Dunicot A cybersecurity consultancy and advisory firm.

Locations · Pakistan · United States · Remote

Where engagements are delivered.

On site from Pakistan and the United States. Remote everywhere else, scheduled to your working hours: between the two offices we cover North American, European, Gulf and Asian business days without anyone waiting overnight for an answer.

Countries · 21

Head office, Karachi

Pakistan

An ISO/IEC 27001 certified practice, founded in Karachi, testing for banks, fintechs and software houses across Pakistan.

US office, Sheridan, Wyoming

United States

A US office in Sheridan, Wyoming, SOC 2, PCI DSS, HIPAA and NYDFS-driven testing on US business hours.

Country

Qatar

Testing for Qatari banks, government-adjacent entities and the platforms serving them, under the NIA framework.

Country

UAE & Dubai

Testing for UAE entities under IAS, DESC, CBUAE and the free-zone data protection regimes.

Country

Saudi Arabia

Testing mapped to NCA ECC and the SAMA framework, the two documents that drive most Saudi security spend.

Country

Kuwait

Testing for Kuwaiti banks, government suppliers and the platforms serving them, mapped to CITRA and CBK requirements.

Country

Bahrain

Testing for Bahraini banks, fintechs and cloud-first platforms, aligned to the CBB Rulebook and PDPL.

Country

Oman

Testing for Omani banks, utilities and government suppliers, aligned to OCERT and CBO expectations.

Country

Singapore

Testing for Singapore fintech, SaaS and financial institutions under MAS TRM and the Cybersecurity Act.

Country

Indonesia

Testing for Indonesian banks, payment providers and platforms under POJK 11/2022 and the UU PDP.

Country

Australia

Testing for Australian financial institutions, SaaS platforms and critical infrastructure under CPS 234 and the SOCI Act.

Country

New Zealand

Testing for New Zealand financial institutions, SaaS platforms and public sector suppliers under the Privacy Act 2020 and NZISM.

Country

Canada

Testing for Canadian financial institutions, SaaS platforms and healthcare providers under OSFI B-13 and PIPEDA.

Country

South Africa

Testing for South African banks, insurers and platforms under POPIA, SARB directives and PCI DSS.

Country

Kenya

Testing for Kenyan banks, mobile money operators and fintech platforms under the Data Protection Act and CBK guidance.

Country

Nigeria

Testing for Nigerian banks, fintechs and payment providers under the CBN framework and the NDPA 2023.

Country

Germany

Testing for German banks, industrial operators and SaaS platforms under BSI IT-Grundschutz, KRITIS and NIS2.

Country

Netherlands

Testing for Dutch banks, fintech and SaaS platforms under DNB expectations, TIBER and NIS2.

Country

Ireland

Testing for Irish financial services, SaaS and the EU headquarters of international technology companies.

Country

Switzerland

Testing for Swiss banks, wealth managers and platforms under FINMA Circular 2023/1 and the revised FADP.

Country

United Kingdom

Remote delivery for UK teams, Article 32 evidence, enterprise-buyer attestation, covered from both offices.

Somewhere else entirely?

Remote delivery works in any timezone with a few hours of overlap. Tell us where you are and when you need it.