Somebody tries to break in, on purpose, and writes down how far they got.

LANTEK delivers penetration testing through a combination of in-house security expertise and specialist cybersecurity partners. Testing uses recognised methodologies and professionally managed tooling to identify exploitable weaknesses before attackers find them. Our security team includes certified penetration-testing and threat-hunting capability, ensuring findings are validated, explained and prioritised against real business risk before recommendations are delivered.

In-house expertise

Certified penetration-testing and threat-hunting capability, including eCPPT v2.0 and eCTHP v2.0 credentials.

Delivery capability

Authorised testing delivered through LANTEK, with specialist cybersecurity-partner capability and professionally managed tools.

Client outcome

Validated findings, business-focused priorities and practical remediation recommendations.

What is network penetration testing?

Network penetration testing is a controlled, authorised exercise in which a specialist attempts to break into your systems the way a real attacker would. Rather than listing weaknesses one by one, the tester chains them together to establish how far into the business somebody could actually get. The output is evidence of real exposure, not a theoretical risk register.

What is the difference between an internal and an external penetration test?

An external penetration test attacks from outside your network, targeting the things exposed to the internet: your firewall, your remote access, your websites and any service published to the world. An internal test simulates somebody who is already inside, whether a visitor on the guest network, a compromised laptop or a dishonest employee, and establishes what they could reach from there.

Most businesses assume the external test is the important one. In practice the internal test is usually more alarming, because most networks are flat inside and the first compromised machine can reach everything.

What happens during a penetration test?

A penetration test runs in five stages. Planning and reconnaissance, where the tester gathers information about your infrastructure. Scanning, to identify weak points. Assessment, where each finding is analysed and rated. Controlled exploitation, where the tester actually attempts to use the weaknesses. Then analysis and reporting, which is the part you keep.

Scope, timing and rules of engagement are agreed in writing before anything starts. Destructive techniques are excluded unless you explicitly ask for them in an isolated environment, there is a named contact on both sides for the duration, and a stop condition is agreed before the test begins.

What do you actually receive at the end?

You receive a written report in three parts: an executive summary a non technical director can read and act on, a technical section listing each finding with evidence and a severity rating, and a prioritised remediation plan. LANTEK then walks you through it. The report is written to be handed to a client, an insurer or an auditor who asks for it.

Where testing is repeated, the report also carries trend data, so you can show that your number of high severity findings is falling. That is the evidence a large client actually wants, and it cannot be produced retrospectively.

How often should a business run a penetration test?

A penetration test is a point in time exercise, so most businesses run one annually. A test is also worth running after any significant infrastructure change, after a merger or office move, and whenever a large client, an insurer or a tender asks for evidence. Between tests, continuous vulnerability scanning is what keeps the picture current.

Will a penetration test disrupt our business?

A properly scoped test does not disrupt live systems. The scope is agreed in writing beforehand, testing windows are chosen around your trading hours, and there is a named contact on both sides throughout. Any test that carries genuine risk of disruption is either excluded or run against an isolated copy, and that decision is yours rather than the tester’s.

Before you call

Who performs the testing?
Testing is performed by LANTEK’s own specialist team, led by a CISSP certified security specialist, rather than being subcontracted. That matters because the findings are explained by the people who found them, and remediation is handled by a team that already knows your environment.
Does LANTEK hold CREST accreditation?
No. LANTEK does not claim CREST accreditation. Testing is led in house by a CISSP certified security specialist. If any provider claims an accreditation, ask to see the certificate and check the date on it.
Does POPIA require a penetration test?
No, POPIA does not name penetration testing as a requirement. Section 19 requires you to identify reasonably foreseeable internal and external risks and to verify that your safeguards are effectively implemented. Testing is the ordinary way a business demonstrates it has done that, rather than simply asserting it.
Can we get a report for a tender or an insurer?
Yes. That is one of the two most common reasons businesses ask for a test. The report is written so it can be handed over directly, with an executive summary that answers the question a non technical reviewer is actually asking.

A free dark web scan
and thirty minutes.

We scan for your company email addresses, passwords and customer data in the places stolen and leaked data gets traded, then spend thirty minutes walking you through what came back and what it actually means. No pressure, no jargon, no obligation. You keep the report either way.

Worried about what it takes to move?

Changing IT provider is the single biggest reason businesses stay somewhere they have outgrown. We plan the move around your working week, and we help carry the cost of getting across. Ask us how that works when we speak.