Skip to content
What we do 01
Service Plans 02 Compliance 03 See it in action 04 About us 05 Our story 06 Clients 07 Accreditations 08 Insights 09 Contact 10 Free IT Audit & Health Check TeamViewer QuickSupport TeamViewer full client
Ballito +27 32 586 0815
info@lantekcomputers.com
Skip to content
Free dark web scan. Thirty minutes, no obligation. Read more

We are always watching.

Most IT companies stop at the laptop. We watch the inbox, the network, the people who click things, and the paperwork a regulator will ask for. One team accountable for all of it, since 1998.

Overview The last 24 hours across a monitored environment.
Estate covered 0% Identity, endpoint, mail and backup
After hours 0 Reviewed, of the last 24 hours
Weekly cover 0 of 168 Nine hours by five days
Restores verified 0 of 14 Volumes, tested rather than assumed

Activity reviewed

The peaks are at night. That is the whole argument of this page.

Where the week goes

45 of 168 covered
  • Weekdays, 09:00 to 18:004526.8%
  • Weeknights7544.6%
  • The weekend4828.6%

Illustration of a monitored environment. LANTEK does not sell a dashboard.

Accredited partners

“We’re too small to be a target.”

Attackers do not choose you. Software does. Automated tools scan whole ranges of the internet looking for an open door. They do not know whether you are a law firm in Ballito or a logistics business in Frankfurt.

You are not too small. You are exactly who they are looking for.

Remote access left open

A remote desktop or a firewall management page still answering from the open internet. A scanner finds it in seconds, and it is the most common way a small business is first reached.

Sign-in that predates multi-factor

A mail server still accepting an older sign-in method. The password works, the second factor is never asked for, and nothing looks unusual from the inside.

A password already in a breach dump

Reused from somewhere that was breached years ago. Nobody has to guess it. They only have to try it, and the attempt costs them nothing.

Nobody gets breached at 2pm on a Tuesday.

Attacks land on a Friday evening, over a long weekend, on Christmas Eve. Not by coincidence, but because that is when nobody is watching.

A week is 168 hours.
You are open for 45.

Attacks do not keep office hours. The distance between when your business is watched and when it is not is the single biggest reason an incident becomes a disaster. It lands on a Friday evening, and nobody looks until Monday. Seventy three percent of the week, nobody is looking. That is the window, and closing it is what the third layer is for.

Read what one unwatched weekend cost

Illustration of a monitored environment. LANTEK does not sell a dashboard.

A week is 168 hours. A normal working week, nine in the morning to six in the evening, Monday to Friday, covers 45 of them, which is 27 percent. The remaining 123 hours, including every night and both weekend days, are not covered.

Where it actually starts

Almost everything you own sits behind one login.

For a business without a security team, the entire digital footprint sits behind one Microsoft 365 identity: email, files, SharePoint, Teams, and the password resets for everything else. An attacker does not need to break your network. They need one person's password to still be working.

The short version

Identity is the way in. Not the firewall, not the laptop, not the server in the corner. Which is why watching the login matters more than anything you can install on a machine.

Five questions to ask whoever runs your IT

Fair questions. A good answer arrives immediately.

Who signed in to our Microsoft 365 last week, and from where?

Every sign-in is logged. The question is whether anybody reads them. In most smaller tenants nobody does, which is why a login from another country at three in the morning goes unremarked.

Is multi-factor authentication enforced on every account, including the ones nobody uses any more?

Enforced, not available. The gaps are almost always the dormant account, the shared mailbox and the service account somebody set up years ago, and those are precisely the ones nobody is watching.

Is legacy sign-in switched off, or can somebody still get in and bypass multi-factor entirely?

Older sign-in methods bypass multi-factor completely. If they are still enabled, the protection you think you have can be walked around, and credential-stuffing bots try that route first.

How many people hold global administrator rights, and when was that last reviewed?

Administrator rights accumulate. They are handed out for one job and never taken back, and each one is an account that can change anything. The honest answer is usually more people than anybody expects.

Would we know if somebody created a mailbox rule that quietly forwards our invoices somewhere else?

A forwarding rule is the standard first move once a mailbox is taken, and it survives a password change. Being alerted when one is created is a setting rather than a product.

If the answer to any of those is “I would have to check”, that is the finding.

Your tools are layer one and two.
We are the third.

Almost every business already owns two layers of protection and does not know it. The devices and the people are the first. The security built into the platforms you already pay for is the second. Both are real, and neither one watches itself. The third layer is a team who reads what those first two produce, acts on it at three in the morning, and can show a regulator the evidence afterwards.

