Nsirhelelo · security

Locked before it's a problem.

Security for the business that has no IT department. We check what you have, fix what is open, and tell you in plain language what we found. No jargon, and no fear either.

  • R17m

    the average cost of recovering from ransomware in South Africa, before any ransom is paid

  • 27%

    of attacks start with a stolen password, not a clever hack

  • 22%

    of South African small businesses hit by ransomware closed for good

Sources: Sophos, The State of Ransomware in South Africa 2026; ESET SMB Digital Security Sentiment Report. Figures are for South African organisations.

What we check

The same checks an attacker runs first, run for you first. Read-only, from the outside and from your own admin console.

  • Domain and email

    Can someone send mail as you? We read your SPF, DKIM and DMARC records and tell you whether a forged invoice from “your” address would land in a customer's inbox.

  • Website and hosting

    Certificates, security headers, third-party scripts, staging copies left open to the world. What is exposed, and what it exposes.

  • Accounts

    Who has admin, who has two-step verification, which former staff still have a login. Read from your Google Workspace or Microsoft 365, not from memory.

  • Backups

    Not whether you have them. Whether they restore, how old they are, and whether the password that opens the office also opens them.

  • People

    How your team handles a convincing email. Measured with a drill, not a lecture.

Ku lulamisa · what we fix

What we fix

The report comes with a fixed price for closing what it found. Most businesses need four or five of these, not all of them.

  • Publish DMARC and tighten SPF so nobody can send as your domain
  • Enforce two-step verification for the whole organisation, so new accounts inherit it
  • Security headers on your site and pinned third-party scripts, so a compromised CDN cannot change your page
  • Close, or put a door on, every staging and test copy
  • A password manager for the team, with the shared logins moved into it and the spreadsheet deleted
  • A restore of your backups that actually ran, on a date you can point to

Where AI does the reading

We use it where it beats a person reading logs at 22:00, and nowhere else.

  • Phishing desk

    Staff forward a suspicious email to one address. Within minutes they get a plain answer: safe, suspicious or fake, and why. The real ones come to us.

  • Weekly log digest

    Your Workspace or 365 sign-in and admin logs, read every week. New devices, new countries, new forwarding rules, in one short note to the owner.

  • Drills written for your business

    Simulated phishing built around your real suppliers and invoice formats, once a quarter. One page of results. Nobody is named and shamed.

AI does the reading. People make the call.

Ndlela · how it runs

How an engagement runs

  1. 01

    Check

    Five working days. Read-only, from the outside and from your admin console. Nothing changes until you say so.

  2. 02

    Report, in your words

    Six pages for whoever runs your systems, one page for the owner. Every finding says how serious it is and what it costs to close.

  3. 03

    Lock down

    We fix what the report found, at the price the report quoted. You approve every change to your own accounts.

  4. 04

    Keep watch

    Monthly re-check, the weekly digest, the phishing desk and a quarterly drill. Cancel any month.

What it costs

  • Start here

    Security Health Check

    R5,500

    once-off

    Five working days. Domain, email, website, accounts, backups. Two reports. No commitment beyond it.

  • Lock-down

    Fixed price

    quoted off the report

    We close what the check found. You approve every change before it is made.

  • Keep watch

    From R2,500

    a month, cancel any month

    Monthly re-check, weekly log digest, the phishing desk and a quarterly drill.

  • POPIA readiness

    Quoted

    to the size of the business

    Eight-conditions gap check, Information Officer registration, privacy notice, breach playbook.

Ntiyiso · straight talk

Straight talk

POPIA, without the panic

The Information Regulator now inspects rather than waits, and has started issuing fines. We map your business against POPIA's eight conditions, register your Information Officer, write a privacy notice your customers will actually read, and leave you a breach-notification playbook so the first hour of a bad day is already written down.

What we are not

We are not a 24-hour security operations centre, and we do not do forensics or insurance-grade incident response. If you are in the middle of a breach right now, call us anyway. We will tell you what to switch off in the next ten minutes, then put you in touch with people who do the rest.

One Tuesday evening

An events company in Giyani forwarded us a Google security notice at 19:22, worried it meant a breach. By 23:45 they had a written answer (it did not), a full assessment of their domain, mail and website, and a fix list with two items that mattered.

Book a health check

R5,500, five working days, and you keep the report whatever you decide next.

Book a health check

Or forward us the email you are worried about