← ResourcesCybersecurity

The 7 things we check first in every South African security audit

After 14 years auditing South African SMEs, the same gaps come up again and again. Here's what we check first — and why it matters under POPIA.

Every few weeks we’re called in to audit the IT of a South African business that “thinks it’s probably fine.” Usually they’re not — not because anyone was careless, but because the basics quietly drifted while everyone got on with running the company.

We’ve done this for 14 years now, across everything from law firms to manufacturers. And the uncomfortable truth is that the serious risks are rarely exotic. They’re the same seven things, over and over. Here’s where we look first.

1. Who can actually log in?

The first thing we pull is a full list of user accounts — including the ones nobody remembers. The ex-employee whose Microsoft 365 account is still active. The shared “admin” login three people know the password to. The service account with a password set in 2019. Dormant accounts are the easiest door into a business, and almost every audit turns up at least one.

2. Is multi-factor authentication actually enforced?

“We have MFA” and “MFA is enforced on every account, with no exceptions” are very different statements. We check the second one. A single account without MFA — especially an admin — undoes the protection on everyone else. Under POPIA, if that account leaks customer data, “we mostly had MFA” is not a defence.

Phishing still causes most of the breaches we clean up. So we test the layers: is email filtering catching the obvious stuff? Is there endpoint protection (we deploy SentinelOne) that can stop ransomware after someone clicks? Has the team ever had real security-awareness training, or just a policy document nobody read?

4. Are the backups real — and have they ever been restored?

Everyone has “backups.” Far fewer have backups that are tested, off-site, and immune to the same ransomware that hits the main system. We ask one question that separates the two: when did you last successfully restore from them? If the answer is “never,” you don’t have a backup — you have a hope.

5. Who’s watching the firewall?

A firewall bought and installed in 2020 and never touched since is a security theatre prop. We check whether the rules still match how the business actually works, whether the firmware is patched, and — critically — whether anyone is actually watching what it reports.

6. Where does your customer data live?

POPIA doesn’t care how big you are. If you hold personal information — and every business does — you’re accountable for protecting it. So we map it: where it sits, who can reach it, and whether it’s encrypted. Most businesses have never drawn this map, which means they can’t protect what they can’t see.

7. What’s the plan when it goes wrong?

Finally: if you were hit tomorrow, what happens in the first hour? Who gets called? Can you keep operating? The businesses that recover well aren’t the ones that were never targeted — they’re the ones who’d decided in advance what to do.

The pattern behind all seven

None of this is expensive to fix. It’s just rarely anyone’s actual job — until it’s an emergency. That’s the real value of an outside audit: someone whose job it is to look, before an attacker does.

If any of these seven made you slightly unsure of the answer, that’s exactly what a free Cyber Health Check is for. We’ll go through them with you, in plain language, and show you where you actually stand.

Keep reading