Hozit Domain Hosting — Smart technology. Powerful results.010 502 2517 · info@hozit.co.za · 24/7 Support
Level 1 B-BBEE100% Black Owned24/7 SupportSouth African Technology Partner
Identify Security Weaknesses Before Attackers Do

Test your systems, applications and networks for exploitable security weaknesses

Hozit provides authorised penetration testing and vulnerability assessment services for websites, applications, networks, cloud platforms, servers, wireless environments and business systems.

Service Overview

Professional IT support for growing and established organisations

Vulnerability assessments identify known weaknesses, while penetration testing validates whether selected weaknesses can be exploited in a controlled and authorised manner.

These services help organisations understand real-world exposure across internet-facing systems, internal networks, applications, cloud platforms and user-access controls.

Hozit follows a structured engagement process covering scope approval, rules of engagement, testing, evidence collection, risk classification, reporting and remediation support.

Testing is conducted only against assets explicitly authorised by the customer.

The outcome is a practical security report that helps technical teams and management prioritise corrective action.

Business Challenges

Common IT problems we help solve

Unknown internet exposure

Public systems may expose services, software versions or weak configurations.

Unpatched vulnerabilities

Servers and applications may contain exploitable known weaknesses.

Weak authentication

Poor password controls or missing MFA can increase account-compromise risk.

Application flaws

Websites and APIs may contain injection, access-control or session weaknesses.

Cloud misconfiguration

Storage, identity and network settings may unintentionally expose systems or data.

Internal lateral movement

A compromised endpoint may allow access to additional systems.

Excessive privileges

Users and service accounts may have more access than required.

Insecure wireless networks

Weak segmentation or authentication may expose internal resources.

Incomplete remediation

Previous findings may remain unresolved or only partially fixed.

Compliance pressure

Customers, auditors and tenders may require independent security testing evidence.

What Is Included

Comprehensive managed IT support services

The final scope is tailored to the organisation's users, systems, locations, risks and internal capabilities.

Engagement scoping

Define authorised targets, test types, exclusions, dates and business constraints.

Rules of engagement

Document testing boundaries, communication channels and escalation procedures.

Asset discovery

Identify approved hosts, domains, applications, services and exposed technologies.

External vulnerability assessment

Assess internet-facing systems for known weaknesses and misconfiguration.

Internal vulnerability assessment

Assess authorised internal networks, servers and endpoints.

External network penetration testing

Validate selected weaknesses affecting public-facing infrastructure.

Internal network penetration testing

Assess lateral movement, privilege escalation and internal exposure.

Web application penetration testing

Test authorised web applications for exploitable security weaknesses.

API security testing

Assess authentication, authorisation, input handling and business logic in APIs.

Mobile application security review

Assess selected Android and iOS application security controls.

Cloud security assessment

Review selected AWS, Azure and Microsoft 365 security configurations.

Server security assessment

Assess operating-system, service, patching and configuration weaknesses.

Firewall security review

Evaluate selected firewall exposure, rules and service access.

Wireless security assessment

Assess authorised corporate and guest wireless environments.

Active Directory security assessment

Review identity, privilege, delegation and domain security weaknesses.

Microsoft 365 security assessment

Assess identity, MFA, sharing, email and administrative controls.

Email security assessment

Review SPF, DKIM, DMARC, phishing exposure and mail-security controls.

Remote-access assessment

Assess VPN, RDP, SSH and remote-support exposure.

Authentication testing

Evaluate password, lockout, MFA and session controls.

Authorisation testing

Assess whether users can access data or functions beyond their permissions.

Input-validation testing

Test selected inputs for injection and unsafe processing weaknesses.

SQL injection testing

Assess authorised applications for database injection weaknesses.

Cross-site scripting testing

Assess reflected, stored and DOM-based XSS risks.

Cross-site request forgery testing

Evaluate whether sensitive actions can be triggered without proper validation.

File-upload security testing

Assess file type, storage, execution and validation controls.

Session-management testing

Review cookies, token handling, expiration and session invalidation.

Business-logic testing

Assess workflows for abuse, bypass or unauthorised outcomes.

Access-control testing

Evaluate horizontal and vertical privilege weaknesses.

Security-header review

Assess browser security headers and related web protections.

TLS and certificate assessment

Review encryption protocols, certificates and exposed cryptographic weaknesses.

Port and service assessment

Identify unnecessary or risky network services.

Patch-level assessment

Identify known vulnerabilities associated with outdated software.

