Find out what an attacker could do, before they do it.
Most businesses test once a year and hope nothing changed. Managed penetration testing runs on a schedule: internal and external testing, findings ranked by business impact, remediation worked to closure, and every fix verified by re-test.
- Test
Real attack technique, on a schedule.
- Fix
Prioritised by business impact, then worked.
- Prove
Closure verified, trend on record.

Why annual testing stopped being enough.
Four ways a test that was passed still fails the business.
Attackers do not wait for your testing window. Between one annual test and the next, your estate gains users, devices, rules, integrations and suppliers, and every one of them can open a path that was not there when the last report was written.
A test once a year
A single snapshot ages badly in an estate that changes every week.
Scans mistaken for tests
A list of vulnerabilities is not proof of what an attacker could reach.
Reports nobody actions
Findings arrive as a PDF, get filed, and the same issues appear next year.
No evidence of closure
Nothing shows what was fixed, when, or whether the fix actually held.
A managed cycle that closes every finding.
The value is not the test. It is the loop: test, understand, fix, verify, and measure whether your exposure is genuinely getting smaller over time.
Scope
Agree networks, locations, exclusions, cadence and rules of engagement in writing.
Deploy
Place the testing capability inside the environment and confirm safe operation.
Test
Run internal and external testing to the agreed depth and schedule.
Report
Findings ranked by business impact, with technical reproduction detail.
Remediate
Fixes prioritised, owned and worked, not left in a document.
Re-test
Confirm each closure and track exposure trend cycle over cycle.
What the service includes.
- Internal network testing
- External perimeter testing
- Credential and privilege testing
- Lateral movement analysis
- Segmentation validation
- Remediation planning
- Verified re-testing
- Executive and technical reporting
Testing on a schedule, not once a year
Tests run monthly, quarterly or to whatever cadence your risk and obligations require, so exposure is measured against the estate you have now rather than the one you had last summer.
Internal testing, from an attacker's position
We test from inside the network, the position an attacker reaches after one phishing click or one stolen credential, and show what could be reached, escalated and taken from there.
External perimeter testing
Internet-facing services, remote access, published applications and exposed administrative interfaces are tested for what an outsider can see, reach and exploit.
Findings ranked by business impact
Every finding is expressed in terms of what it would cost you: which systems, which data, which process stops. Severity is a business judgement first and a technical score second.
Remediation that is owned
Each finding gets an owner, a fix and a date. Where we manage the environment, we do the work. Where someone else does, we give them what they need and track it with you.
Re-testing and trend reporting
Closures are verified by re-test, and the trend across cycles becomes the measure that matters: fewer findings, faster closure, smaller exposure.
Tested where the risk actually sits.
Real incidents rarely start with an exotic exploit. They start with a reused password, a forgotten published service, a flat network or an administrator account that nobody needed to keep.
We test the areas that decide outcomes, then rank what we find by what it would cost your business if it were used against you.
See how this pairs with cyber resilienceOpen any item for what falls in scope, how we test it, what it changes in practice and the evidence you receive.
Internal network and Active Directory
What an attacker could do from inside, after a single compromised device or credential.
- Domain configuration, privilege paths, service accounts, password practice, host hardening and internal service exposure.
- Authenticated and unauthenticated internal testing, privilege escalation attempts and lateral movement mapping.
- The paths that turn one small compromise into a full estate takeover are found and closed.
- Attack path diagrams, privilege escalation findings and a prioritised internal remediation plan.
External perimeter and remote access
Everything reachable from the internet, including the things nobody remembers publishing.
- Public IP ranges, remote access services, published applications, mail and DNS configuration, and administrative interfaces.
- External discovery and enumeration, exploitation attempts against exposed services, and configuration review.
- Forgotten exposure is retired before it becomes the way in, and the perimeter matches what you believe it to be.
- External exposure inventory, exploitable findings and a confirmed closure record.
Credentials and password practice
The single most common route in, and the one most estates underestimate.
- Password strength and reuse, exposed and breached credentials, service account handling and multi-factor coverage gaps.
- Credential testing against agreed targets, breach-data correlation and authentication control review.
- Weak and reused credentials are found before they are used, and multi-factor gaps are closed where they matter most.
- Credential findings summary, multi-factor coverage report and remediation actions taken.
Segmentation and lateral movement
Whether a compromise stays contained, or spreads to everything on the same wire.
- Network segmentation between users, servers, operational systems, guest networks and site-to-site links.
- Controlled movement attempts between segments to test whether boundaries hold in practice.
- Containment is proven rather than assumed, which is what limits damage on the day it matters.
- Segmentation test results, boundary failures identified and the agreed remediation design.
Misconfiguration and hardening
The accumulated small decisions that quietly widen the attack surface over years.
- Default credentials, legacy protocols, unnecessary services, patch state and insecure administrative practice.
- Configuration review paired with exploitation attempts against the weaknesses found.
- Hardening becomes a maintained standard instead of a project that was done once, long ago.
- Hardening findings by host and service, with a re-tested closure status per item.
Cloud and identity services
Where most business systems now live, and where access control decides the outcome.
- Cloud tenant and identity configuration, conditional access, administrative roles, sharing and guest access.
- Configuration assessment against recognised baselines, with access-path testing where permitted.
- Cloud exposure is treated with the same rigour as the network, rather than assumed to be handled by the vendor.
