Cyber security is no longer only an information technology concern. It is a business continuity, financial management, legal compliance and reputation-management responsibility. A successful attack can interrupt operations, expose confidential information, prevent staff from working and damage customer trust.
This guide provides a practical security framework for South African organisations. It explains the controls businesses should implement across users, identities, devices, networks, email, cloud services, backups and incident response.
The objective is not to eliminate every possible risk. No organisation can guarantee that it will never experience a security incident. The objective is to reduce the likelihood of an attack, detect suspicious activity early, limit the impact and restore operations quickly.
What is business cyber security?
Business cyber security is the combination of people, policies, processes and technologies used to protect an organisation's systems, networks, applications and information.
A useful starting point is the confidentiality, integrity and availability model. Confidentiality means information is only available to authorised people. Integrity means information remains accurate and is not changed without authorisation. Availability means systems and information remain accessible when the business needs them.
Security must therefore protect more than files. It must protect business operations, communications, financial systems, customer records, employee information, intellectual property and the technology used to provide services.
- Protect confidential business and customer information.
- Prevent unauthorised changes to systems and data.
- Keep critical services available during disruption.
- Detect suspicious activity before it becomes a major incident.
- Support legal, contractual and regulatory obligations.
Why businesses are targeted
Attackers often target businesses because they process payments, store valuable information, operate email accounts and depend on technology to function. Smaller organisations are not ignored. They may be targeted because they have fewer dedicated security resources or because they provide access to larger customers.
Many attacks are automated. Criminals continuously scan the internet for exposed services, weak passwords, outdated software and misconfigured websites. An organisation does not need to be personally selected before it is attacked.
- Weak or reused passwords.
- Unprotected remote-access services.
- Outdated operating systems and applications.
- Employees who have not received security-awareness training.
- Poorly configured cloud services.
- Backups connected permanently to the production environment.
- Excessive administrator privileges.
Common cyber threats facing organisations
The threat landscape includes both technically sophisticated attacks and simple attempts to manipulate employees. Businesses must prepare for several attack methods rather than relying on a single security product.
| Threat | How it works | Possible business impact |
|---|---|---|
| Phishing | Fraudulent messages persuade users to disclose credentials, open attachments or approve payments. | Account compromise, malware infection and financial fraud. |
| Ransomware | Malicious software encrypts files or systems and demands payment. | Operational shutdown, data loss, recovery costs and reputational damage. |
| Business email compromise | An attacker impersonates or takes control of a trusted email account. | Fraudulent payments, altered banking details and information theft. |
| Credential attacks | Stolen, guessed or reused passwords are used to access business services. | Unauthorised access to email, cloud systems and sensitive information. |
| Insider threats | Employees or contractors misuse legitimate access deliberately or accidentally. | Data leakage, fraud, system damage or compliance failures. |
| Distributed denial of service | Large volumes of traffic are directed at an online service. | Website, application or network unavailability. |
Adopt a defence-in-depth strategy
Defence in depth means using several complementary security controls. When one control fails, another control should still prevent, detect or limit the attack.
For example, an employee may enter a password into a fraudulent website. Multi-factor authentication may prevent the attacker from signing in. Conditional-access policies may block the sign-in because it originates from an unusual location. Security monitoring may then alert administrators to investigate the attempt.
- Governance, policies and assigned responsibility.
- Identity and access management.
- Firewall and network segmentation.
- Endpoint protection and device management.
- Email and collaboration security.
- Application and cloud security.
- Backups and disaster recovery.
- Logging, monitoring and incident response.
- Employee awareness and ongoing training.
Establish cyber security governance
Security controls are more effective when ownership is clearly defined. Management should approve security policies, determine acceptable risk and ensure that corrective actions receive the necessary resources.
Every organisation should maintain an inventory of important systems, data, applications, suppliers and administrators. It is difficult to protect assets that the business has not identified.
- Assign responsibility for cyber security.
- Maintain hardware, software and cloud-service inventories.
- Classify sensitive and business-critical information.
- Document acceptable-use and access-control policies.
- Assess suppliers that process or access company information.
- Review security risks at least annually and after major changes.
Protect identities and user accounts
Identity has become one of the most important security boundaries. Employees access email, applications and company information from offices, homes, mobile phones and cloud platforms. A stolen account can therefore give an attacker access from almost anywhere.
Access should follow the principle of least privilege. Users should receive only the permissions required for their responsibilities, and those permissions should be reviewed when roles change.
- Require multi-factor authentication for all supported services.
- Use separate named administrator accounts.
- Disable accounts promptly when employees leave.
- Review privileged and shared accounts regularly.
- Use password managers instead of spreadsheets or browser notes.
- Apply conditional access where available.
- Block legacy authentication protocols.
Implement strong password practices
Passwords remain necessary for many systems, but password security should not depend on users remembering many complex strings. Long, unique passphrases stored in an approved password manager are generally more practical than short passwords changed frequently.
