Cybersecurity · Risk Management · GRC Advisory
A Malaysian consultancy built on a decade of trust — now bringing proactive cybersecurity to the organisations we serve.
TGT CAPITAL SDN BHD · Registration No. 955461-P · Kuala Lumpur, Malaysia
Cybersecurity services
Designed to expose weaknesses, validate controls, and keep your business running. Since 2011, TGT Capital has helped organisations manage risk — now with a dedicated cybersecurity practice.
Security validation, incident prevention, compliance support, and vendor assessment — with evidence, not assumptions.
See how it works ↓Offensive security testing across eight attack surfaces — from web applications to full-scope adversary emulation.
See the eight domains ↓Governance frameworks, maturity assessments, and regulatory readiness — from RMiT to the Cyber Security Act 2024.
See advisory services ↓Core service
We partner with organisations to validate that security controls actually work — with evidence, not assumptions.
Confirm that security controls work — with evidence.
Reduce the likelihood of data breaches and ransomware, and minimise business disruption from cyber threats.
Regulatory alignment and audit readiness across Malaysian and international standards.
Due diligence on third-party security posture across your supply chain.
From the attacker's perspective
Every engagement begins where a real adversary would — at your exposed surface.
Offensive security
Vulnerability Assessment & Penetration Testing across eight attack surfaces.
OWASP-aligned testing across custom and off-the-shelf web apps.
REST, GraphQL, and SOAP endpoint assessment.
OS, patch, and configuration review.
Engine, schema, and privilege assessment.
SAST-driven analysis for logic and injection flaws.
Phishing, vishing, and physical intrusion drills.
iOS & Android, static and dynamic testing.
Full-scope adversary emulation.
Governance, Risk & Compliance
Strategic guidance to build resilient governance frameworks and demonstrate compliance.
RMiT · GTRM · ISO 27001 alignment
Baseline today, benchmark tomorrow
Prepare for Malaysia's new mandate
Prioritised multi-year investment plan
Procedures that teams actually follow
Tabletop exercises · staff awareness
IT Disaster Recovery validation
Vendor and supply-chain assurance
Technology Risk Management Framework
Our people
Certifications held across our cybersecurity practice.
Credentialed practitioners applying vendor-agnostic methodologies to every engagement — regardless of scope or size.
How we work
We align to globally recognised frameworks — not invented-here playbooks.
Our commitment: vendor-agnostic methodology applied consistently to every engagement, regardless of scope or size.
Kuala Lumpur
Headquartered in KL — serving Malaysian organisations since 2011.
Get in touch
Whether you need a cybersecurity assessment, regulatory readiness review, or a full red team engagement — we'd be glad to discuss how we can support you.