These seven firms deliver the mobile application penetration tests, OWASP MASVS reviews, and BNM RMiT-aligned audits required in Malaysia’s 2026 compliance cycle. All maintain active teams in the Klang Valley and can assess Android, iOS, and the backend APIs those apps connect to.
The 2026 audit round is already structured around the Cyber Security Act 2024, which requires National Critical Information Infrastructure (NCII) sectors to hold audited evidence for every internet-facing service, including mobile apps. Below are the working teams, not the generic consultancy brochures, with their actual operating methods and the kind of defects they find in Malaysian production apps.
1. LGMS Berhad
LGMS Berhad is a Bursa Malaysia-listed security firm headquartered in Kelana Jaya, Petaling Jaya. Unlike the global assurance practices, LGMS operates its own ISO/IEC 17025-accredited security testing laboratory, which gives it an edge when a mobile audit result must survive a regulator’s evidence check. Its mobile practice covers black-box penetration testing for Android (APK and AAB builds) and iOS IPA files, plus white-box code review against the OWASP Mobile Application Security Verification Standard (MASVS).
The actual engagement runs concurrently against the backend JSON API endpoints. LGMS engineers test for Broken Object Level Authorization (BOLA), horizontal privilege escalation, and weak token lifecycle management. This is the most common failure in Malaysian e-wallet and logistics apps: the client-side binary is hardened, but the API accepts a device ID as proof of identity. LGMS audits map directly to Cyber Security Act 2024 audit requests, since the firm’s evidence logs are standardized for government submission.
Best for: DuitNow QR-connected financial services, licensed e-money providers, and fintech apps that need a lab-grade audit trail.
2. Nettitude Malaysia
Nettitude is a CREST-registered security firm that runs a global delivery centre in Kuala Lumpur. Its Malaysian team approaches mobile audits as threat-led testing: they begin every assignment with the MITRE ATT&CK for Mobile matrix and build the test plan around the app’s actual transaction flow, not just the default OWASP checklist.
On a typical 2026 engagement, Nettitude tests both platforms, including Flutter-generated binaries, which are now common across Malaysian digital banks. The team performs certificate pinning bypass using Frida and objection, then verifies whether the app actually detects rooting or jailbreaking or silently ignores it. Nettitude also reviews the CI/CD pipeline, especially the signing certificates, exported keys, and secret rotation process, which is where most mobile supply-chain attacks originate this year.
Best for: BNM digital bank licensees, cross-border remittance operators, and companies moving mobile backends into containerized infrastructure.
3. CyberSecurity Malaysia
CyberSecurity Malaysia (CSM) is the government’s dedicated security assurance agency under the Ministry of Digital. Its Cyber Security Assurance division and digital forensics labs in Serdang produce mobile security audit reports that are accepted directly by federal agencies and statutory bodies.
CSM audits two layers: the app binary and the supporting infrastructure. In practice, CSM engineers validate public-facing services against national risk thresholds, then package the report as evidence for the Cyber Security Act 2024 compliance timeline. CSM also handles the forensic side of a failed audit, meaning if an app has already been exploited, CSM can shift from assessment mode to evidence-gathering mode without changing contractors. That dual role is rare among the private firms in this list.
Best for: ministry-linked mobile services, public healthcare apps, and government-linked company dashboards with citizen-facing login flows.
4. KPMG Malaysia
KPMG Malaysia’s Cyber and Resilience practice in the Klang Valley works with banks and insurers that fall under Bank Negara Malaysia (BNM) supervision. Their mobile audits are placed inside larger annual technology risk assessment programs, producing reports structured for board-level governance rather than for simple engineering handover.
The mobile team uses a combined manual and tool-assisted methodology: a static analysis pass with MobSF and commercial scanners, dynamic black-box testing through Burp Suite, and code-level review of encryption libraries and key management mechanisms. In 2026, KPMG’s Kuala Lumpur clients are running these audits on apps for RM-denominated investment products, insurance claims, and corporate cash management. The audit partner signs the report, which is a hard requirement for annual audit committee review at most licensed financial institutions.