Businesses should prevent password reuse, protect administrator credentials and investigate credentials that appear in known data breaches.
- Use unique passwords for every service.
- Prefer long passphrases.
- Protect password-manager accounts with multi-factor authentication.
- Never share passwords through ordinary email or messaging.
- Change passwords immediately when compromise is suspected.
- Do not use one shared administrator password across devices.
Secure business networks
Network security controls traffic between the internet, offices, servers, workstations, wireless devices and cloud systems. A flat network allows an attacker who compromises one device to move more easily to other systems.
Network segmentation separates systems according to business function and risk. Servers, guest Wi-Fi, telephones, cameras, administrative devices and ordinary user workstations should not automatically share unrestricted access.
- Use a properly configured firewall-services.html">business firewall.
- Separate guest and internal wireless networks.
- Use VLANs to isolate systems and device types.
- Disable unused switch ports and services.
- Use secure VPN access for remote administration.
- Monitor internet links and important network devices.
- Change default passwords on routers, switches and access points.
Deploy and manage business firewalls
A firewall-services.html">business firewall controls traffic entering and leaving the network. Modern next-generation firewalls may also provide intrusion prevention, web filtering, application control, malware inspection and secure remote-access services.
A firewall is not effective simply because it is installed. Rules, firmware, subscriptions, administrator access, VPN configuration and security logs must be reviewed and maintained.
For a more detailed explanation, read the firewall-services.html">Business Firewall Guide in the Hozit Knowledge Centre.
- Allow only services that the business requires.
- Remove obsolete firewall rules.
- Restrict management interfaces to trusted sources.
- Enable security updates and threat-intelligence services.
- Back up the configuration after approved changes.
- Review blocked and suspicious traffic.
Protect endpoints and mobile devices
Endpoints include desktops, laptops, servers, tablets and mobile phones. These devices regularly process email, documents, customer information and authentication tokens.
Endpoint detection and response tools provide greater visibility than traditional antivirus by monitoring suspicious behaviour and supporting investigation and containment.
- Install centrally managed endpoint protection.
- Apply operating-system and application updates.
- Encrypt laptops and portable devices.
- Remove local administrator access where unnecessary.
- Control removable storage and unauthorised software.
- Use mobile-device management for business-owned mobile devices.
- Automatically lock inactive devices.
Improve email security
Email is a primary attack route because it combines technical vulnerabilities with human decision-making. Attackers impersonate executives, suppliers, customers and financial institutions.
Technical controls should be combined with procedures for verifying payment instructions, banking-detail changes and unusual requests.
- Configure SPF, DKIM and DMARC for company domains.
- Use anti-phishing and attachment-scanning controls.
- Block automatic forwarding to external addresses unless approved.
- Require independent verification of banking-detail changes.
- Display warnings on messages received from outside the organisation.
- Train employees to report suspicious messages.
Strengthen Microsoft 365 security
Microsoft 365 stores business email, files, collaboration data and identity information. Default settings may not be sufficient for every organisation, particularly where sensitive information or privileged accounts are involved.
Microsoft 365 security should include identity protection, email security, device management, data-loss controls, auditing and backup.
- Enable multi-factor authentication.
- Use Microsoft Entra ID security and conditional-access features.
- Review administrator roles.
- Configure Defender policies where licensed.
- Protect SharePoint and OneDrive sharing.
- Audit mailbox forwarding and inbox rules.
- Retain appropriate audit logs.
- Use an independent backup where required by business risk.
Secure cloud services and applications
Cloud providers secure their underlying infrastructure, but customers remain responsible for users, permissions, configurations, data and many application-level controls. This is commonly described as the shared-responsibility model.
Cloud environments should be configured using least privilege, encryption, logging and controlled administrative access.
- Maintain an inventory of approved cloud services.
- Remove abandoned resources and unused accounts.
- Restrict public storage and database exposure.
- Protect API keys and administrative credentials.
- Enable audit logging and security alerts.
- Encrypt sensitive information in transit and at rest.
- Review third-party application permissions.
Use secure backup practices
Backups provide the final recovery option when production systems are encrypted, deleted, corrupted or unavailable. Attackers frequently attempt to destroy backups before deploying ransomware.
The 3-2-1 principle recommends three copies of important information, stored on two types of media, with at least one copy held separately from the production environment.
- Back up critical servers, databases, applications and cloud data.
- Use offline, isolated or immutable backup copies.
- Encrypt backup data.
- Protect backup consoles with multi-factor authentication.
- Monitor backup failures.
- Test file and system restoration regularly.
- Document who may delete or alter backups.
Plan for disaster recovery and business continuity
Disaster recovery restores technology after a serious disruption. Business continuity determines how essential operations continue while systems, offices, suppliers or communications are unavailable.
The recovery time objective defines how quickly a service should be restored. The recovery point objective defines how much recent data the organisation can tolerate losing.
