and regulatory requirements.

How much does penetration testing cost in Singapore?+

Penetration testing costs in Singapore vary significantly based on scope and complexity. A standard web application test typically ranges from $5,000 to $25,000, network penetration tests from $10,000 to $30,000, and comprehensive red team engagements from $30,000 to over $100,000. Key cost factors include the number of targets, required accreditations, testing methodology, and whether on-site presence is needed. See our general pricing guide for more detail.