How do you know your defences actually work?
Most businesses find out the hard way. Penetration testing and vulnerability scanning are the two ways to find out on purpose instead, before somebody else does it for you. Both delivered in house, led by a CISSP certified security specialist.
What is vulnerability scanning?
Vulnerability scanning is an automated, repeated check across your servers, workstations, network devices and internet facing services that identifies known weaknesses. It finds missing security patches, software that is no longer supported by its maker, misconfigured services, default passwords still in place, and ports open to the internet that should not be. Each finding is rated by severity so the dangerous ones get fixed first.
The value of scanning is not the first report. It is the trend. A business that scans continuously can show that its number of high severity findings is falling, which is exactly the evidence an insurer or a large client asks for, and it is impossible to produce retrospectively.
What is penetration testing?
Penetration testing is a controlled, authorised attempt by a specialist to break into your systems the way a real attacker would. Rather than listing weaknesses individually, the tester chains them together to see how far into the business somebody could actually get. The result answers a question a scan cannot: if one person clicks one link on a Tuesday afternoon, what can the attacker reach by Wednesday?
LANTEK scopes each test in writing before it starts, agrees the rules of engagement and a stop condition, and provides a named contact for the duration. Testing is performed by the in house specialist team, not subcontracted.
Which one does a small business need first?
A business that has never done either should start with vulnerability scanning. It is continuous, it is far less disruptive, and it almost always finds enough unpatched and end of life software to keep a team busy for a quarter. Penetration testing is worth its cost once the obvious weaknesses are closed, because a tester who spends the engagement walking through open doors tells you nothing you could not have found with a scan.
The exception is a business that has been asked directly for a penetration test report by a client, an insurer or a tender. In that case the test is the deliverable and the sequence is decided for you.
What does POPIA say about security testing?
POPIA Section 19 requires a business to secure the integrity and confidentiality of personal information using appropriate, reasonable technical and organisational measures, and to identify reasonably foreseeable internal and external risks. It does not name penetration testing as a requirement. It does require you to identify risks, and regular scanning and testing is the ordinary way a business demonstrates that it has done so rather than asserting it.
The practical test a regulator or an insurer applies is whether you can produce evidence. A dated report showing what was found and what was fixed is evidence. A statement that you take security seriously is not.
What is dark web monitoring, and is it the same thing?
Dark web monitoring is a different exercise. It does not test your systems at all. It watches the places where stolen and leaked data is traded and alerts you when your company email addresses, passwords or customer records appear there, usually because they were taken in a breach at some other organisation your staff also had accounts with. It tells you what has already escaped, rather than what could.
The two work together. Scanning and testing find the doors. Dark web monitoring tells you whether somebody already has a key. LANTEK includes dark web monitoring in all three service plans, and the free health check starts with a dark web scan.
When did somebody last try to break into your business on purpose, and write down what they found?
If the answer is never, that is not unusual, and it is not a criticism. It is simply the most common reason a business does not know where it stands.
Before you call
What is the difference between a vulnerability scan and a penetration test?
How often should a business run each one?
Will a penetration test break anything?
Who performs the testing?
What do we actually receive at the end?
A free dark web scan
and thirty minutes.
We scan for your company email addresses, passwords and customer data in the places stolen and leaked data gets traded, then spend thirty minutes walking you through what came back and what it actually means. No pressure, no jargon, no obligation. You keep the report either way.
Worried about what it takes to move?
Changing IT provider is the single biggest reason businesses stay somewhere they have outgrown. We plan the move around your working week, and we help carry the cost of getting across. Ask us how that works when we speak.