Offensive security consultancy · Windhoek, Namibia

Find the way in before someone else does.

Root View Cyber Security and Software Services tests networks, applications and people the way a real attacker would. We work with organisations across Namibia and the wider SADC region that have systems worth protecting and limited internal security capacity.

  • Penetration testing
  • Red teaming
  • Attack surface assessment
  • DFIR advisory
RVS-0000-000 High

Service account password recoverable by any domain user

Asset
DC01.corp.internal
Technique
Kerberoasting — T1558.003
Evidence
TGS-REP hash recovered offline
Impact
Domain Admin via delegated SPN
Recommended fix

Move to a group managed service account, rotate the credential, and remove the SPN that is no longer required. Re-tested before the finding is closed.

Representative example. This is an illustration of how Root View writes up a finding. It is not taken from a client engagement and does not describe any real organisation’s systems.

Services

Each engagement is scoped, authorised and priced before any testing begins. Testing is manual and evidence-led — a scanner report is not a penetration test, and we do not sell one as though it were.

Penetration testing

External, internal, web application and wireless testing. We work from an attacker’s starting position, chain what we find, and show you the route rather than a list of unrelated issues.

Security assessments

Configuration and architecture review across servers, endpoints, identity, cloud and network. Findings are prioritised by real business impact and returned as a remediation plan your team can work through.

External attack surface assessment

Everything your organisation exposes to the internet, discovered and assessed: forgotten hosts, shadow infrastructure, exposed services, leaked credentials and third-party assets carrying your name.

Red teaming

Objective-based adversary simulation against agreed goals, testing detection and response rather than only prevention. Social engineering and physical elements are included only where explicitly authorised.

Security hardening

Hands-on remediation support after an assessment: Active Directory, server and endpoint baselines, TLS, DNS and email authentication, and HTTP security policy, verified by re-testing.

DFIR and security advisory

Digital forensics and incident response support when something has gone wrong, post-incident review to establish what happened, and ongoing advisory for organisations without an internal security function.

How an engagement works

Four steps, from first call to verified fix. You know the price and the dates before any testing begins.

  1. 01

    Scope

    A free 30-minute call to agree targets, testing window, rules of engagement and a fixed price. Nothing is touched before written authorisation is signed.

  2. 02

    Test

    Testing runs inside the agreed window with a short daily progress note. Anything critical is escalated to you the moment it is confirmed, not held back for the report.

  3. 03

    Report

    An executive summary your board can read and technical detail your engineers can act on. Every finding carries reproduction steps, business impact and a specific fix.

  4. 04

    Retest

    Once you have remediated, findings are retested and the report is reissued with fixes verified. Included in the original price.

Frameworks and standards

Where it is useful to you, we align assessment scope, testing methodology and reporting to recognised frameworks, so findings map to something your auditors, insurers or board already understand.

ISO/IEC 27001

Findings mapped to Annex A control areas to support an existing or planned information security management system.

NIST

Reporting structured against the Cybersecurity Framework functions, with technical testing conducted along SP 800-115 lines.

CIS Controls

Configuration review measured against CIS Benchmarks, with remediation sequenced by implementation group.

OWASP

Web application testing follows the Web Security Testing Guide, with findings referenced to ASVS requirements and the Top 10 where relevant.

PCI DSS

Testing scoped to cardholder data environments and reported in a form usable as supporting evidence within a wider compliance programme.

HIPAA Security Rule

Technical safeguard review for organisations handling protected health information, reported against the relevant safeguard categories.

MITRE ATT&CK

Adversary simulation and reporting mapped to ATT&CK techniques so your detection coverage can be measured against what we actually did.

Security intelligence

Current reporting from established security publishers and government sources, aggregated from their published feeds. Headlines and excerpts only — every card links to the original publisher.

Recent work

Client details are anonymised. Full reports remain confidential to the client.

Web application security review

Offshore services company · Windhoek

Reconnaissance, technology fingerprinting, security header analysis and vulnerability identification against a public-facing corporate site, delivered as a prioritised remediation plan.

  • Reconnaissance
  • Web security
  • Remediation plan

Deployment hardening and header configuration

Automotive services business · Namibia

Hosting, DNS and TLS configuration reviewed and rebuilt, with a full HTTP security header policy applied and verified against an independent external grading service after remediation.

  • Hardening
  • DNS and TLS
  • Header policy

About Root View

Root View Cyber Security and Software Services is an independent offensive security consultancy based in Windhoek, serving clients across Namibia and the wider SADC region.

We work with organisations that have real systems to protect and limited internal security capacity — financial services, logistics, professional services, education and the public sector. Engagements are run by practitioners holding hands-on, exam-assessed offensive security certifications.

Company registration with BIPA is in progress. Engagements currently run under a signed scope and written authorisation agreement.

  • Authorised, always

    No testing begins without written authorisation and an agreed scope.

  • Manual and evidence-led

    Automated tooling supports the work. It does not constitute the work.

  • Fixed price, no surprises

    Scope and cost agreed before we start. Retesting is included.

  • Confidential by default

    Client names, findings and reports stay private unless you tell us otherwise.

Request a scope call

Tell us roughly what you have and what is worrying you. You will get a reply within one working day and a fixed quote after a 30-minute call.

We do not share your details with anyone.