- Identify critical business processes and systems.
- Define recovery priorities.
- Document recovery time and recovery point objectives.
- Assign recovery responsibilities.
- Maintain supplier and escalation contacts.
- Test recovery procedures rather than relying only on written plans.
Prepare an incident-response plan
An incident-response plan helps the organisation make controlled decisions during a security event. Without a plan, employees may destroy evidence, communicate inconsistently or delay containment.
The plan should define how incidents are reported, who has authority to isolate systems, when legal or regulatory advice is required and how customers or affected parties will be informed.
- Preparation.
- Detection and analysis.
- Containment.
- Eradication.
- Recovery.
- Post-incident review and improvement.
Support POPIA security obligations
The Protection of Personal Information Act requires responsible parties to implement appropriate technical and organisational measures to protect personal information. Security measures should be proportionate to the information, threats and potential harm.
Cyber security does not by itself guarantee POPIA compliance, but weak access control, inadequate monitoring, unprotected devices and poor incident management can create serious compliance risks.
- Know what personal information the organisation processes.
- Limit access according to business need.
- Protect information during storage and transmission.
- Control retention and secure disposal.
- Assess operators and service providers.
- Maintain incident and breach-response procedures.
- Keep evidence of security reviews and corrective actions.
Train employees and build security awareness
Employees are an important security control when they understand common threats and know how to report concerns. Training should be practical, relevant to each role and reinforced throughout the year.
Phishing simulations can help measure awareness, but they should be used to improve behaviour rather than embarrass employees.
- Recognising phishing and impersonation.
- Protecting passwords and authentication prompts.
- Verifying payment and banking instructions.
- Handling confidential information.
- Securing remote-working environments.
- Reporting lost devices and suspicious activity.
Monitor systems and investigate alerts
Preventive controls cannot stop every incident. Organisations also need visibility into authentication events, endpoint activity, firewall traffic, email threats, server logs and cloud changes.
A security information and event management platform can collect and correlate logs. A security operations centre may provide ongoing monitoring, investigation and escalation.
- Collect logs from critical systems.
- Synchronise device time.
- Protect logs against unauthorised alteration.
- Define alert severity and escalation procedures.
- Investigate repeated failed logins and unusual administrator activity.
- Retain logs according to business and compliance requirements.
Manage third-party and supplier risk
Suppliers may host information, maintain systems, process payments or connect remotely to the company network. Their weaknesses can therefore become the organisation's weaknesses.
Security requirements should be considered before a supplier is appointed and reviewed during the relationship.
- Identify suppliers with access to sensitive information or systems.
- Define security responsibilities in agreements.
- Restrict and monitor supplier access.
- Require prompt incident notification.
- Remove access when contracts end.
- Review important suppliers periodically.
Build a practical cyber security roadmap
Most organisations cannot implement every control at once. A risk-based roadmap prioritises measures that reduce the greatest business risks first.
| Priority | Recommended actions |
|---|---|
| Immediate | Enable MFA, close exposed services, secure backups, patch critical vulnerabilities and remove obsolete accounts. |
| First 90 days | Review firewall rules, deploy managed endpoint protection, document assets, implement employee training and formalise incident reporting. |
| Three to six months | Introduce network segmentation, improve Microsoft 365 controls, test disaster recovery and complete vulnerability assessments. |
| Six to twelve months | Improve central logging, supplier assurance, data protection controls, penetration testing and executive security reporting. |
| Ongoing | Monitor, test, train, patch, review access and update the security roadmap as the business changes. |
Business cyber security implementation checklist
Use this checklist as a high-level starting point. The controls required by a specific organisation will depend on its services, information, contractual obligations, systems and risk profile.
- Security responsibility has been assigned.
- Hardware, software and cloud-service inventories are maintained.
- Multi-factor authentication is enabled.
- Administrator privileges are restricted.
- Business firewalls are configured and maintained.
- Endpoints use managed security protection.
- Critical patches are applied promptly.
- Email domains use SPF, DKIM and DMARC.
- Backups are isolated and restoration is tested.
- An incident-response plan is documented.
- Employees receive ongoing awareness training.
- Suppliers with system or data access are assessed.
- Security logs are collected and reviewed.
- Vulnerability assessments are completed periodically.
- Management receives security-risk reports.
How Hozit can support your organisation
Hozit Domain Hosting helps organisations assess, implement and manage practical cyber security controls. Support can be aligned with the organisation's size, technology environment, risk profile and operational priorities.
Services can include managed IT support, firewall implementation, Microsoft 365 security, endpoint protection, network security, vulnerability assessments, backup, disaster recovery and security planning.
- Cyber security assessments.
- firewall-services.html">Managed firewall services.
- Microsoft 365 security configuration.
- Endpoint protection and monitoring.
- Network segmentation and secure remote access.
- Backup and disaster-recovery solutions.
- Vulnerability assessment and remediation support.
- Managed IT support and security monitoring.