06 / Practical security

Security that matches your real risk.

Small and mid-sized organisations are targeted precisely because their defences are assumed to be weak. The controls that prevent the overwhelming majority of incidents are not exotic — they are multi-factor authentication, current patches, tested backups, mail authentication and least-privilege access. We implement those properly, then build outward.

The problem

Where incidents actually start

Almost always with identity, email or an unpatched endpoint.

Common exposure

  • Passwords reused across business and personal accounts
  • No multi-factor authentication on email or administrative accounts
  • Missing SPF, DKIM and DMARC, so your domain can be spoofed
  • Local administrator rights on every workstation
  • Backups on the same network as the data they protect
  • No record of who has access to what

Controlled

  • Multi-factor authentication enforced, with conditional access policies
  • Managed endpoint protection with central visibility and response
  • Mail authentication published and enforced against spoofing
  • Administrative rights separated from daily-use accounts
  • Immutable, offsite backup copies isolated from the production network
  • Reviewed access registers and a tested incident response plan
Services

What we implement

01

Security assessment

A practical review of identity, endpoints, email, network and backup, with findings ranked by real-world consequence.

02

Identity hardening

Multi-factor authentication, conditional access, privileged account separation and access reviews.

03

Endpoint protection

Managed detection on workstations and servers, with central visibility and response capability.

04

Email security

SPF, DKIM and DMARC, anti-phishing controls, and protection against impersonation of your own domain.

05

Network security

Firewall configuration and review, segmentation, and secure remote access.

06

Data protection

Encryption, retention, access control and handling aligned to POPIA obligations.

07

Backup & ransomware resilience

Isolated, immutable backup copies and a recovery process proven by test restore.

08

Awareness training

Short, practical sessions on the attacks your staff will actually encounter.

09

Incident response

A written plan, agreed contacts, and support during and after an incident.

Process

01 / 1–2 weeks

Assess

We review the environment against the controls that prevent the majority of real incidents, and report findings in business language.

02 / Within assessment

Prioritise

Findings ranked by likelihood and consequence. The first few items usually remove most of the exposure.

03 / 2–8 weeks

Remediate

Controls implemented in order of impact, scheduled to avoid disrupting the business.

04 / 1 week

Verify

Configuration confirmed, restores tested, mail authentication validated. Verification is part of the work, not an optional extra.

05 / Continuous

Monitor & review

Ongoing monitoring, patching, access review and periodic reassessment as the environment changes.

Cybersecurity

Questions we are actually asked

Most attacks are not targeted. They are automated, and they find exposed accounts and unpatched systems regardless of company size. Smaller organisations are compromised more often precisely because the basic controls are frequently absent.

Works with

Managed IT

Day-to-day technology operations — support, monitoring, patching and vendor management — run to an agreed standard with a named contact.

Explore Managed IT Explore

Cloud & Infrastructure

Cloud environments, identity, email and business continuity — designed for the workload, documented, and operated rather than merely installed.

Explore Cloud & Infrastructure Explore

Software & Systems

Business systems built around how your organisation actually works — replacing spreadsheets, email chains and disconnected tools with one connected platform.

Explore Software & Systems Explore

Tell us what is not working.

A short conversation is usually enough to tell whether this is the right capability for your situation — and we will say so if it is not.