Configuration review

Evaluate selected systems against secure configuration practices.

Default credential testing

Check authorised systems for default or weak credentials.

Password policy assessment

Review password requirements and exposure to common attacks.

Privilege-escalation testing

Assess whether limited access can be elevated.

Lateral-movement testing

Evaluate whether compromise of one system can lead to others.

Network segmentation testing

Verify whether security zones effectively restrict access.

Sensitive-data exposure testing

Identify unprotected data in authorised systems or responses.

Information-disclosure testing

Identify verbose errors, exposed backups, metadata and internal details.

Subdomain assessment

Review approved subdomains for takeover risks, abandoned services and exposure.

DNS security review

Assess selected DNS records, mail authentication and configuration weaknesses.

Cloud storage exposure review

Identify publicly accessible or weakly controlled storage resources.

IAM assessment

Review selected cloud identities, roles, permissions and trust relationships.

Container security assessment

Assess selected container images, registries and runtime configurations.

Virtualisation security assessment

Review selected VMware and Hyper-V security configurations.

Database security assessment

Assess selected database access, exposure and configuration weaknesses.

Backup security assessment

Review backup access, encryption, immutability and ransomware resilience.

Endpoint security validation

Assess selected endpoint protection, hardening and local privilege risks.

Phishing simulation

Conduct authorised awareness testing under an approved scenario.

Social engineering assessment

Perform explicitly authorised human-layer testing within agreed boundaries.

Credential exposure review

Assess whether organisational credentials appear in approved exposure sources.

Dark-web exposure review

Check approved indicators for known credential or data exposure.

Vulnerability validation

Confirm whether high-priority scanner findings are genuine and exploitable.

Exploitability assessment

Evaluate practical likelihood and impact without causing unnecessary disruption.

Safe proof of concept

Provide controlled evidence of selected weaknesses.

Risk rating

Classify findings according to severity, likelihood and business impact.

CVSS scoring

Apply recognised scoring where appropriate.

Executive summary

Explain key risks and priorities for management.

Technical findings report

Provide affected assets, evidence, impact and remediation steps.

Remediation workshop

Review findings with technical teams and agree corrective actions.

Remediation roadmap

Prioritise fixes according to severity and operational dependency.

Retesting

Verify whether agreed vulnerabilities have been corrected.

Closure report

Document retest outcomes and remaining risks.

Continuous vulnerability management

Provide scheduled scanning, review and remediation support.

Compliance support

Provide selected testing evidence for audits, tenders and customer assurance.

POPIA security support

Identify technical weaknesses affecting personal-information protection.

ISO 27001 technical testing support

Provide selected security testing evidence for information-security controls.

PCI DSS testing support

Support selected vulnerability and penetration-testing requirements.

Business Benefits

Why organisations choose managed IT support

Realistic security insight

Controlled testing shows which weaknesses may be practically exploitable.

Prioritised remediation

Risk ratings help teams focus on the most important issues first.

Reduced attack surface

Exposure, unnecessary services and weak configurations can be corrected.

Improved application security

Web and API flaws are identified before they are abused.

Stronger compliance readiness

Testing evidence supports selected audit and assurance requirements.

Better management visibility

Executive reporting explains risk in business terms.

Verified fixes

Retesting confirms whether corrective actions are effective.

Continuous improvement

Recurring assessments support an ongoing vulnerability-management programme.

Our Methodology

From discovery to ongoing improvement

1

Authorise scope

Confirm target assets, exclusions, testing windows and responsible contacts.

2

Define rules of engagement

Agree testing methods, safety controls and escalation procedures.

3

Discover assets and exposure

Identify approved systems, services, applications and technologies.

4

Assess vulnerabilities

Use manual and automated techniques to identify weaknesses.

5

Validate exploitability

Safely confirm selected findings within approved limits.

6

Analyse risk

Evaluate severity, likelihood, affected data and business impact.

7

Prepare findings

Document evidence, affected assets and recommended remediation.

8

Present results

Review executive and technical findings with relevant stakeholders.

9

Support remediation

Assist technical teams with prioritisation and corrective actions.

10

Retest and close

Confirm fixes and document remaining risk.

Engagement Options

Flexible IT support models

External penetration test

Assess approved internet-facing infrastructure and services.

Internal penetration test

Assess authorised internal networks, identity and lateral-movement risks.

Web application penetration test

Test websites and portals for application-layer weaknesses.

