In a move set to redefine the cybersecurity landscape in Southern Africa, fast-growing Cape Town-based services firm Risk X Group (RXG) has announced the acquisition of South Africa’s Wolfpack Information Risk.
The strategic deal merges RXG’s operational infrastructure with Wolfpack’s deep advisory expertise, creating an integrated security partner capable of covering every dimension of organisational cyber risk.
The acquisition brings together two entities long recognised for their depth of expertise and client-centric approach.
By combining RXG’s 24/7 managed detection and response capabilities with Wolfpack’s reputation in cyber risk advisory, threat intelligence, and security awareness, the group aims to offer a seamless “end-to-end” security partnership.
A Partnership of Impact
Craig Rosewarne, the industry veteran who founded Wolfpack in 2011, joins RXG as Chief Solutions Officer. Rosewarne emphasised that the merger is about amplifying the impact of Wolfpack’s existing work.
“This is about impact, taking everything, Wolfpack has built and amplifying it through a partnership that can protect more organisations, more completely, than either of us could alone,” said Rosewarne.
“The threat to South African businesses is real and growing. We are now better equipped than ever to meet it head-on. For clients, nothing changes overnight.
“They will deal with the same people they always have, with a much wider set of capabilities behind them.”
Bridging the Gap Between Strategy and Defence
The combined entity is designed to address a critical gap in the market: the disconnect between strategic advisory and active defence.
While Wolfpack has built a strong reputation for governance and training across government and private sectors, RXG brings CREST-accredited offensive security and 24/7 managed security operations to the table.
Andrew Dalrymple, CEO of Risk X Group, highlighted the unique market position the merger creates.
“Wolfpack’s advisory strength, our offensive testing, our governance work and our 24/7 operations add up to something the South African market hasn’t seen, one partner that takes a client from risk assessment to active defence, with no handoffs, no gaps and no excuses,” said Dalrymple.
What the Combined Entity Delivers
RXG states that the new group offers “Complete Cyber Confidence.” With the integration of Wolfpack’s offerings, the group now spans the full spectrum of modern cybersecurity requirements.
The expanded service portfolio includes:
-
Governance, Risk & Compliance Advisory: Strategic cyber risk management, board-level reporting, SOC 2 Type 1 and 2, PCI DSS, ISO 27001, ISO 42001, and AI Governance.
-
Threat Intelligence & Executive Advisory: Dark web monitoring, adversary profiling, executive digital risk, and security leadership services.
-
CREST-Accredited Offensive Security: Penetration testing across infrastructure, web applications, APIs, mobile, and OT/IOT environments; red teaming and adversary simulation.
-
24/7 Managed Security Operations: SOC, SIEM, MDR, continuous threat monitoring, incident response, and remediation.
-
Cloud and AI Security: Cloud security posture management, AI governance, and readiness assessments.
-
Security Awareness and Culture: Human risk management, training, and attack simulation programmes.
Dual-Brand Strategy and Client Continuity
For existing clients of both firms, the immediate operational impact will be minimal. The group will operate a dual-brand model where Wolfpack will continue to trade under its name as a Risk X Group company. The same teams will deliver the same services.
According to the announcement, the two brands will be brought closer together over time, guided by client needs rather than a fixed timeline. This approach ensures that clients retain the trusted relationships they have built while gaining access to a broader suite of technical capabilities.