What that covers

Illustration of a monitored environment. LANTEK does not sell a dashboard.

Defence in depth, in three layers. Your devices and people are the first and never report themselves. The platforms you already pay for are the second, and their alerts go unread. LANTEK is the third layer: it reads what the first two produce and acts on what it finds.

One Friday night, twice.

The same mailbox, the same stolen invoice, the same long weekend. Drag the handle. The only thing different on the right is that somebody was reading what the tools were producing.

Nobody watching Third layer on
Monday, 08:10

The invoice was paid on Friday afternoon. The mailbox rule that hid the replies has been running all weekend. Nobody has opened the alert queue since Friday at five, and the first person to notice is the supplier, asking where their money is.

Found on Monday
Friday, 19:04

The forwarding rule is created and held within the minute. The account is locked, the session is revoked, the supplier is telephoned on a number already on file, and the payment never leaves. There is a written record of all of it by Saturday morning.

Stopped in minutes

What the third layer actually did that night.

19:04 A forwarding rule appears

Created on a mailbox by somebody who is not its owner, twelve minutes after the last person left the building.

19:05 The rule is held, not deleted

Held so it can be read later. Deleting it first is how you lose the only evidence of how somebody got in.

19:11 The session is revoked

The password is changed and every live session on that account is ended, because a password change on its own does not end one.

19:40 The supplier is telephoned

On a number already on file rather than the one in the email. The payment is stopped before the weekend starts.

Saturday It is written down

What happened, what was done and when, in a form a client, an insurer or the Information Regulator can be handed.

Illustrative scenario, built from attack patterns LANTEK sees in South African businesses. It does not depict a real client.

Everything your business runs on, watched by one team.

Security is not a product bolted on at the end. It is six layers of control, built into your environment from the first day, and one accountable team rather than five suppliers pointing at each other when something goes wrong.

Device

The laptop, desktop or server itself. Patched on a schedule, encrypted, and carrying detection that reports somewhere a human reads.

Identity and email

Who is logging in, from where, and what lands in the inbox. The single most attacked surface in any small business, and the one most often left on defaults.

Network

The edge, the segmentation, and the traffic moving between systems. Built so that one compromised machine does not become every machine.

People

Training, simulated phishing, and the habits that stop most real attacks before any technology has to. The cheapest control you will ever buy.

Someone watching

Detection and response, around the clock, acting the moment something is found rather than filing it for Monday. Most of what we catch happens while the building is empty. This is the one almost nobody has.

The paperwork

Policies, registers and evidence that prove it was all in place. The part that decides whether an incident becomes a fine.

Seven services sit across these six layers. Take one on its own, or hand over the whole environment. See all seven

We build to a framework, not to a feeling.

The NIST Cybersecurity Framework 2.0 is the structure a regulator, an insurer and a large client all recognise. Six functions. Every control we put in your environment maps to one of them, which is what turns a pile of software into something you can be assessed on.

The six functions of the NIST Cybersecurity Framework 2.0 Govern sits at the centre. Identify, Protect, Detect, Respond and Recover form a ring around it. The table beside this diagram gives the full detail in text. Identify Protect Detect Respond Recover

NIST Cybersecurity Framework 2.0: six functions

GOVERN

Policy and oversight

Security and acceptable use policies, Information Officer support, compliance registers, and data processing agreements with every vendor that touches your data, so accountability is documented rather than assumed.

IDENTIFY

Know your risk

Asset registers, data classification, quarterly reviewed risk registers, end of life software flagging and data flow mapping. You cannot protect what you cannot see.

PROTECT

Lock it down

Enforced multi-factor authentication, least privilege access, endpoint detection and response on every device, proactive patch management, encryption, email security, DNS filtering, and backup that is routinely tested.

DETECT

Always watching

Round the clock monitoring, alerting on suspicious activity and ransomware indicators, dark web monitoring, and regular vulnerability scanning.

RESPOND

Act fast

Documented incident response plans, tested containment, evidence preservation, clear client notification service levels, and support for POPIA and Cybercrimes Act reporting. Calm, fast and by the book.

RECOVER

Bounce back

Tested business continuity and disaster recovery, verified backups, rehearsed restores, and lessons that feed back into the plan, because getting back to work is what actually matters.

