100% Black Female-OwnedSouth Africa FocusedGauteng Based
Live Diagnostic Preview
67%
Defined
Sample Cyber Maturity Score
Current State: Defined
Use the slider to explore the five maturity levels and see what each stage looks like for your organisation.
Ad HocDevelopingDefinedManagedOptimized
Sample Domain Scores
Identity & Access72%
Network Security58%
Data Security45%
Security Culture32%
Compliance Mgmt65%
Physical Security80%
Why This Matters Now
The threat landscape has never been more complex or more costly.
This diagnostic is built for board-level visibility, legal exposure reduction, and operational resilience across organisations of all sizes.
Average Incident Timeline
Day 0
Breach occurs
Day 12
Avg. internal detection
Day 72hrs
POPIA notify deadline
Day 200+
Full containment avg.
Top Global Risk
Protiviti 2026
Cybersecurity failure ranks among the top five global risks, above natural disasters, economic crises, and supply chain disruption. For South African organisations, the risk is amplified by skills shortages and inconsistent governance.
Board Oversight Gap
Governance & Fiduciary Duty
68% of boards report insufficient understanding of their own cyber risk posture. Without structured visibility, directors cannot fulfill their legal duty of care, exposing the organisation to both regulatory and shareholder action.
Unseen Vulnerabilities
People, Process & Technology
Critical gaps are rarely in technology alone. Shadow IT, unreviewed vendor access, inconsistent patch cycles, and unmonitored privileged accounts create exposure that no firewall can fix. Only a structured assessment can surface these risks.
Penalty & Litigation Risk
Protection of Personal Information Act (POPIA) & Regulatory Exposure
South Africa's Protection of Personal Information Act (POPIA) carries fines up to R10 million and up to 10 years imprisonment for responsible parties. Poor incident preparedness, combined with a failure to notify within 72 hours, significantly amplifies legal and reputational liability.
Where Do You Stand?
5-Level Cybersecurity Maturity Model
Every organisation sits somewhere on this spectrum. The assessment identifies your precise position and charts the practical path forward.
12345
01
Ad Hoc
Reactive, fire-fighting posture. Controls are informal or nonexistent. Security decisions depend on individuals rather than process.
• No documented policies
• Incidents handled ad hoc
• No board visibility
02
Developing
Some controls exist but are siloed, poorly communicated, and inconsistently applied across teams or business units.
• Fragmented documentation
• Uncoordinated response
• Limited metrics
Industry Avg.
03
Defined
Documented policies and repeatable practices exist. Teams understand their responsibilities but measurement and optimisation are still developing.
• Documented controls
• Regular review cycles
• Some KPI tracking
04
Managed
Metrics and leadership oversight actively drive security decisions. Performance is tracked, reported upward, and used to improve posture.
• Board reporting in place
• KPI/KRI dashboards
• Proactive risk review
05
Optimised
Continuous improvement is embedded. Threat intelligence feeds into proactive control updates. Security culture is a competitive advantage.
• Threat intel integration
• Continuous improvement
• Security as culture
Full Coverage
Assessment Scope
14 domains spanning governance, operations, and technical security, covering every critical layer of your organisation's cyber posture, assessed and scored.
Governance & Policy
Operations & Process
Technical Controls
Sample radar, illustrative only
Auditing
Evaluates the effectiveness of security control reviews and the frequency, independence, and rigour of audit processes across the organisation.
Compliance Management
Assesses alignment with POPIA, ISO 27001, NIST, and applicable sector regulations. Identifies compliance gaps and enforcement accountability.
Policy & Process Governance
Reviews policy maturity, enforceability, staff awareness, and whether documented processes are operationally adopted or merely exist on paper.
Event & Incident Management
Assesses readiness to detect, contain, and recover from security incidents, including playbook quality, escalation paths, and post-incident learning.
Risk Analysis
Translates raw risk data into prioritised business decisions. Evaluates risk register quality, likelihood/impact assessment, and executive risk reporting.
Security Culture
Measures staff awareness, training cadence, accountability structures, and whether leadership behaviour models the security posture expected organisation-wide.
Vulnerability Management
Assesses the identification, prioritisation, and remediation of technical weaknesses, including scan frequency, patch service level agreements (SLAs), and exception handling.
Servers
Reviews server hardening standards, privileged access controls, patch compliance, logging, and monitoring across on-premise and cloud infrastructure.
End User Devices
Evaluates endpoint security controls including mobile device management (MDM), encryption, Bring Your Own Device (BYOD) policy, antivirus coverage, and device lifecycle management practices.
Identity & Access Management
Validates user provisioning, multi-factor authentication (MFA) adoption, privileged account governance, access reviews, and offboarding processes across all systems.
Data Security
Assesses data classification, encryption at rest and in transit, data loss prevention (DLP) controls, data retention compliance, and handling of sensitive personal information under POPIA.
Applications
Evaluates secure development practices, third-party application governance, patch management for business software, and application access controls.
Assesses physical access controls, visitor management, server room security, clean desk policies, and asset disposal procedures protecting people and infrastructure.
