IT Security Governance & Management Assessment

Move From Reactive Security to Governance-Led Resilience

We help leadership teams identify governance gaps, prioritise cyber risk, and build a practical action roadmap across people, process, and technology.

100% Black Female-Owned South Africa Focused Gauteng Based

Live Diagnostic Preview

67%

Defined

Sample Cyber Maturity Score

Current State: Defined

Use the slider to explore the five maturity levels and see what each stage looks like for your organisation.

Ad HocDevelopingDefinedManagedOptimized

Sample Domain Scores

Identity & Access72%
Network Security58%
Data Security45%
Security Culture32%
Compliance Mgmt65%
Physical Security80%

Why This Matters Now

The threat landscape has never been more complex or more costly.

This diagnostic is built for board-level visibility, legal exposure reduction, and operational resilience across organisations of all sizes.

Average Incident Timeline

Day 0
Breach occurs
Day 12
Avg. internal detection
Day 72hrs
POPIA notify deadline
Day 200+
Full containment avg.

Top Global Risk

Protiviti 2026

Cybersecurity failure ranks among the top five global risks, above natural disasters, economic crises, and supply chain disruption. For South African organisations, the risk is amplified by skills shortages and inconsistent governance.

Board Oversight Gap

Governance & Fiduciary Duty

68% of boards report insufficient understanding of their own cyber risk posture. Without structured visibility, directors cannot fulfill their legal duty of care, exposing the organisation to both regulatory and shareholder action.

Unseen Vulnerabilities

People, Process & Technology

Critical gaps are rarely in technology alone. Shadow IT, unreviewed vendor access, inconsistent patch cycles, and unmonitored privileged accounts create exposure that no firewall can fix. Only a structured assessment can surface these risks.

Penalty & Litigation Risk

Protection of Personal Information Act (POPIA) & Regulatory Exposure

South Africa's Protection of Personal Information Act (POPIA) carries fines up to R10 million and up to 10 years imprisonment for responsible parties. Poor incident preparedness, combined with a failure to notify within 72 hours, significantly amplifies legal and reputational liability.

Where Do You Stand?

5-Level Cybersecurity Maturity Model

Every organisation sits somewhere on this spectrum. The assessment identifies your precise position and charts the practical path forward.

12345
01

Ad Hoc

Reactive, fire-fighting posture. Controls are informal or nonexistent. Security decisions depend on individuals rather than process.

• No documented policies

• Incidents handled ad hoc

• No board visibility

02

Developing

Some controls exist but are siloed, poorly communicated, and inconsistently applied across teams or business units.

• Fragmented documentation

• Uncoordinated response

• Limited metrics

Industry Avg.
03

Defined

Documented policies and repeatable practices exist. Teams understand their responsibilities but measurement and optimisation are still developing.

• Documented controls

• Regular review cycles

• Some KPI tracking

04

Managed

Metrics and leadership oversight actively drive security decisions. Performance is tracked, reported upward, and used to improve posture.

• Board reporting in place

• KPI/KRI dashboards

• Proactive risk review

05

Optimised

Continuous improvement is embedded. Threat intelligence feeds into proactive control updates. Security culture is a competitive advantage.

• Threat intel integration

• Continuous improvement

• Security as culture

Full Coverage

Assessment Scope

14 domains spanning governance, operations, and technical security, covering every critical layer of your organisation's cyber posture, assessed and scored.

Governance & Policy
Operations & Process
Technical Controls

Sample radar, illustrative only

Auditing

Evaluates the effectiveness of security control reviews and the frequency, independence, and rigour of audit processes across the organisation.

Compliance Management

Assesses alignment with POPIA, ISO 27001, NIST, and applicable sector regulations. Identifies compliance gaps and enforcement accountability.

Policy & Process Governance

Reviews policy maturity, enforceability, staff awareness, and whether documented processes are operationally adopted or merely exist on paper.

Event & Incident Management

Assesses readiness to detect, contain, and recover from security incidents, including playbook quality, escalation paths, and post-incident learning.

Risk Analysis

Translates raw risk data into prioritised business decisions. Evaluates risk register quality, likelihood/impact assessment, and executive risk reporting.

Security Culture

Measures staff awareness, training cadence, accountability structures, and whether leadership behaviour models the security posture expected organisation-wide.

Vulnerability Management

Assesses the identification, prioritisation, and remediation of technical weaknesses, including scan frequency, patch service level agreements (SLAs), and exception handling.

Servers

Reviews server hardening standards, privileged access controls, patch compliance, logging, and monitoring across on-premise and cloud infrastructure.

End User Devices

Evaluates endpoint security controls including mobile device management (MDM), encryption, Bring Your Own Device (BYOD) policy, antivirus coverage, and device lifecycle management practices.

Identity & Access Management

Validates user provisioning, multi-factor authentication (MFA) adoption, privileged account governance, access reviews, and offboarding processes across all systems.

Data Security

Assesses data classification, encryption at rest and in transit, data loss prevention (DLP) controls, data retention compliance, and handling of sensitive personal information under POPIA.

Applications

Evaluates secure development practices, third-party application governance, patch management for business software, and application access controls.

Network Security

Reviews perimeter defences, internal segmentation, traffic monitoring, firewall rule hygiene, virtual private network (VPN) usage, and wireless security standards.

Physical Security

Assesses physical access controls, visitor management, server room security, clean desk policies, and asset disposal procedures protecting people and infrastructure.