Also in scope

POPIA and the Cybercrimes Act are not separate projects. Section 19 of POPIA already requires appropriate technical and organisational measures, and the maximum administrative fine is R10 million. The same six functions satisfy both, which is why we build to them once rather than assembling evidence in a panic after somebody asks.

Not sure which of that you already have? The free health check now includes a review of your Microsoft 365 tenant.

Free IT Audit & Health Check

What of yours is
already out there?

Company email addresses, passwords and customer data get traded in the places stolen and leaked data ends up. Most businesses have something circulating and no idea it is there. A single reused password from a breach four years ago is still a working key today.

  • We scan for your domain, your people and your credentials
  • Thirty minutes walking you through what came back, in plain language
  • You keep the report whether or not you ever work with us
Run my free dark web scan
lantek / exposure scan
> lantek scan --domain yourcompany.co.za
initialising ok
breach corpora 2,410 sources
paste and market listings indexed
 
scanning company email addresses done
scanning credential pairs done
scanning customer records done
 
FOUND 4 addresses across 2 breach sets
FOUND 1 password still in active use
FOUND 2 addresses on a market listing
 
> report ready. 30 minutes to walk you through it.

Illustration of a completed scan

Accreditation is not decoration.

Each one represents assessments passed, engineers certified and kept current, and a direct line into vendor engineering when something goes wrong at your premises at eleven at night.

Ask any IT provider for their current accreditation list. The length of the answer, and how quickly it arrives, tells you most of what you need to know.

MicrosoftSolutions Partner
FortinetAuthorized Partner
ESETGold Partner
AcronisGold Service Provider
VeeamAuthorized Reseller
Dell TechnologiesAuthorized Partner
Lenovo 360Authorized Partner
HPET2 Solution Provider
CiscoRegistered Partner
The controls we run
Endpoint detection and response
Round the clock monitoring
Email security and impersonation control
Multi-factor and conditional access
DNS and web filtering
Immutable, tested backup
Vulnerability scanning
Penetration testing
Simulated phishing
Dark web monitoring
Patch orchestration
Network segmentation
In house

Security is led in house by a CISSP certified security specialist, not subcontracted to whoever answers first. It is the difference between an alert being forwarded to you and an alert being dealt with.

All partner names and logos are the trademarks of their respective owners.

Clients who have stayed a long time.

Public sector appointment

Appointed IT specialist advisor to the Bid Committees of Dube TradePort Corporation, the KwaZulu-Natal parastatal, from October 2025 to October 2028.

LANTEK ensure that we are able to service our clients and remain competitive. They are extremely proactive, efficient and speak in a language we understand. Our partnership with LANTEK is one of the best business decisions we have made.

Tony B

Director, Activ8 Group

LANTEK IT Solutions is our preferred service provider and has been for the past 15 years. The level of professionalism and calibre of the team is excellent.

Mrs P. Pillay

SA Branch Manager, HYTORC South Africa

We have worked with LANTEK on the infrastructure design, project management and implementation for both our Cato Ridge and Scottburgh facilities. They work in an efficient and professional manner.

Richard Mills

CEO, Hibiscus Hospitals

Businesses we look after
Hibiscus Hospitals
Dube TradePort

We were there when a virus was just noise.

We are here now that criminals do their homework.

1998

Twenty eight years trading, through every shift in what an attack looks like.

Two offices

Ballito in KwaZulu-Natal and Sandton in Gauteng, with nationwide remote support.

B-BBEE Level 1

100% Black owned. CSD registered, supplier number MAAA0008129.

NIST CSF 2.0

Every control mapped to one of the six functions, and to POPIA alongside it.

A free IT audit, and a free dark web scan.

Our specialists come to you and go through the network, the computers, the Microsoft 365 tenant, the cybersecurity controls and the backups, then hand you a written report and an action plan. Every audit includes a dark web exposure scan, run against your domain before anybody visits. You keep the findings either way.

Thirty minutes. No obligation, and you keep the report either way.

Worried what a move would cost

It is the single biggest reason businesses stay somewhere they have outgrown. We plan the migration around your working week rather than ours, we help carry the cost of getting across, and you land on a monthly plan sized to what you actually run. Ask us how that works when we speak.

Already have an IT company?

Good. The audit and the scan still cost nothing and the findings are yours. Plenty of the businesses we look after came to us after finding out what their previous provider had never checked.

Before you renew your Microsoft licences

Two things are worth checking first: whether you are paying for licences nobody uses, and whether the tenant they sit in is actually secured. Most businesses are wrong about at least one of them, and renewal is the only day of the year anybody looks.