We are always watching.
Most IT companies stop at the laptop. We watch the inbox, the network, the people who click things, and the paperwork a regulator will ask for. One team accountable for all of it, since 1998.
Activity reviewed
The peaks are at night. That is the whole argument of this page.
Where the week goes
- Weekdays, 09:00 to 18:004526.8%
- Weeknights7544.6%
- The weekend4828.6%
Illustration of a monitored environment. LANTEK does not sell a dashboard.
Accredited partners
“We’re too small to be a target.”
Attackers do not choose you. Software does. Automated tools scan whole ranges of the internet looking for an open door. They do not know whether you are a law firm in Ballito or a logistics business in Frankfurt.
You are not too small. You are exactly who they are looking for.
A remote desktop or a firewall management page still answering from the open internet. A scanner finds it in seconds, and it is the most common way a small business is first reached.
A mail server still accepting an older sign-in method. The password works, the second factor is never asked for, and nothing looks unusual from the inside.
Reused from somewhere that was breached years ago. Nobody has to guess it. They only have to try it, and the attempt costs them nothing.
Nobody gets breached at 2pm on a Tuesday.
Attacks land on a Friday evening, over a long weekend, on Christmas Eve. Not by coincidence, but because that is when nobody is watching.
A week is 168 hours.
You are open for 45.
Attacks do not keep office hours. The distance between when your business is watched and when it is not is the single biggest reason an incident becomes a disaster. It lands on a Friday evening, and nobody looks until Monday. Seventy three percent of the week, nobody is looking. That is the window, and closing it is what the third layer is for.
Read what one unwatched weekend costIllustration of a monitored environment. LANTEK does not sell a dashboard.
A week is 168 hours. A normal working week, nine in the morning to six in the evening, Monday to Friday, covers 45 of them, which is 27 percent. The remaining 123 hours, including every night and both weekend days, are not covered.
Almost everything you own sits behind one login.
For a business without a security team, the entire digital footprint sits behind one Microsoft 365 identity: email, files, SharePoint, Teams, and the password resets for everything else. An attacker does not need to break your network. They need one person's password to still be working.
Identity is the way in. Not the firewall, not the laptop, not the server in the corner. Which is why watching the login matters more than anything you can install on a machine.
Five questions to ask whoever runs your IT
Fair questions. A good answer arrives immediately.
Who signed in to our Microsoft 365 last week, and from where?
Every sign-in is logged. The question is whether anybody reads them. In most smaller tenants nobody does, which is why a login from another country at three in the morning goes unremarked.
Is multi-factor authentication enforced on every account, including the ones nobody uses any more?
Enforced, not available. The gaps are almost always the dormant account, the shared mailbox and the service account somebody set up years ago, and those are precisely the ones nobody is watching.
Is legacy sign-in switched off, or can somebody still get in and bypass multi-factor entirely?
Older sign-in methods bypass multi-factor completely. If they are still enabled, the protection you think you have can be walked around, and credential-stuffing bots try that route first.
How many people hold global administrator rights, and when was that last reviewed?
Administrator rights accumulate. They are handed out for one job and never taken back, and each one is an account that can change anything. The honest answer is usually more people than anybody expects.
Would we know if somebody created a mailbox rule that quietly forwards our invoices somewhere else?
A forwarding rule is the standard first move once a mailbox is taken, and it survives a password change. Being alerted when one is created is a setting rather than a product.
If the answer to any of those is “I would have to check”, that is the finding.
Your tools are layer one and two.
We are the third.
Almost every business already owns two layers of protection and does not know it. The devices and the people are the first. The security built into the platforms you already pay for is the second. Both are real, and neither one watches itself. The third layer is a team who reads what those first two produce, acts on it at three in the morning, and can show a regulator the evidence afterwards.
What that coversIllustration of a monitored environment. LANTEK does not sell a dashboard.
Defence in depth, in three layers. Your devices and people are the first and never report themselves. The platforms you already pay for are the second, and their alerts go unread. LANTEK is the third layer: it reads what the first two produce and acts on what it finds.
One Friday night, twice.
The same mailbox, the same stolen invoice, the same long weekend. Drag the handle. The only thing different on the right is that somebody was reading what the tools were producing.
The invoice was paid on Friday afternoon. The mailbox rule that hid the replies has been running all weekend. Nobody has opened the alert queue since Friday at five, and the first person to notice is the supplier, asking where their money is.
Found on MondayThe forwarding rule is created and held within the minute. The account is locked, the session is revoked, the supplier is telephoned on a number already on file, and the payment never leaves. There is a written record of all of it by Saturday morning.
Stopped in minutesWhat the third layer actually did that night.
Created on a mailbox by somebody who is not its owner, twelve minutes after the last person left the building.
Held so it can be read later. Deleting it first is how you lose the only evidence of how somebody got in.
The password is changed and every live session on that account is ended, because a password change on its own does not end one.
On a number already on file rather than the one in the email. The payment is stopped before the weekend starts.
What happened, what was done and when, in a form a client, an insurer or the Information Regulator can be handed.
Illustrative scenario, built from attack patterns LANTEK sees in South African businesses. It does not depict a real client.
Everything your business runs on, watched by one team.
Security is not a product bolted on at the end. It is six layers of control, built into your environment from the first day, and one accountable team rather than five suppliers pointing at each other when something goes wrong.
The laptop, desktop or server itself. Patched on a schedule, encrypted, and carrying detection that reports somewhere a human reads.