⚠ Governance & Legal Exposure
Boards Are Failing Their Fiduciary Cyber Duties
Most boards have limited cybersecurity knowledge and lack the visibility required to govern digital risk effectively, creating direct legal and financial exposure.
Regulatory Reality
South Africa's Protection of Personal Information Act (POPIA) and related data protection legislation carry penalties up to R10 million and imprisonment of up to 10 years for data protection failures linked to poor cyber governance.
68%
of boards report insufficient understanding of their organisation's cyber risk posture
R4.5M+
average cost of a data breach in South Africa, not counting reputational damage and litigation
72hrs
regulatory window to notify authorities of a breach. Most organisations lack the incident readiness to respond in time
3×
organisations with active, effective governance frameworks are three times less likely to suffer a material incident
How It Works
3-Stage Transformation Roadmap
From raw stakeholder insight to a boardroom-ready governance strategy, in three deliberate stages.
01
Stakeholder Insight
We capture what your leadership team and IT staff actually believe about security, surfacing blind spots that surveys and audits miss.
→ Structured interviews & workshops
→ Multi-stakeholder perspective mapping
→ Governance perception vs. reality gap analysis
02
Data-Driven Prioritisation
Stakeholder input is converted into structured maturity scores across all 14 domains, ranked by risk severity and business impact.
→ Domain-level scoring framework
→ Risk impact & likelihood matrix
→ Executive-ready data visualisation
03
Strategic Resilience
A practical governance roadmap aligned to industry best practices, giving your board and leadership team a clear path forward.
→ ISO 27001 & NIST framework alignment
→ Phased improvement roadmap
→ KPI/KRI monitoring framework
Outputs & Deliverables
What Your Organisation Receives
Three structured outputs designed for both boardroom presentation and operational execution.
Maturity Scorecard
A boardroom-ready summary of your organisation's current cybersecurity standing, benchmarked against industry best practice and the 5-level maturity model.
✓ Overall maturity level (1–5)
✓ Benchmark vs. sector peers
✓ Executive summary narrative
Primary Output
Prioritised Risk Roadmap
A ranked action plan guiding immediate and medium-term security improvements, ordered by business impact, feasibility, and governance urgency.
✓ Risk ranked by severity
✓ Quick wins vs. strategic initiatives
✓ Owner & timeline recommendations
Domain Deep-Dive Report
Granular scores and findings across all 14 assessment domains, with specific attention to Governance, Policy & Process, and Identity & Access Management.
✓ Score per domain (1–5)
✓ Finding narrative per domain
✓ Recommended next actions
Industry Alert
32%
of IT staff regularly receive security awareness training
That means more than two-thirds of your team is operating without current cyber hygiene knowledge, regardless of how strong your technical controls are.
82%
of breaches involve a human element (phishing, credential misuse, error)
5×
return on investment for structured security awareness programs
Security Culture Domain
Security Culture: Your Biggest Vulnerability
Technical tools such as firewalls, Endpoint Detection and Response (EDR), and Security Information and Event Management (SIEM) platforms are only as strong as the people operating and using them. This assessment dedicates an entire domain to measuring human behaviour, accountability, and security awareness maturity.
01
Awareness Training Cadence
Assess whether staff receive relevant, up-to-date training aligned to current threat vectors.
02
Accountability Structures
Determine whether security ownership is distributed across business units and not siloed in IT.
03
Leadership Tone at the Top
Measure whether board and executive behaviour models the security culture expected of all staff.
Is This For You?
Built for South African Organisations That Have Something to Protect
This assessment is designed for all organisations, including those operating in regulated or high-stakes environments where a governance failure is not just a technical problem but a board-level liability.
Financial Services & Banking
Regulated by SARB, FSCA, and POPIA. High-value targets for ransomware, fraud, and data exfiltration, carrying direct reputational and regulatory exposure.
Healthcare & Medical Groups
Patient records are among the most sensitive data categories under POPIA. Breaches carry severe regulatory consequences and immediate trust damage with patients and partners.
Legal & Professional Services
Law firms, auditors, and consultancies hold confidential client data under strict professional privilege. A single breach can end client relationships and trigger disciplinary proceedings.
Government & Public Entities
SOEs and municipalities face increasing cyber threat from both criminal actors and state-sponsored groups, with limited internal security capacity and high public accountability.
Energy, Mining & Infrastructure
Critical infrastructure operators face OT/IT convergence risks and are prime targets for disruption. Operational downtime translates directly to revenue loss and national security implications.
Retail, Insurance & E-Commerce
High transaction volumes, card data, and customer PII create broad attack surfaces. Compliance with PCI-DSS and POPIA requires demonstrable controls and board-level governance accountability.
The Investment Case
Cost-effective governance rigour
90×
At R4.5M average breach cost, this assessment represents less than 1% of the liability it helps you prevent
King IV
Demonstrates board-level due diligence on cyber risk, a direct fiduciary requirement under King IV governance principles
The discovery session is not a sales call. It is a structured working conversation where we map your organisation's current maturity position across the 14 domains, informed by your sector, size, existing documentation, and stakeholder input. You leave with a clearer picture of your risk landscape and a sense of where to focus first.