Cybersecurity
Endpoint protection, email security and patching, managed as a standing concern rather than a project you did once in 2019.
Security as maintenance, not a purchase
Most breaches at businesses your size do not involve anything clever. They involve an unpatched machine, a password reused from a leaked site, or someone clicking a convincing invoice. That is good news, because the defences are ordinary and achievable.
What we put in place
- Endpoint protection built on ESET, centrally managed so we can see which machines are actually protected rather than assuming.
- Email security, because email remains the way most attacks arrive.
- Patch management on a schedule across operating systems and common applications.
- Access reviews, so the person who left in March no longer has a live account.
- Backup with tested recovery, which is the only defence that still works after ransomware.
- Security advisory in plain language, so you can make decisions without a translator.
Why an untested backup is not a backup
A backup you have never restored from is a hope. We test recovery so that the day you need it is not the day you find out the job had been failing quietly for four months. This is the single most common gap we find when we take over an environment.
Compliance
If you handle personal information in South Africa, POPIA applies to you. Good security practice and POPIA obligations overlap heavily, so doing the sensible things gets you most of the way. We advise on where you stand and what is worth prioritising, and we are candid about what is genuinely required versus what a vendor is trying to sell you.
Where to start
An initial assessment of your environment, at no charge. You get a clear picture of what you have, where the gaps are, and which ones actually matter. Some clients act on it with us, some act on it themselves. Either is a better outcome than not knowing.
Questions we get asked
Is antivirus enough on its own?
No. Endpoint protection is necessary but it is one layer. Patching, email filtering, access control and tested backups do at least as much work, and they cover the failures antivirus cannot.
Do you help after a breach?
Yes. If you are dealing with something live, call 010 020 1288 rather than filling in a form. Speed matters more than process.
Does this cover POPIA?
We advise on where your environment stands against POPIA obligations and what to prioritise. Compliance is broader than IT, so we cover the technical side and are clear about where legal advice is needed.
