02
Disc 02 — Signal Locked

Cybersecurity &
Software Testing

AI-powered threat detection, automated VAPT scoping, and intelligent test generation. We find vulnerabilities before attackers do — and prove your software works before users find out it doesn't.

Very High
Market Demand
RM 38-75K
Startup Investment
Very High
Gov't Tender Potential
What We Deliver

Service Categories

NACSA Licensed

As of October 2024, NACSA licensing is mandatory for penetration testing in Malaysia. Penalties: up to RM 500,000 fine, 10 years imprisonment. Parsec operates under full NACSA compliance.

Offensive Security

Penetration Testing (VAPT)

Network, web application, mobile app, and API penetration testing. CREST-aligned methodology with detailed remediation guidance.

Assessment

Security Posture Assessment

Configuration reviews against CIS benchmarks, patch assessment, access control review, and security architecture evaluation.

Compliance

Security Audits & Compliance

ISO 27001, PDPA, Cyber Security Act 2024, Bank Negara RMiT, PCI DSS. Gap analysis through full audit support.

Quality Assurance

Functional Testing

Manual and automated software testing. Test automation frameworks (Selenium, Playwright), API testing (Postman), regression suites.

Performance

Load & Stress Testing

System capacity validation with JMeter/k6. Identify bottlenecks under peak load conditions before production deployment.

GRC

Governance, Risk & Compliance

Security policy development, risk registers, incident response planning, business continuity, and tabletop exercises.

Credentials

Certifications & Standards

CREST CRT
CREST International
Practical, 2.5 hrsNo expiry
Critical — Gov't VAPT
CompTIA Security+
CompTIA
90 questions, 90 min3-year renewal
Foundation
CEH v13
EC-Council
125 MCQ, 4 hrs3-year renewal
Industry Standard
OSCP
Offensive Security
24-hour practicalLifetime
Gold Standard
ISTQB CTFL
MSTB (Malaysia)
40 MCQ, 60 minLifetime
Testing
ISO 27001 Lead Auditor
PECB / IRCA
5-day course3-year renewal
Audit
Regulatory Opportunity

NCII Mandatory Sectors

The Cyber Security Act 2024 mandates VAPT by NACSA-licensed providers across 11 National Critical Information Infrastructure sectors:

01Government
02Banking & Finance
03Transportation
04Defence & National Security
05Information & Digital
06Healthcare Services
07Water & Sewerage
08Energy
09Agriculture & Plantation
10Trade, Industry & Economy
11Science, Tech & Innovation
How We Work

Engagement Process

01

Scoping

Define boundaries, constraints, testing targets. What's in scope, what's off-limits. Rules of engagement established.

02

Documentation

Signed SOW, NDA, written authorization letter, emergency contacts. For VAPT: formal Rules of Engagement before any testing begins.

03

Execution

Follow CREST/OWASP methodology. Daily status updates. Critical findings escalated immediately — no waiting for the final report.

04

Reporting

Executive summary for management, technical findings for IT. Risk ratings, remediation recommendations, evidence documentation.

05

Debrief & Retest

Walkthrough session with client. Verify fixes, update report, close findings. Annual retest contracts for continuous assurance.

Pillar Lead

Your Point of Contact

IZ
Izzudin
Cybersecurity & Testing Lead

Owns the full security lifecycle — from initial scoping through VAPT execution, compliance assessments, and software testing. Building credentials across CREST, CompTIA, and ISTQB certification pathways while delivering real engagements.