Cybersecurity Risk Management, Delivered Remotely Worldwide
Identity first, because that is where the attacks actually land.
Cybersecurity risk management is mostly not about buying security products. It is about knowing what you have, closing the routes attackers actually use, and being able to prove both. Most estates we assess have bought more tooling than they have configured.
The starting position matters here. The dominant route into a small or mid-sized business is no longer an exploited vulnerability in something unpatched — it is a valid login used by someone who should not have it. That single fact should reorder the whole spending plan, and usually it has not.
Where cybersecurity risk management should start
Identity, first and by a distance. Multi-factor authentication everywhere with no standing exemptions, legacy authentication protocols disabled, conditional access policies that reflect how the business actually operates, and privileged accounts separated from daily-use accounts. Deploying MFA is not the same as covering everyone with it — the difference is where most incidents live, and we set out the specific gaps in our analysis of why identity attacks now beat exploits.
Endpoints, second. Actual endpoint detection and response rather than the antivirus that came with the machine, with alerts going somewhere a person looks. A detection nobody reads is an expensive log entry.
Email, third. The domain records that stop your name being used to attack other people — SPF, DKIM and a DMARC policy that is actually enforcing rather than sitting at p=none for three years.
Recovery, underneath all of it. Every control above can fail. What determines whether that is an incident or a catastrophe is whether you can restore, which is why disaster recovery is a security control and not an IT housekeeping task.
Assessment before purchase
Cybersecurity risk management starts with finding out what is true, which is less obvious than it sounds. Typical findings in a first assessment:
- Accounts belonging to people who left, still licensed and still able to authenticate.
- MFA exemptions created for a specific reason years ago and never removed.
- Shared administrator credentials in a spreadsheet, a chat history, or somebody’s head.
- A security product paid for monthly and never fully rolled out.
- Logging retained for a period so short that a breach discovered normally — weeks after it happened — cannot be investigated at all.
- Third-party and supplier accounts with more access than the relationship requires, and no process for removing them when the supplier changes staff.
None of these need a purchase to fix. They need someone to look, write it down, and work through the list.
POPIA is a security obligation, not just a legal one
South African businesses have a statutory duty to secure personal information under the Protection of Personal Information Act, and the technical half of that lands on whoever runs the systems. Section 19 requires appropriate, reasonable technical and organisational measures; section 22 requires notification when there are reasonable grounds to believe personal information has been accessed by an unauthorised person.
That second one has a practical consequence people miss: you cannot notify about something you cannot detect, and you cannot describe the scope of a breach without logs that go back far enough. Retention is a compliance control, not just an operational preference. The full technical checklist is in our POPIA compliance guide, and the Information Regulator publishes its own guidance and breach notification form on the Information Regulator’s website.
The evidence problem
Increasingly the question is not "are you secure" but "show me". Three groups now ask, and they ask in different formats:
- Insurers, on the application form, where an optimistic answer can void the policy at claim time. The controls they ask about are consistent and public — we went through a real application in our piece on the controls underwriters check.
- Clients, particularly larger ones, via security questionnaires that arrive with a procurement deadline attached.
- Auditors and regulators, who want the policy, the evidence it was applied, and the record of exceptions.
Answering these from memory each time is slow and inconsistent. Part of cybersecurity risk management is maintaining the artefacts once so the answers are the same every time and can be produced in an afternoon.
What a risk register is actually for
A risk register is not a list of things that are wrong. It is a record of decisions. Each entry names a risk, an owner, and what was decided — accept, mitigate, transfer to an insurer, or avoid by not doing the thing.
Accepting a risk deliberately is a perfectly legitimate business position. A small firm may reasonably decide that a four-hour recovery time is not worth what it costs to achieve. What is not defensible is the same exposure existing because nobody ever raised it. The register is the difference between the two, and it is the document that matters most if something does go wrong.
Working with what you already have
Most businesses on Microsoft 365 Business Premium are paying for security capability they have not switched on. Conditional access, device compliance policies, Defender, sensitivity labelling and audit retention are frequently included and frequently unconfigured. Before recommending anything new, we establish what the current licences already entitle you to — it is common for the first phase of work to have no additional software cost at all.
Where new spending is genuinely needed we will say so, with the reasoning and the alternative. We do not resell security products, so there is no margin riding on the recommendation.
Who this work is usually for
Professional firms, medical practices, financial services businesses and manufacturers — worked with remotely across South Africa, the UK and Europe, and on site across the Helderberg and Cape Town. Almost none of this needs anyone physically present: identity, conditional access, endpoint policy and logging are configured through the same admin surfaces wherever you sit. The regulated ones tend to arrive because of an external deadline — a client questionnaire, an insurance renewal, an audit finding. The unregulated ones usually arrive after something happened to a business they know.
Either way, cybersecurity risk management starts the same: a bounded assessment producing a documented estate, a prioritised risk list and a costed remediation plan. You keep all three regardless of what you decide to do next, and the prioritisation is honest about which items are cheap. Several usually are.