Who is logging in, from where, and what lands in the inbox. The single most attacked surface in any small business, and the one most often left on defaults.
The edge, the segmentation, and the traffic moving between systems. Built so that one compromised machine does not become every machine.
Training, simulated phishing, and the habits that stop most real attacks before any technology has to. The cheapest control you will ever buy.
Detection and response, around the clock, acting the moment something is found rather than filing it for Monday. Most of what we catch happens while the building is empty. This is the one almost nobody has.
Policies, registers and evidence that prove it was all in place. The part that decides whether an incident becomes a fine.
Seven services sit across these six layers. Take one on its own, or hand over the whole environment. See all seven
We build to a framework, not to a feeling.
The NIST Cybersecurity Framework 2.0 is the structure a regulator, an insurer and a large client all recognise. Six functions. Every control we put in your environment maps to one of them, which is what turns a pile of software into something you can be assessed on.
NIST Cybersecurity Framework 2.0: six functions
Policy and oversight
Security and acceptable use policies, Information Officer support, compliance registers, and data processing agreements with every vendor that touches your data, so accountability is documented rather than assumed.
Know your risk
Asset registers, data classification, quarterly reviewed risk registers, end of life software flagging and data flow mapping. You cannot protect what you cannot see.
Lock it down
Enforced multi-factor authentication, least privilege access, endpoint detection and response on every device, proactive patch management, encryption, email security, DNS filtering, and backup that is routinely tested.
Always watching
Round the clock monitoring, alerting on suspicious activity and ransomware indicators, dark web monitoring, and regular vulnerability scanning.
Act fast
Documented incident response plans, tested containment, evidence preservation, clear client notification service levels, and support for POPIA and Cybercrimes Act reporting. Calm, fast and by the book.
Bounce back
Tested business continuity and disaster recovery, verified backups, rehearsed restores, and lessons that feed back into the plan, because getting back to work is what actually matters.
POPIA and the Cybercrimes Act are not separate projects. Section 19 of POPIA already requires appropriate technical and organisational measures, and the maximum administrative fine is R10 million. The same six functions satisfy both, which is why we build to them once rather than assembling evidence in a panic after somebody asks.
Not sure which of that you already have? The free health check now includes a review of your Microsoft 365 tenant.
Free IT Audit & Health Check What of yours is
already out there?
Company email addresses, passwords and customer data get traded in the places stolen and leaked data ends up. Most businesses have something circulating and no idea it is there. A single reused password from a breach four years ago is still a working key today.
- We scan for your domain, your people and your credentials
- Thirty minutes walking you through what came back, in plain language
- You keep the report whether or not you ever work with us
Illustration of a completed scan
This is not hypothetical.
Four real attack patterns, and exactly how the layers stop them. Four minutes each, no jargon, and no sales pitch at the end.
Accreditation is not decoration.
Each one represents assessments passed, engineers certified and kept current, and a direct line into vendor engineering when something goes wrong at your premises at eleven at night.
Ask any IT provider for their current accreditation list. The length of the answer, and how quickly it arrives, tells you most of what you need to know.
Security is led in house by a CISSP certified security specialist, not subcontracted to whoever answers first. It is the difference between an alert being forwarded to you and an alert being dealt with.
All partner names and logos are the trademarks of their respective owners.
Clients who have stayed a long time.
Appointed IT specialist advisor to the Bid Committees of Dube TradePort Corporation, the KwaZulu-Natal parastatal, from October 2025 to October 2028.
LANTEK ensure that we are able to service our clients and remain competitive. They are extremely proactive, efficient and speak in a language we understand. Our partnership with LANTEK is one of the best business decisions we have made.
Tony B
Director, Activ8 Group
LANTEK IT Solutions is our preferred service provider and has been for the past 15 years. The level of professionalism and calibre of the team is excellent.
Mrs P. Pillay
SA Branch Manager, HYTORC South Africa
We have worked with LANTEK on the infrastructure design, project management and implementation for both our Cato Ridge and Scottburgh facilities. They work in an efficient and professional manner.
Richard Mills
CEO, Hibiscus Hospitals
We were there when a virus was just noise.
We are here now that criminals do their homework.
Twenty eight years trading, through every shift in what an attack looks like.
Ballito in KwaZulu-Natal and Sandton in Gauteng, with nationwide remote support.
100% Black owned. CSD registered, supplier number MAAA0008129.
Every control mapped to one of the six functions, and to POPIA alongside it.
A free IT audit, and a free dark web scan.
Our specialists come to you and go through the network, the computers, the Microsoft 365 tenant, the cybersecurity controls and the backups, then hand you a written report and an action plan. Every audit includes a dark web exposure scan, run against your domain before anybody visits. You keep the findings either way.
Thirty minutes. No obligation, and you keep the report either way.
Worried what a move would cost
It is the single biggest reason businesses stay somewhere they have outgrown. We plan the migration around your working week rather than ours, we help carry the cost of getting across, and you land on a monthly plan sized to what you actually run. Ask us how that works when we speak.
Already have an IT company?
Good. The audit and the scan still cost nothing and the findings are yours. Plenty of the businesses we look after came to us after finding out what their previous provider had never checked.
Before you renew your Microsoft licences
Two things are worth checking first: whether you are paying for licences nobody uses, and whether the tenant they sit in is actually secured. Most businesses are wrong about at least one of them, and renewal is the only day of the year anybody looks.