Service 04 · Threat & vigilance
You do not need to be a target. You only need to be reachable.
Firewall configuration, network segmentation, monitoring and response — set up properly and then actually watched, rather than installed once and forgotten.

The problem
Almost no attack on a business this size is personal. It is automated, it is looking for anything exposed, and it does not care what you do.
The common pattern is not a sophisticated breach. It is a default password on a device facing the internet, a flat network where a single infected laptop can reach the file server, or a staff member who clicked something and nobody noticed for three weeks.
We harden what is exposed, segment the network so one compromised device cannot reach everything, and put monitoring in place so an incident is caught in hours rather than discovered by a client. Where you have compliance obligations under POPIA, we document what was done.
Layers of defence
Firewall and network hardening, monitoring, and incident response.
- Hardened
Firewall & zoning
Zone-based rules, VLAN segmentation, and intrusion prevention configured, not left on defaults.
- Hardened
Exposure review
What of yours is reachable from the internet, and what should not be.
- Hardened
Endpoint protection
Managed protection on workstations and servers, with alerts that reach a human.
- Hardened
Backup verification
A backup nobody has restored from is not a backup. We test yours.
- Hardened
Access & identity
Multi-factor authentication, account hygiene, and removing access when people leave.
- Hardened
Incident response
A written plan for who does what, and us on the end of the phone when it happens.
Response timeline
How an engagement runs.
01 / Review
Find what is exposed
Assessment of the network, devices, accounts and current defences.
02 / Prioritise
Fix the cheap wins first
Ranked by risk against effort, so the worst gaps close immediately.
03 / Harden
Implement
Firewall, segmentation, MFA, endpoint protection and tested backups.
04 / Watch
Monitor & respond
Ongoing monitoring, patching and a response plan on retainer.
Questions we get asked
- We are small. Is this really necessary?
- Small businesses are targeted more often precisely because the defences are usually weaker. The cost of a week of downtime is almost always higher than a year of getting this right.
- Do you do penetration testing?
- We do assessment and hardening. For formal penetration testing against a compliance requirement, we scope it separately and give you the report as the deliverable.
- What does POPIA require of us?
- In short, reasonable steps to secure personal information you hold and a plan for reporting breaches. We are not attorneys — but we implement and document the technical side so your compliance advisor has something to point at.
Start here
Start with the audit. It costs you a morning.
Tell us where things are breaking. We walk the site, map what you have, and come back with a phased plan and a real number.
Book an audit