Nsirhelelo · security
Locked before it's a problem.
Security for the business that has no IT department. We check what you have, fix what is open, and tell you in plain language what we found. No jargon, and no fear either.
R17m
the average cost of recovering from ransomware in South Africa, before any ransom is paid
27%
of attacks start with a stolen password, not a clever hack
22%
of South African small businesses hit by ransomware closed for good
Sources: Sophos, The State of Ransomware in South Africa 2026; ESET SMB Digital Security Sentiment Report. Figures are for South African organisations.
What we check
The same checks an attacker runs first, run for you first. Read-only, from the outside and from your own admin console.
Domain and email
Can someone send mail as you? We read your SPF, DKIM and DMARC records and tell you whether a forged invoice from “your” address would land in a customer's inbox.
Website and hosting
Certificates, security headers, third-party scripts, staging copies left open to the world. What is exposed, and what it exposes.
Accounts
Who has admin, who has two-step verification, which former staff still have a login. Read from your Google Workspace or Microsoft 365, not from memory.
Backups
Not whether you have them. Whether they restore, how old they are, and whether the password that opens the office also opens them.
People
How your team handles a convincing email. Measured with a drill, not a lecture.
Ku lulamisa · what we fix
What we fix
The report comes with a fixed price for closing what it found. Most businesses need four or five of these, not all of them.
- Publish DMARC and tighten SPF so nobody can send as your domain
- Enforce two-step verification for the whole organisation, so new accounts inherit it
- Security headers on your site and pinned third-party scripts, so a compromised CDN cannot change your page
- Close, or put a door on, every staging and test copy
- A password manager for the team, with the shared logins moved into it and the spreadsheet deleted
- A restore of your backups that actually ran, on a date you can point to
Where AI does the reading
We use it where it beats a person reading logs at 22:00, and nowhere else.
Phishing desk
Staff forward a suspicious email to one address. Within minutes they get a plain answer: safe, suspicious or fake, and why. The real ones come to us.
Weekly log digest
Your Workspace or 365 sign-in and admin logs, read every week. New devices, new countries, new forwarding rules, in one short note to the owner.
Drills written for your business
Simulated phishing built around your real suppliers and invoice formats, once a quarter. One page of results. Nobody is named and shamed.
AI does the reading. People make the call.
Ndlela · how it runs
How an engagement runs
01
Check
Five working days. Read-only, from the outside and from your admin console. Nothing changes until you say so.
02
Report, in your words
Six pages for whoever runs your systems, one page for the owner. Every finding says how serious it is and what it costs to close.
03
Lock down
We fix what the report found, at the price the report quoted. You approve every change to your own accounts.
04
Keep watch
Monthly re-check, the weekly digest, the phishing desk and a quarterly drill. Cancel any month.
What it costs
Start here
Security Health Check
R5,500
once-off
Five working days. Domain, email, website, accounts, backups. Two reports. No commitment beyond it.
Lock-down
Fixed price
quoted off the report
We close what the check found. You approve every change before it is made.
Keep watch
From R2,500
a month, cancel any month
Monthly re-check, weekly log digest, the phishing desk and a quarterly drill.
POPIA readiness
Quoted
to the size of the business
Eight-conditions gap check, Information Officer registration, privacy notice, breach playbook.
Ntiyiso · straight talk
Straight talk
POPIA, without the panic
The Information Regulator now inspects rather than waits, and has started issuing fines. We map your business against POPIA's eight conditions, register your Information Officer, write a privacy notice your customers will actually read, and leave you a breach-notification playbook so the first hour of a bad day is already written down.
What we are not
We are not a 24-hour security operations centre, and we do not do forensics or insurance-grade incident response. If you are in the middle of a breach right now, call us anyway. We will tell you what to switch off in the next ten minutes, then put you in touch with people who do the rest.
One Tuesday evening
An events company in Giyani forwarded us a Google security notice at 19:22, worried it meant a breach. By 23:45 they had a written answer (it did not), a full assessment of their domain, mail and website, and a fix list with two items that mattered.
Book a health check
R5,500, five working days, and you keep the report whatever you decide next.
Book a health check