Security assessment
A practical review of identity, endpoints, email, network and backup, with findings ranked by real-world consequence.
Small and mid-sized organisations are targeted precisely because their defences are assumed to be weak. The controls that prevent the overwhelming majority of incidents are not exotic — they are multi-factor authentication, current patches, tested backups, mail authentication and least-privilege access. We implement those properly, then build outward.
Almost always with identity, email or an unpatched endpoint.
A practical review of identity, endpoints, email, network and backup, with findings ranked by real-world consequence.
Multi-factor authentication, conditional access, privileged account separation and access reviews.
Managed detection on workstations and servers, with central visibility and response capability.
SPF, DKIM and DMARC, anti-phishing controls, and protection against impersonation of your own domain.
Firewall configuration and review, segmentation, and secure remote access.
Encryption, retention, access control and handling aligned to POPIA obligations.
Isolated, immutable backup copies and a recovery process proven by test restore.
Short, practical sessions on the attacks your staff will actually encounter.
A written plan, agreed contacts, and support during and after an incident.
We review the environment against the controls that prevent the majority of real incidents, and report findings in business language.
Findings ranked by likelihood and consequence. The first few items usually remove most of the exposure.
Controls implemented in order of impact, scheduled to avoid disrupting the business.
Configuration confirmed, restores tested, mail authentication validated. Verification is part of the work, not an optional extra.
Ongoing monitoring, patching, access review and periodic reassessment as the environment changes.
Most attacks are not targeted. They are automated, and they find exposed accounts and unpatched systems regardless of company size. Smaller organisations are compromised more often precisely because the basic controls are frequently absent.
Day-to-day technology operations — support, monitoring, patching and vendor management — run to an agreed standard with a named contact.
Explore Managed IT ExploreCloud environments, identity, email and business continuity — designed for the workload, documented, and operated rather than merely installed.
Explore Cloud & Infrastructure ExploreBusiness systems built around how your organisation actually works — replacing spreadsheets, email chains and disconnected tools with one connected platform.
Explore Software & Systems ExploreA short conversation is usually enough to tell whether this is the right capability for your situation — and we will say so if it is not.
Nothing matches that. Try “software”, “security” or “SpikeOS”.