Training people, then safely checking whether the training worked.

Technology alone does not stop every attack. Controlled phishing simulations help measure how employees respond to realistic attack scenarios in a safe environment, providing useful insight into organisational risk and highlighting where focused security-awareness training may be required.

In-house expertise

Security specialists who interpret results and connect patterns to awareness training.

Delivery capability

Managed simulation and awareness capability with structured client reporting.

Client outcome

More focused training, measurable improvement and safer behaviour.

What is simulated phishing?

Simulated phishing sends your own team a harmless test email designed to look like a real scam, then measures who clicked, who entered credentials and who reported it. Nothing is installed and no real credentials are captured. The purpose is to find out how your business actually behaves under a realistic attempt, rather than assuming.

Does it not just embarrass people?

It does if it is run badly. LANTEK trains first and tests afterwards, reports results as a team percentage rather than a list of names, and treats a rising report rate as the headline number rather than the click rate. Run as a blame exercise, simulation makes a business less safe, because people stop reporting genuine suspicious email in case they look foolish.

What does the training cover?

Short, scheduled modules covering the attacks that actually reach South African businesses: invoice and banking detail fraud, chief executive impersonation, fake sign in pages, malicious attachments, and the pressure tactics that make all of them work. Modules are aimed at a non technical person and are designed to be completed in a few minutes rather than as an afternoon course.

What number should we be watching?

Two. The click rate, which should fall between rounds, and the report rate, which should rise. The report rate is the more useful of the two, because a business where people confidently forward a suspicious email to somebody who can check it has a working control. A business with a low click rate and a zero report rate simply has staff who delete things quietly.

How does this help with compliance?

POPIA Section 19 requires appropriate and reasonable organisational measures, not only technical ones, and staff awareness is the clearest example of an organisational measure. Dated training records and simulation results are evidence you can produce. A statement that staff are security conscious is not.

Before you call

Which plans include it?
Scheduled awareness training and simulated phishing campaigns are included in the SECURE and SENTINEL plans. They are not part of CORE, and LANTEK does not describe CORE as including them.
How often should campaigns run?
Quarterly suits most businesses. More frequently than that and people begin to recognise the pattern rather than the technique, which measures familiarity with the exercise instead of resilience to a real attack.
What if somebody fails repeatedly?
That is a training need, not a disciplinary matter, and treating it as the latter is the fastest way to destroy the reporting culture the exercise exists to build. Repeated clicks usually indicate a role under time pressure, most often finance or reception, which is also exactly where a real attacker aims.

A free dark web scan
and thirty minutes.

We scan for your company email addresses, passwords and customer data in the places stolen and leaked data gets traded, then spend thirty minutes walking you through what came back and what it actually means. No pressure, no jargon, no obligation. You keep the report either way.

Worried about what it takes to move?

Changing IT provider is the single biggest reason businesses stay somewhere they have outgrown. We plan the move around your working week, and we help carry the cost of getting across. Ask us how that works when we speak.