Managed Penetration Testing Services

Find out what an attacker could do, before they do it.

Most businesses test once a year and hope nothing changed. Managed penetration testing runs on a schedule: internal and external testing, findings ranked by business impact, remediation worked to closure, and every fix verified by re-test.

  • Test

    Real attack technique, on a schedule.

  • Fix

    Prioritised by business impact, then worked.

  • Prove

    Closure verified, trend on record.

A Numata specialist reviewing test findings in an office.

Why annual testing stopped being enough.

The problem
Where it goes wrong

Four ways a test that was passed still fails the business.

Attackers do not wait for your testing window. Between one annual test and the next, your estate gains users, devices, rules, integrations and suppliers, and every one of them can open a path that was not there when the last report was written.

  • A test once a year

    A single snapshot ages badly in an estate that changes every week.

  • Scans mistaken for tests

    A list of vulnerabilities is not proof of what an attacker could reach.

  • Reports nobody actions

    Findings arrive as a PDF, get filed, and the same issues appear next year.

  • No evidence of closure

    Nothing shows what was fixed, when, or whether the fix actually held.

The cycle

A managed cycle that closes every finding.

The value is not the test. It is the loop: test, understand, fix, verify, and measure whether your exposure is genuinely getting smaller over time.

  1. Scope

    Agree networks, locations, exclusions, cadence and rules of engagement in writing.

  2. Deploy

    Place the testing capability inside the environment and confirm safe operation.

  3. Test

    Run internal and external testing to the agreed depth and schedule.

  4. Report

    Findings ranked by business impact, with technical reproduction detail.

  5. Remediate

    Fixes prioritised, owned and worked, not left in a document.

  6. Re-test

    Confirm each closure and track exposure trend cycle over cycle.

What Numata manages

What the service includes.

  • Internal network testing
  • External perimeter testing
  • Credential and privilege testing
  • Lateral movement analysis
  • Segmentation validation
  • Remediation planning
  • Verified re-testing
  • Executive and technical reporting
  • Testing on a schedule, not once a year

    Tests run monthly, quarterly or to whatever cadence your risk and obligations require, so exposure is measured against the estate you have now rather than the one you had last summer.

  • Internal testing, from an attacker's position

    We test from inside the network, the position an attacker reaches after one phishing click or one stolen credential, and show what could be reached, escalated and taken from there.

  • External perimeter testing

    Internet-facing services, remote access, published applications and exposed administrative interfaces are tested for what an outsider can see, reach and exploit.

  • Findings ranked by business impact

    Every finding is expressed in terms of what it would cost you: which systems, which data, which process stops. Severity is a business judgement first and a technical score second.

  • Remediation that is owned

    Each finding gets an owner, a fix and a date. Where we manage the environment, we do the work. Where someone else does, we give them what they need and track it with you.

  • Re-testing and trend reporting

    Closures are verified by re-test, and the trend across cycles becomes the measure that matters: fewer findings, faster closure, smaller exposure.

Areas covered by testing

Tested where the risk actually sits.

Real incidents rarely start with an exotic exploit. They start with a reused password, a forgotten published service, a flat network or an administrator account that nobody needed to keep.

We test the areas that decide outcomes, then rank what we find by what it would cost your business if it were used against you.

See how this pairs with cyber resilience

Open any item for what falls in scope, how we test it, what it changes in practice and the evidence you receive.

  • Internal network and Active Directory

    What an attacker could do from inside, after a single compromised device or credential.

    Scope
    Domain configuration, privilege paths, service accounts, password practice, host hardening and internal service exposure.
    Method
    Authenticated and unauthenticated internal testing, privilege escalation attempts and lateral movement mapping.
    What changes
    The paths that turn one small compromise into a full estate takeover are found and closed.
    Evidence
    Attack path diagrams, privilege escalation findings and a prioritised internal remediation plan.
  • External perimeter and remote access

    Everything reachable from the internet, including the things nobody remembers publishing.

