How do you know your defences actually work?

Most businesses find out the hard way. Penetration testing and vulnerability scanning are the two ways to find out on purpose instead, before somebody else does it for you. Both delivered in house, led by a CISSP certified security specialist.

What is vulnerability scanning?

Vulnerability scanning is an automated, repeated check across your servers, workstations, network devices and internet facing services that identifies known weaknesses. It finds missing security patches, software that is no longer supported by its maker, misconfigured services, default passwords still in place, and ports open to the internet that should not be. Each finding is rated by severity so the dangerous ones get fixed first.

The value of scanning is not the first report. It is the trend. A business that scans continuously can show that its number of high severity findings is falling, which is exactly the evidence an insurer or a large client asks for, and it is impossible to produce retrospectively.

What is penetration testing?

Penetration testing is a controlled, authorised attempt by a specialist to break into your systems the way a real attacker would. Rather than listing weaknesses individually, the tester chains them together to see how far into the business somebody could actually get. The result answers a question a scan cannot: if one person clicks one link on a Tuesday afternoon, what can the attacker reach by Wednesday?

LANTEK scopes each test in writing before it starts, agrees the rules of engagement and a stop condition, and provides a named contact for the duration. Testing is performed by the in house specialist team, not subcontracted.

Which one does a small business need first?

A business that has never done either should start with vulnerability scanning. It is continuous, it is far less disruptive, and it almost always finds enough unpatched and end of life software to keep a team busy for a quarter. Penetration testing is worth its cost once the obvious weaknesses are closed, because a tester who spends the engagement walking through open doors tells you nothing you could not have found with a scan.

The exception is a business that has been asked directly for a penetration test report by a client, an insurer or a tender. In that case the test is the deliverable and the sequence is decided for you.

What does POPIA say about security testing?

POPIA Section 19 requires a business to secure the integrity and confidentiality of personal information using appropriate, reasonable technical and organisational measures, and to identify reasonably foreseeable internal and external risks. It does not name penetration testing as a requirement. It does require you to identify risks, and regular scanning and testing is the ordinary way a business demonstrates that it has done so rather than asserting it.

The practical test a regulator or an insurer applies is whether you can produce evidence. A dated report showing what was found and what was fixed is evidence. A statement that you take security seriously is not.

What is dark web monitoring, and is it the same thing?

Dark web monitoring is a different exercise. It does not test your systems at all. It watches the places where stolen and leaked data is traded and alerts you when your company email addresses, passwords or customer records appear there, usually because they were taken in a breach at some other organisation your staff also had accounts with. It tells you what has already escaped, rather than what could.

The two work together. Scanning and testing find the doors. Dark web monitoring tells you whether somebody already has a key. LANTEK includes dark web monitoring in all three service plans, and the free health check starts with a dark web scan.

When did somebody last try to break into your business on purpose, and write down what they found?

If the answer is never, that is not unusual, and it is not a criticism. It is simply the most common reason a business does not know where it stands.

Before you call

What is the difference between a vulnerability scan and a penetration test?
A vulnerability scan is an automated check that lists known weaknesses across your systems, such as missing patches, unsupported software and exposed services. A penetration test is a person deliberately trying to break in, using those weaknesses in combination the way a real attacker would. The scan tells you which doors are unlocked. The test tells you what somebody can actually reach once they walk through one.
How often should a business run each one?
Vulnerability scanning should run continuously or on a regular schedule, because new weaknesses appear in software every week and a scan from six months ago describes a system that no longer exists. Penetration testing is a point in time exercise and is usually run annually, after a significant infrastructure change, or when a large client or insurer asks for evidence.
Will a penetration test break anything?
A properly scoped penetration test does not disrupt live systems. Scope, timing and rules of engagement are agreed in writing before anything starts, destructive techniques are excluded unless explicitly requested in an isolated environment, and there is a named contact on both sides for the duration. LANTEK agrees a stop condition before the test begins.
Who performs the testing?
Testing is performed in house by LANTEK’s own specialist team, led by a CISSP certified security specialist, rather than being subcontracted to a third party. That matters for two reasons: the findings are explained by the people who found them, and the remediation is handled by a team that already knows your environment.
What do we actually receive at the end?
You receive a written report with an executive summary a non technical director can read, a technical section listing each finding with evidence and a severity rating, and a prioritised remediation plan. LANTEK then walks through it with you. The report is written to be handed to a client, an insurer or an auditor who asks for it.

A free dark web scan
and thirty minutes.

We scan for your company email addresses, passwords and customer data in the places stolen and leaked data gets traded, then spend thirty minutes walking you through what came back and what it actually means. No pressure, no jargon, no obligation. You keep the report either way.

Worried about what it takes to move?

Changing IT provider is the single biggest reason businesses stay somewhere they have outgrown. We plan the move around your working week, and we help carry the cost of getting across. Ask us how that works when we speak.