API penetration test

Assess authorised APIs for authentication, access and input-handling flaws.

Cloud security assessment

Review selected AWS, Azure and Microsoft 365 environments.

Wireless security assessment

Assess approved corporate and guest wireless networks.

Vulnerability assessment

Identify and prioritise known technical weaknesses.

Continuous testing programme

Provide scheduled assessments, remediation reviews and retesting.

Technology Coverage

Platforms and technologies we support

Support is subject to the agreed scope, vendor requirements, licences and available technical documentation.

Web Applications REST APIs GraphQL Mobile Applications Windows Server Linux Active Directory Microsoft 365 Microsoft Entra ID AWS Microsoft Azure VMware Hyper-V Firewalls VPN Wireless Networks Databases Containers Docker Kubernetes TLS DNS SPF DKIM DMARC OWASP Top 10 OWASP API Security Top 10 CVSS NIST CIS Controls ISO 27001 POPIA PCI DSS Vulnerability Scanning Penetration Testing Security Validation Privilege Escalation Lateral Movement Retesting
Industries

Managed IT support across key sectors

Why Hozit

A practical technology partner for your organisation

Authorised and controlled testing

Testing is limited to approved assets and agreed rules of engagement.

Business-focused reporting

Findings are explained in terms of practical and organisational impact.

Technical depth

Assessments can cover applications, networks, cloud, servers and identity.

Actionable remediation

Reports provide clear corrective guidance rather than scanner output alone.

Retesting available

Critical fixes can be independently verified.

Broader security support

Hozit can assist with firewalls, servers, cloud, backup and remediation projects.

Example Scenarios

How managed IT support can be applied

These are illustrative examples and are not presented as named customer case studies.

Internet-facing infrastructure test

Public servers and services can be assessed for exploitable exposure.

Customer portal assessment

Authentication, access control, session and input weaknesses can be tested.

Microsoft 365 review

Identity, MFA, sharing and administrative security can be assessed.

Internal network test

Lateral movement and privilege escalation can be evaluated.

API security assessment

Authorisation, data exposure and business-logic risks can be tested.

Remediation retest

Resolved findings can be validated before closure.

Frequently Asked Questions

Managed IT support FAQs

What is penetration testing?

Penetration testing is an authorised security assessment that validates whether selected weaknesses can be exploited.

What is a vulnerability assessment?

A vulnerability assessment identifies and prioritises known weaknesses without necessarily attempting exploitation.

What is the difference between the two?

A vulnerability assessment identifies possible weaknesses, while penetration testing validates selected risks through controlled testing.

Is penetration testing legal?

Yes, when performed with explicit authorisation and within an agreed scope.

Do you test websites?

Yes. We test authorised websites, portals and web applications.

Do you test APIs?

Yes. REST, GraphQL and selected other API environments can be assessed.

Can you test internal networks?

Yes. Internal assessments can evaluate segmentation, privilege and lateral-movement risks.

Can you assess Microsoft 365?

Yes. Identity, MFA, sharing, email and administrative controls can be reviewed.

Can you test AWS and Azure?

Yes. Selected cloud identity, networking, storage and security controls can be assessed.

Do you perform wireless testing?

Yes. Authorised corporate and guest wireless networks can be assessed.

Will testing disrupt our systems?

Testing is planned to reduce risk, but all engagements require agreed windows, exclusions and escalation procedures.

Do you use automated scanners?

Yes, but findings are reviewed and validated manually where appropriate.

Will we receive a report?

Yes. Reports include an executive summary, technical findings, evidence, risk ratings and remediation guidance.

How are vulnerabilities rated?

Findings are rated according to technical severity, exploitability, likelihood and business impact.

Do you provide CVSS scores?

CVSS scoring can be included where appropriate.

Can you help us fix the findings?

Yes. Hozit can support approved remediation work.

Do you provide retesting?

Yes. Retesting can confirm whether agreed weaknesses have been resolved.

How often should penetration testing be performed?

Testing should be considered regularly and after significant system, application or infrastructure changes.

Can testing support compliance requirements?

Yes. Selected testing evidence can support audits, tenders and security-assurance requirements.

How do we request a quotation?

Provide the authorised targets, preferred test type, environment size and required completion date.

Related Services

Build a stronger technology environment

Improve the reliability and security of your IT environment

Speak to Hozit about your users, infrastructure, support challenges and technology priorities.

Request an IT Assessment
Request a Quote WhatsApp