    Scope
    Public IP ranges, remote access services, published applications, mail and DNS configuration, and administrative interfaces.
    Method
    External discovery and enumeration, exploitation attempts against exposed services, and configuration review.
    What changes
    Forgotten exposure is retired before it becomes the way in, and the perimeter matches what you believe it to be.
    Evidence
    External exposure inventory, exploitable findings and a confirmed closure record.
  • Credentials and password practice

    The single most common route in, and the one most estates underestimate.

    Scope
    Password strength and reuse, exposed and breached credentials, service account handling and multi-factor coverage gaps.
    Method
    Credential testing against agreed targets, breach-data correlation and authentication control review.
    What changes
    Weak and reused credentials are found before they are used, and multi-factor gaps are closed where they matter most.
    Evidence
    Credential findings summary, multi-factor coverage report and remediation actions taken.
  • Segmentation and lateral movement

    Whether a compromise stays contained, or spreads to everything on the same wire.

    Scope
    Network segmentation between users, servers, operational systems, guest networks and site-to-site links.
    Method
    Controlled movement attempts between segments to test whether boundaries hold in practice.
    What changes
    Containment is proven rather than assumed, which is what limits damage on the day it matters.
    Evidence
    Segmentation test results, boundary failures identified and the agreed remediation design.
  • Misconfiguration and hardening

    The accumulated small decisions that quietly widen the attack surface over years.

    Scope
    Default credentials, legacy protocols, unnecessary services, patch state and insecure administrative practice.
    Method
    Configuration review paired with exploitation attempts against the weaknesses found.
    What changes
    Hardening becomes a maintained standard instead of a project that was done once, long ago.
    Evidence
    Hardening findings by host and service, with a re-tested closure status per item.
  • Cloud and identity services

    Where most business systems now live, and where access control decides the outcome.

    Scope
    Cloud tenant and identity configuration, conditional access, administrative roles, sharing and guest access.
    Method
    Configuration assessment against recognised baselines, with access-path testing where permitted.
    What changes
    Cloud exposure is treated with the same rigour as the network, rather than assumed to be handled by the vendor.
    Evidence
    Tenant configuration findings, privileged role inventory and a remediation record.
  • Compliance and insurance evidence

    Where regular testing is not optional but something you must be able to demonstrate.

    Scope
    Testing frequency, scope statements, findings, remediation records and retention of reports.
    Method
    Testing mapped to the framework in play, whether ISO 27001, SOC 2, PCI DSS or an insurer's requirement.
    What changes
    The question about penetration testing is answered from evidence already produced on schedule.
    Evidence
    Dated reports, scope statements, remediation logs and re-test confirmations for the required period.

Scope is agreed in writing before any testing begins, including exclusions and testing windows.

The platform

Automation for reach, engineers for judgement.

The service runs on an enterprise network penetration testing platform we licence, deploy and operate on your behalf. Automation gives us the reach and repeatability to test the whole estate every cycle. Our engineers do the part automation cannot: decide what actually matters to your business and what to do about it first.

  • Testing capability inside the network

    The internal testing runs from within your environment, so it sees what a real attacker who got a foothold would see, rather than what a scan from outside can guess.

  • Consistent method, every cycle

    The same tested method is applied each time, which makes results comparable cycle over cycle instead of depending on which consultant showed up.

  • Automated depth, human judgement

    Automation performs the exhaustive work at a scale and repeatability no manual test matches. Our engineers interpret, validate and prioritise what it finds.

  • Non-destructive by default

    Techniques are chosen to prove exposure without breaking production. Anything with disruptive potential is agreed in advance or excluded.

  • Two reports, two audiences

    An executive summary in business language, and a technical report with reproduction steps, so the decision and the fix are both supported.

  • Operated by us, end to end

    Scoping, scheduling, execution, interpretation, remediation planning and re-testing are all part of the service. You do not buy tooling or licences.

Reporting

Is our exposure getting smaller? Answered.

Each cycle produces a plain report: what was found, how severe it is in business terms, what has been fixed, what was verified by re-test and what still needs a decision from you.

