Secure · Cybersecurity

Security you can
show someone.

Not a product you bought and forgot about. Layered protection that is monitored, staff who know what a bad email looks like, and documentation that stands up when an insurer, a client or the Information Regulator asks how you handle personal data.

Endpoint, email and identity Awareness training POPIA documentation

The honest version

Most breaches are not clever.

The attacks that hurt small and mid-sized South African businesses are rarely sophisticated. Someone reuses a password. An invoice arrives from a supplier's compromised mailbox with new banking details. A laptop with no encryption goes missing. A server that has not been patched in two years gets found by a scanner that was not even looking for you.

None of that needs an expensive product to prevent. It needs a small number of controls, applied consistently, checked regularly, and written down. That is what this service is.

We will also tell you when you do not need something. Selling a mid-sized business an enterprise security stack it cannot operate is a good way to take money and leave the risk exactly where it was.

Where we start. If you do nothing else, do these four. They are cheap, they are fast, and between them they close most of the routes in.

1. Multi-factor authentication on email, for everyone, with no exceptions left undocumented.

2. A backup that has been restored from at least once, and is kept where ransomware cannot reach it.

3. A leaver process that closes accounts on the day someone walks out.

4. Patching on a schedule, including the things that are not Windows.

What we put in place

Layers, because any
single control will fail.

The point of layering is that no one mistake is fatal. Somebody will eventually click the link. The question is what happens next.

  • On the device

    • Managed endpoint detection and response
    • Disk encryption on laptops
    • Operating system and application patching
    • Local administrator rights removed
    • Remote wipe for lost devices
  • On email

    • Advanced filtering and link checking
    • SPF, DKIM and DMARC configured properly
    • Impersonation and display-name protection
    • External sender warnings
    • Mailbox rule monitoring
  • On identity

    • Multi-factor authentication everywhere
    • Conditional access by location and device
    • Scheduled access reviews
    • Same-day offboarding
    • Privileged accounts separated from daily use
  • On the network

    • Firewall rules reviewed and documented
    • Guest and operational traffic separated
    • Remote access through VPN only
    • Default credentials removed from devices
    • Logging kept long enough to be useful
  • On your people

    • Short, practical awareness sessions
    • Simulated phishing with follow-up coaching
    • A clear route to report something suspicious
    • Payment-change verification procedure
    • Induction material for new starters
  • When it goes wrong

    • Written incident response plan
    • Defined isolation and containment steps
    • Tested restore path and timings
    • Notification obligations mapped out
    • Post-incident review and fixes

POPIA

The technical half
of compliance.

POPIA is a legal obligation with a large technical component. We do not give legal advice — that is your attorney's job — but we handle the part that lives in your systems, and produce the evidence your Information Officer needs.

  1. Find the personal information Where it lives across mailboxes, file shares, cloud storage, operational systems and that one spreadsheet on somebody's desktop. You cannot protect what nobody has mapped.
  2. Control who can reach it Permissions reviewed against who actually needs access, with the over-broad shares tightened and the results recorded.
  3. Apply the safeguards Encryption, multi-factor authentication, backups and logging — the "reasonable technical measures" the Act expects, implemented and evidenced rather than asserted.
  4. Set retention and deletion How long each category of information is kept and what happens at the end of it, configured in the systems rather than left as a policy nobody applies.
  5. Prepare for an incident A breach has notification obligations with time pressure attached. Deciding who does what beforehand is considerably cheaper than working it out on the day.

Common questions

Security, answered.

We are small. Are we really a target?

Most attacks are not aimed at anyone in particular. Automated scanning finds exposed services and weak passwords regardless of company size, and business email compromise specifically favours smaller firms because the payment approval chain is short. Being small changes what you should spend, not whether you should bother.

Do you run a 24/7 security operations centre?

No, and we would rather say so than imply otherwise. We deploy and manage monitored endpoint protection, and where a client genuinely needs round-the-clock monitored detection and response we bring in a specialist partner and manage that relationship. Most businesses our clients' size are better served by getting the fundamentals consistently right.

Does cyber insurance require any of this?

Increasingly, yes. Insurers commonly ask whether you enforce multi-factor authentication, whether backups are offline or immutable, and whether staff receive security training. Answering those questions accurately — and being able to show it — affects both whether you are covered and what you pay.

How disruptive is rolling out MFA?

Less than people expect, if it is communicated first. The usual pattern is a short notice period, a walkthrough for staff, a staged rollout by department, and support standing by on the switchover day. The complaints last about a week. The alternative lasts considerably longer.

Can you assess what we have without taking over our IT?

Yes. A standalone security assessment gives you a documented view of your current state and a prioritised list of what to fix, with costs. The report is yours to act on with whoever you like, including your existing provider.

Next step

Tell us what you need.

A paragraph is enough to start. We come back with what we would do, what it would cost and how long it would take.