Penetration testing
External, internal, web application and wireless testing. We work from an attacker’s starting position, chain what we find, and show you the route rather than a list of unrelated issues.
Offensive security consultancy · Windhoek, Namibia
Root View Cyber Security and Software Services tests networks, applications and people the way a real attacker would. We work with organisations across Namibia and the wider SADC region that have systems worth protecting and limited internal security capacity.
Move to a group managed service account, rotate the credential, and remove the SPN that is no longer required. Re-tested before the finding is closed.
Each engagement is scoped, authorised and priced before any testing begins. Testing is manual and evidence-led — a scanner report is not a penetration test, and we do not sell one as though it were.
External, internal, web application and wireless testing. We work from an attacker’s starting position, chain what we find, and show you the route rather than a list of unrelated issues.
Configuration and architecture review across servers, endpoints, identity, cloud and network. Findings are prioritised by real business impact and returned as a remediation plan your team can work through.
Everything your organisation exposes to the internet, discovered and assessed: forgotten hosts, shadow infrastructure, exposed services, leaked credentials and third-party assets carrying your name.
Objective-based adversary simulation against agreed goals, testing detection and response rather than only prevention. Social engineering and physical elements are included only where explicitly authorised.
Hands-on remediation support after an assessment: Active Directory, server and endpoint baselines, TLS, DNS and email authentication, and HTTP security policy, verified by re-testing.
Digital forensics and incident response support when something has gone wrong, post-incident review to establish what happened, and ongoing advisory for organisations without an internal security function.
Four steps, from first call to verified fix. You know the price and the dates before any testing begins.
A free 30-minute call to agree targets, testing window, rules of engagement and a fixed price. Nothing is touched before written authorisation is signed.
Testing runs inside the agreed window with a short daily progress note. Anything critical is escalated to you the moment it is confirmed, not held back for the report.
An executive summary your board can read and technical detail your engineers can act on. Every finding carries reproduction steps, business impact and a specific fix.
Once you have remediated, findings are retested and the report is reissued with fixes verified. Included in the original price.
Where it is useful to you, we align assessment scope, testing methodology and reporting to recognised frameworks, so findings map to something your auditors, insurers or board already understand.
Findings mapped to Annex A control areas to support an existing or planned information security management system.
Reporting structured against the Cybersecurity Framework functions, with technical testing conducted along SP 800-115 lines.
Configuration review measured against CIS Benchmarks, with remediation sequenced by implementation group.
Web application testing follows the Web Security Testing Guide, with findings referenced to ASVS requirements and the Top 10 where relevant.
Testing scoped to cardholder data environments and reported in a form usable as supporting evidence within a wider compliance programme.
Technical safeguard review for organisations handling protected health information, reported against the relevant safeguard categories.
Adversary simulation and reporting mapped to ATT&CK techniques so your detection coverage can be measured against what we actually did.
Current reporting from established security publishers and government sources, aggregated from their published feeds. Headlines and excerpts only — every card links to the original publisher.
Vulnerabilities the US Cybersecurity and Infrastructure Security Agency has confirmed are being exploited in the wild. If something you run appears here, exploitation is no longer theoretical. Each entry links to its NVD record.
Content belongs to the respective publishers and is shown as headline, short excerpt and link under normal syndication practice. Root View Cyber Security and Software Services is not affiliated with, endorsed by, or speaking on behalf of any source shown here. Statistics are retrieved live from CISA and NIST and are not our own figures.
Client details are anonymised. Full reports remain confidential to the client.
Offshore services company · Windhoek
Reconnaissance, technology fingerprinting, security header analysis and vulnerability identification against a public-facing corporate site, delivered as a prioritised remediation plan.
Automotive services business · Namibia
Hosting, DNS and TLS configuration reviewed and rebuilt, with a full HTTP security header policy applied and verified against an independent external grading service after remediation.
Root View Cyber Security and Software Services is an independent offensive security consultancy based in Windhoek, serving clients across Namibia and the wider SADC region.
We work with organisations that have real systems to protect and limited internal security capacity — financial services, logistics, professional services, education and the public sector. Engagements are run by practitioners holding hands-on, exam-assessed offensive security certifications.
Company registration with BIPA is in progress. Engagements currently run under a signed scope and written authorisation agreement.
No testing begins without written authorisation and an agreed scope.
Automated tooling supports the work. It does not constitute the work.
Scope and cost agreed before we start. Retesting is included.
Client names, findings and reports stay private unless you tell us otherwise.
Tell us roughly what you have and what is worrying you. You will get a reply within one working day and a fixed quote after a 30-minute call.