⚠ Governance & Legal Exposure

Boards Are Failing Their
Fiduciary Cyber Duties

Most boards have limited cybersecurity knowledge and lack the visibility required to govern digital risk effectively, creating direct legal and financial exposure.

Regulatory Reality

South Africa's Protection of Personal Information Act (POPIA) and related data protection legislation carry penalties up to R10 million and imprisonment of up to 10 years for data protection failures linked to poor cyber governance.

68%

of boards report insufficient understanding of their organisation's cyber risk posture

R4.5M+

average cost of a data breach in South Africa, not counting reputational damage and litigation

72hrs

regulatory window to notify authorities of a breach. Most organisations lack the incident readiness to respond in time

organisations with active, effective governance frameworks are three times less likely to suffer a material incident

How It Works

3-Stage Transformation Roadmap

From raw stakeholder insight to a boardroom-ready governance strategy, in three deliberate stages.

01

Stakeholder Insight

We capture what your leadership team and IT staff actually believe about security, surfacing blind spots that surveys and audits miss.

  • Structured interviews & workshops
  • Multi-stakeholder perspective mapping
  • Governance perception vs. reality gap analysis
02

Data-Driven Prioritisation

Stakeholder input is converted into structured maturity scores across all 14 domains, ranked by risk severity and business impact.

  • Domain-level scoring framework
  • Risk impact & likelihood matrix
  • Executive-ready data visualisation
03

Strategic Resilience

A practical governance roadmap aligned to industry best practices, giving your board and leadership team a clear path forward.

  • ISO 27001 & NIST framework alignment
  • Phased improvement roadmap
  • KPI/KRI monitoring framework

Outputs & Deliverables

What Your Organisation Receives

Three structured outputs designed for both boardroom presentation and operational execution.

Maturity Scorecard

A boardroom-ready summary of your organisation's current cybersecurity standing, benchmarked against industry best practice and the 5-level maturity model.

  • Overall maturity level (1–5)
  • Benchmark vs. sector peers
  • Executive summary narrative

Primary Output

Prioritised Risk Roadmap

A ranked action plan guiding immediate and medium-term security improvements, ordered by business impact, feasibility, and governance urgency.

  • Risk ranked by severity
  • Quick wins vs. strategic initiatives
  • Owner & timeline recommendations

Domain Deep-Dive Report

Granular scores and findings across all 14 assessment domains, with specific attention to Governance, Policy & Process, and Identity & Access Management.

  • Score per domain (1–5)
  • Finding narrative per domain
  • Recommended next actions

Industry Alert

32%

of IT staff regularly receive security awareness training

That means more than two-thirds of your team is operating without current cyber hygiene knowledge, regardless of how strong your technical controls are.

82%

of breaches involve a human element (phishing, credential misuse, error)

return on investment for structured security awareness programs

Security Culture Domain

Security Culture:
Your Biggest Vulnerability

Technical tools such as firewalls, Endpoint Detection and Response (EDR), and Security Information and Event Management (SIEM) platforms are only as strong as the people operating and using them. This assessment dedicates an entire domain to measuring human behaviour, accountability, and security awareness maturity.

01

Awareness Training Cadence

Assess whether staff receive relevant, up-to-date training aligned to current threat vectors.

02

Accountability Structures

Determine whether security ownership is distributed across business units and not siloed in IT.

03

Leadership Tone at the Top

Measure whether board and executive behaviour models the security culture expected of all staff.

Is This For You?

Built for South African Organisations That Have Something to Protect

This assessment is designed for all organisations, including those operating in regulated or high-stakes environments where a governance failure is not just a technical problem but a board-level liability.

Financial Services & Banking

Regulated by SARB, FSCA, and POPIA. High-value targets for ransomware, fraud, and data exfiltration, carrying direct reputational and regulatory exposure.

Healthcare & Medical Groups

Patient records are among the most sensitive data categories under POPIA. Breaches carry severe regulatory consequences and immediate trust damage with patients and partners.

Legal & Professional Services

Law firms, auditors, and consultancies hold confidential client data under strict professional privilege. A single breach can end client relationships and trigger disciplinary proceedings.

Government & Public Entities

SOEs and municipalities face increasing cyber threat from both criminal actors and state-sponsored groups, with limited internal security capacity and high public accountability.

Energy, Mining & Infrastructure

Critical infrastructure operators face OT/IT convergence risks and are prime targets for disruption. Operational downtime translates directly to revenue loss and national security implications.

Retail, Insurance & E-Commerce

High transaction volumes, card data, and customer PII create broad attack surfaces. Compliance with PCI-DSS and POPIA requires demonstrable controls and board-level governance accountability.

The Investment Case

Cost-effective governance rigour

90×

At R4.5M average breach cost, this assessment represents less than 1% of the liability it helps you prevent

King IV

Demonstrates board-level due diligence on cyber risk, a direct fiduciary requirement under King IV governance principles

The discovery session is not a sales call. It is a structured working conversation where we map your organisation's current maturity position across the 14 domains, informed by your sector, size, existing documentation, and stakeholder input. You leave with a clearer picture of your risk landscape and a sense of where to focus first.

Book Your Session

Free Discovery Call

No commitment. No sales pressure.

Email to Book Now Call +27 69 676 3644
No commitment required after the session
Confidentiality assured. NDA available on request
B-BBEE Level 1, supports your procurement scorecard
Available in-person (Gauteng) or virtual

Or visit us at

www.lebonemarang.co.za