Standard documentation set
  • Scope and rules of engagement
  • Executive summary report
  • Technical findings report
  • Prioritised remediation plan
  • Re-test confirmation record
  • Exposure trend report
What we report on
  1. 01Findings by severity
  2. 02Exploitable paths identified
  3. 03Remediation completed
  4. 04Findings re-tested and closed
  5. 05Time to close by severity
  6. 06Exposure trend versus last cycle
Commercial model

A monthly subscription, priced by scope and cadence.

Managed penetration testing is proposed on a twelve month agreement, billed monthly in advance and sized by the number of network locations and how often you test, with a one-off onboarding fee covering scoping, deployment and the baseline test. Platform licensing, execution, interpretation and re-testing are part of the service.

  • One-off

    Onboarding

    Scoping and rules of engagement, deployment inside the environment, and the baseline internal and external test.

  • Monthly

    Managed service

    Scheduled testing to the agreed cadence, findings interpretation, remediation planning, re-testing and reporting.

  • Included

    No hidden fees

    Platform licensing, engineer time for analysis and prioritisation, executive and technical reports, and evidence retained for audit.

Fit

Built for businesses that must prove their security posture.

  • A client, insurer or regulator asks for evidence of regular penetration testing.
  • The estate changes often enough that an annual test no longer reflects reality.
  • Previous test reports were filed rather than fixed, and nobody can show closure.
Boundaries

Clear boundaries keep the position honest.

We test the networks, systems and cloud services inside the agreed scope. Custom application code review, physical intrusion testing and social engineering against your people are separate exercises we scope on request rather than imply here. Testing does not remove the need for the controls it measures, and findings owned by a third-party vendor depend on that vendor to close.

Proof

Testing that turned into fixes, then into evidence.

Security engineer reviewing penetration test findings and remediation status
Case study
Case study · Governance and cyber

Governance, risk and compliance run as a managed service.

Recurring technical assessment feeding a governed remediation programme, so control claims were backed by tested evidence rather than intent.

Read the case study
FAQs

Managed penetration testing, answered.

What is penetration testing, in plain terms?

A controlled attempt to break into your own environment, run the way a real attacker would, so weaknesses are found and fixed before someone else finds them. A vulnerability scan tells you what looks wrong. A penetration test shows what an attacker could actually do with it.

How is this different from the annual test we already buy?

A once-a-year test describes one day in the life of your estate. Your environment changes every week: new users, new devices, new firewall rules, new software. We run testing on a recurring schedule so exposure is measured continuously and fixes are verified, not assumed.

Is it safe to run on a live network?

Yes. Testing is scoped and scheduled with you, uses non-destructive techniques by default, and anything with disruptive potential is agreed in writing beforehand. Most clients run tests during business hours without users noticing.

What gets tested?

Internal network testing looks at what an attacker who already has a foothold could reach: credential exposure, privilege escalation, lateral movement, weak segmentation and misconfiguration. External testing looks at what is reachable from the internet. Both are in scope, with the depth agreed per engagement.

Who reads the report?

You receive two things: an executive summary written for a business audience, with risk ranked by business impact, and a technical report with the reproduction steps and remediation detail your IT team or ours needs to act.

Do you fix what you find?

Where Numata manages the environment, remediation is handled as part of the managed service and re-tested to confirm closure. Where a third party manages it, we provide the detail they need and track closure with you.

Does it satisfy compliance and insurance requirements?

Regular penetration testing is expected by ISO 27001, SOC 2, PCI DSS, POPIA and most cyber-insurance questionnaires. The reports and remediation records are formatted so they can be handed to an assessor, insurer or client as evidence.

How is it priced?

As a monthly subscription on a twelve month agreement, sized by the number of network locations and the testing cadence you choose, with a one-off onboarding fee covering scoping, deployment and the baseline test.

Find out what your network
would give away today.

We scope the test, run it on a schedule, rank what we find by business impact, then fix and verify.