Best for: licensed banks, insurance service providers, and stockbroking mobile apps that require a big-four audit partner signature.
5. PwC Malaysia
PwC Malaysia runs its mobile application security practice out of the Cybersecurity, Digital Trust and Data Protection team in Kuala Lumpur. For annual audit cycles, PwC applies a repeatable risk scoring system across both iOS and Android builds, anchored to ISO 27005 aligned criteria.
A standard engagement uses a fixed test plan: binary reconnaissance with apktool and jadx, TLS and HTTP/2 traffic interception through a local proxy, backend API fuzzing with Burp Intruder, and dynamic analysis on rooted emulator images. PwC also reviews every logging statement in the app for Personal Data Protection Act (PDPA) exposure, a legally material issue after the 2024 PDPA amendments expanded breach notification duty. The result is a repeatable table of findings that the same client can re-test annually without re-scoping the contract.
Best for: telecommunications companion apps, government-linked companies, and private healthcare data platforms.
6. BDO Malaysia
BDO Malaysia’s cybersecurity division handles mobile audits with a faster delivery window and a mid-market fee structure. The standard eight-week mobile security audit covers Android, iOS, and the shared backend API, using automated scanning with MobSF and Drozer, manual exploitation, and a remediation report grouped by severity.
The practice is common among fintech startups that need a defensible audit report before entering bank partnership talks or launching a new e-money service. BDO also offers an optional secure-development engagement: it embeds commit-time scanning into GitLab CI and GitHub Actions, and requires verification of Gradle credentials in Android builds and Apple Developer portal key permissions before any release. This protects the startup’s next funding due-diligence check from turning into a full rebuild.
Best for: startup e-money applications, logistics technology companies, and firms exposing both a mobile app and a public API.
7. EY Malaysia
EY Malaysia places mobile audit capability inside its Cybersecurity, Privacy and Digital Trust practice. The team tests what traditional penetration testers often skip: JavaScript bridges inside WebView components, in-app URL scheme handlers, and the configuration of third-party tracker SDKs.
On the 2026 workload, EY’s Kuala Lumpur team prioritises zero-click attack surface on messaging-enabled fintech apps. They also validate session handling when a device switches from LTE to Wi-Fi mid-transaction, a common real-world test that uncovers session fixation defects in Malaysian apps. The EY review maps every embedded SDK, including analytics, chat, and advertising identifiers, to the vendor’s access controls, which is directly useful for vendor risk management requirements under BNM RMiT.
Best for: high-volume consumer e-wallets, e-commerce mobile apps, and any platform using in-app browsers or live chat features.
| # | Firm | Base of Operations | Anchor Service | Best For |
|---|---|---|---|---|
| 1 | LGMS Berhad | Petaling Jaya | OWASP MASVS audit with ISO/IEC 17025 lab evidence | DuitNow QR-linked fintech, e-money providers |
| 2 | Nettitude Malaysia | Kuala Lumpur | MITRE ATT&CK Mobile threat-led pentest, CREST-registered | Digital banks, remittance operators |
| 3 | CyberSecurity Malaysia | Serdang | Government-accepted audit reports, forensic evidence chain | Public-sector mobile services, NCII compliance |
| 4 | KPMG Malaysia | Kuala Lumpur | Board-level annual technology risk audit | Licensed banks, insurers, broking apps |
| 5 | PwC Malaysia | Kuala Lumpur | Fixed-plan binary and API fuzz assessment, PDPA logging review | Telcos, GLCs, health data platforms |
| 6 | BDO Malaysia | Kuala Lumpur | Eight-week full-stack mobile audit plus CI/CD scanning | Fintech startups, logistics tech |
| 7 | EY Malaysia | Kuala Lumpur | WebView bridge, SDK privacy, and session-handover testing | Consumer e-wallets, e-commerce apps |
Ready to Accelerate Your Digital Growth Strategy?
Partner with an industry-leading digital agency to upscale your infrastructure today.








