Dunicot A cybersecurity consultancy and advisory firm.

Region · North America

Penetration testing services across North America

This is the one region where we are physically present. Our Sheridan, Wyoming office shares North American business hours, and Karachi picks up overnight, so work continues while your team is closed rather than pausing until morning.

Overview

Engagements across North America cover SaaS platforms whose buyers demand evidence before signing, financial institutions and fintechs, healthcare and health technology under HIPAA, and the technology suppliers serving all three.

What drives testing here is rarely a regulator alone. It is the enterprise buyer, the auditor and the cyber insurer asking the same question in three different formats, and one engagement has to answer all three.

What drives testing here

Local drivers

SOC 2 and enterprise procurement
Independent testing has become a de facto condition of selling upmarket, and a redacted attestation is what security review actually asks for.
SEC cyber disclosure
Public companies must disclose material incidents and describe their risk management process, which makes an untested control a disclosure problem as well as a security one.
HIPAA and PCI DSS
The Security Rule is deliberately technology-neutral and PCI DSS is not, but both are evidenced by the same testing when the report is written for each.
Canadian supervision
OSFI B-13 sets independent assurance expectations for federally regulated institutions, and Quebec Law 25 attaches real penalties regardless of where the organisation sits.

How engagements are delivered

Delivered from our Sheridan, Wyoming office on North American business hours, with Karachi covering overnight progress. On-site attendance arranged where internal network or workshop scope requires it.

Delivery model

Delivery
From our Sheridan, Wyoming office; Karachi covers overnight
Frameworks
SOC 2, HIPAA, PCI DSS, NIST CSF, OSFI B-13 and Law 25 as applicable
Coverage
United States and Canada, remote nationwide
Deliverables
Technical report, auditor summary and shareable attestation letter

Most requested here

Questions

Do you actually have a US presence?

Yes. Our US office is in Sheridan, Wyoming, and it is the reason North American engagements run on your hours rather than on ours. Our head office remains in Karachi, Pakistan, and both are stated wherever the company is described.

We need something to send enterprise buyers. What do we get?

Three documents. The full technical report for your engineers, an auditor-facing summary with scope, dates, methodology and outcomes, and a redacted attestation letter with no exploitation detail that is written specifically to be sent to customers and prospects under NDA.

Can you cover a US parent and a Canadian subsidiary together?

Yes, and it avoids paying twice for the same findings. The technical work is one engagement; the reporting covers SOC 2 or HIPAA for the parent and OSFI B-13, PIPEDA or Law 25 for the Canadian entity, from the same evidence.

How much does a penetration test cost in North America?

Cost follows scope rather than a North American rate card. Delivery from our Sheridan, Wyoming office means your business hours without US consultancy pricing, which is the practical reason the office exists.

Which is the best penetration testing company in North America?

No single name is honest in a market this size. Ask who performs your test and what they personally hold, whether the firm holds ISO 27001 itself, whether retesting is included, and whether you can review a redacted report before signing.

Do you work directly with our auditor?

Yes, where you want that. Reports are written so your auditor can file them without a walkthrough, and direct questions from the audit firm are answered with your authorisation rather than routed back through your team.

Can you support a cyber insurance application or renewal?

Yes. Insurers ask what was tested, what was found, what was fixed and how the fix was verified. All four are in the report, and the signed retest attestation is usually the document that answers the renewal questionnaire fastest.

Do you test for state privacy laws as well as federal requirements?

The technical work is the same; the framing differs. Reports cover whichever regimes apply to you, which for most organisations now means a federal or sector requirement plus a patchwork of state laws, all evidenced from the same findings rather than from separate engagements.

Penetration testing in North America

Describe the scope and the deadline. Delivery in your working hours, with a fixed quote after scoping.