- Tenant configuration findings, privileged role inventory and a remediation record.
Compliance and insurance evidence
Where regular testing is not optional but something you must be able to demonstrate.
- Testing frequency, scope statements, findings, remediation records and retention of reports.
- Testing mapped to the framework in play, whether ISO 27001, SOC 2, PCI DSS or an insurer's requirement.
- The question about penetration testing is answered from evidence already produced on schedule.
- Dated reports, scope statements, remediation logs and re-test confirmations for the required period.
Scope is agreed in writing before any testing begins, including exclusions and testing windows.
Automation for reach, engineers for judgement.
The service runs on an enterprise network penetration testing platform we licence, deploy and operate on your behalf. Automation gives us the reach and repeatability to test the whole estate every cycle. Our engineers do the part automation cannot: decide what actually matters to your business and what to do about it first.
Testing capability inside the network
The internal testing runs from within your environment, so it sees what a real attacker who got a foothold would see, rather than what a scan from outside can guess.
Consistent method, every cycle
The same tested method is applied each time, which makes results comparable cycle over cycle instead of depending on which consultant showed up.
Automated depth, human judgement
Automation performs the exhaustive work at a scale and repeatability no manual test matches. Our engineers interpret, validate and prioritise what it finds.
Non-destructive by default
Techniques are chosen to prove exposure without breaking production. Anything with disruptive potential is agreed in advance or excluded.
Two reports, two audiences
An executive summary in business language, and a technical report with reproduction steps, so the decision and the fix are both supported.
Operated by us, end to end
Scoping, scheduling, execution, interpretation, remediation planning and re-testing are all part of the service. You do not buy tooling or licences.
Is our exposure getting smaller? Answered.
Each cycle produces a plain report: what was found, how severe it is in business terms, what has been fixed, what was verified by re-test and what still needs a decision from you.
- Scope and rules of engagement
- Executive summary report
- Technical findings report
- Prioritised remediation plan
- Re-test confirmation record
- Exposure trend report
- Findings by severity
- Exploitable paths identified
- Remediation completed
- Findings re-tested and closed
- Time to close by severity
- Exposure trend versus last cycle
A monthly subscription, priced by scope and cadence.
Managed penetration testing is proposed on a twelve month agreement, billed monthly in advance and sized by the number of network locations and how often you test, with a one-off onboarding fee covering scoping, deployment and the baseline test. Platform licensing, execution, interpretation and re-testing are part of the service.
Onboarding
Scoping and rules of engagement, deployment inside the environment, and the baseline internal and external test.
Managed service
Scheduled testing to the agreed cadence, findings interpretation, remediation planning, re-testing and reporting.
No hidden fees
Platform licensing, engineer time for analysis and prioritisation, executive and technical reports, and evidence retained for audit.
Built for businesses that must prove their security posture.
- A client, insurer or regulator asks for evidence of regular penetration testing.
- The estate changes often enough that an annual test no longer reflects reality.
- Previous test reports were filed rather than fixed, and nobody can show closure.
Clear boundaries keep the position honest.
We test the networks, systems and cloud services inside the agreed scope. Custom application code review, physical intrusion testing and social engineering against your people are separate exercises we scope on request rather than imply here. Testing does not remove the need for the controls it measures, and findings owned by a third-party vendor depend on that vendor to close.

Governance, risk and compliance run as a managed service.
Recurring technical assessment feeding a governed remediation programme, so control claims were backed by tested evidence rather than intent.
Read the case studyManaged penetration testing, answered.
What is penetration testing, in plain terms?
A controlled attempt to break into your own environment, run the way a real attacker would, so weaknesses are found and fixed before someone else finds them. A vulnerability scan tells you what looks wrong. A penetration test shows what an attacker could actually do with it.
How is this different from the annual test we already buy?
A once-a-year test describes one day in the life of your estate. Your environment changes every week: new users, new devices, new firewall rules, new software. We run testing on a recurring schedule so exposure is measured continuously and fixes are verified, not assumed.
Is it safe to run on a live network?
Yes. Testing is scoped and scheduled with you, uses non-destructive techniques by default, and anything with disruptive potential is agreed in writing beforehand. Most clients run tests during business hours without users noticing.
What gets tested?
Internal network testing looks at what an attacker who already has a foothold could reach: credential exposure, privilege escalation, lateral movement, weak segmentation and misconfiguration. External testing looks at what is reachable from the internet. Both are in scope, with the depth agreed per engagement.
Who reads the report?
You receive two things: an executive summary written for a business audience, with risk ranked by business impact, and a technical report with the reproduction steps and remediation detail your IT team or ours needs to act.
Do you fix what you find?
Where Numata manages the environment, remediation is handled as part of the managed service and re-tested to confirm closure. Where a third party manages it, we provide the detail they need and track closure with you.
Does it satisfy compliance and insurance requirements?
Regular penetration testing is expected by ISO 27001, SOC 2, PCI DSS, POPIA and most cyber-insurance questionnaires. The reports and remediation records are formatted so they can be handed to an assessor, insurer or client as evidence.
How is it priced?
As a monthly subscription on a twelve month agreement, sized by the number of network locations and the testing cadence you choose, with a one-off onboarding fee covering scoping, deployment and the baseline test.
Find out what your network
would give away today.
We scope the test, run it on a schedule, rank what we find by business impact, then fix and verify.
