NewsroomContact Us
Our Businesses

Consulting

IT consultancy and governance, risk and compliance services — covering ISO/IEC 27001 readiness, information security audit, penetration testing and security operations.

Services

Advisory delivered by practitioners

Six service lines, contracted individually or as a combined programme, delivered by certified practitioners with operational infrastructure experience.

01

ISO/IEC 27001 readiness and implementation

Gap assessment, management system design, risk assessment and treatment, Statement of Applicability, policy development, internal audit and management review, through to the certification body’s Stage 1 and Stage 2 audits.

Gap assessmentRisk registerSoA & controlsInternal audit
02

Information security audit

Independent audit against a defined framework, covering control effectiveness and evidence review, with findings assigned severity and ownership and a remediation plan scoped to the client’s operational capacity.

Control testingEvidence reviewFindings & CAPA
03

Penetration testing

Scoped and authorised testing of infrastructure, web and API environments, reported for both engineering remediation and executive review. A licensable service under Act 854.

InfrastructureWeb & APIRetest included
04

Security operations

Monitoring, detection and incident response delivered as a managed service. A licensable service under Act 854.

MonitoringDetectionIncident response
05

Governance, risk and compliance advisory

Enterprise risk registers, control mapping across frameworks, third-party risk assessment, board-level reporting and structured audit-readiness programmes.

Enterprise riskControl mappingBoard reporting
06

IT consultancy

Architecture, migration and infrastructure advisory across on-premises, hybrid and data-centre environments, informed by the Group’s own operational experience.

ArchitectureMigrationInfrastructure
Professional standards

Independence in assurance

The practice provides consultancy and readiness services toward ISO/IEC 27001 and does not act as a certification body.

Under ISO/IEC 17021-1, certification is undertaken by an accredited certification body that is independent of the organisation which implemented the management system. Our role is implementation, internal audit and evidence preparation, and support through the certification audit conducted by the client’s appointed body.

Penetration testing and managed security operations are licensable services in Malaysia under the Cyber Security Act 2024. The Group delivers services in these categories in accordance with that framework, and publishes its licence status.

Capability development

Developing client capability

Where an audit identifies a capability gap rather than a technical one, the Group’s academy delivers the corresponding training programme.

Remediation frequently depends on the client’s own technical capacity. Packet Labs Academy provides structured training in information security management, secure operations and internal audit, delivered by the same practitioners who conduct the engagements.

For Malaysian employers, these programmes are intended to be claimable against the HRD Corp levy following Training Provider registration.

Engagements

Discuss an engagement

Certification programmes, audit, penetration testing and security operations, scoped against your compliance and operational requirements.