Regulators, threat actors and legacy risk look different in every sector. We bring the South African specifics: the laws, the auditors and the attack patterns that actually apply to your industry.
Each engagement is tuned to your regulatory reality and the threats your peers are actually facing.
Banks, insurers, asset managers and fintechs, both JSE-listed and privately held.
Payment fraud and card-data exposure, open-banking and third-party fintech risk, and being a high-value target for organised financially-motivated actors.
Power, energy and water utilities operating critical national infrastructure.
Operational technology (OT/SCADA) exposure across generation and distribution, continuity of essential water and power services, and ITGCs over billing and SAP environments.
Government departments, municipalities and state-owned entities.
Disruption of citizen-facing services, exposure of large volumes of personal data, and audit findings from the Auditor-General on IT controls and governance.
Airlines, airports and transport operators running safety-critical systems.
Availability of safety- and operations-critical systems, complex third-party and interface dependencies, and ITGCs over reservations, scheduling and SAP environments.
Mining houses and resource operators with distributed sites.
Operational technology (OT/SCADA) exposure at remote sites, safety-critical system availability, and theft of exploration and geological IP.
Universities, colleges and education bodies with large student data estates.
Protection of large volumes of student and staff personal data, availability of teaching and research systems, and ITGCs over student-information and finance systems.
Tell us your industry and regulatory footprint. We’ll bring the specifics, and a right-sized plan to match.