Home
Smart DMS KBS Academy Personnel login Talk to us
Capability 04

Cybersecurity & ICT governance

Protect the estate, and demonstrate that it is protected. Patch posture, access changes and incident history documented in the form an auditor expects to receive them — because in the public sector, an undocumented control is an absent control.

The problem we are engaged to solve

The posture before it is tested

The perimeter is assumed

Firewall rules accumulate over years without review, and nobody can say which are still required.

Patch posture is unknown

Servers, endpoints and network devices drift out of currency with no visibility of the exposure.

Incidents leave no evidence

A breach is handled informally, and the organisation cannot demonstrate what was done or when.

Capability

Defence you can evidence

Perimeter & secure access

Firewall alignment and rule review, network access control, secure remote access and segmentation to contain lateral movement.

Monitoring & response

Security monitoring, alert triage, incident response and post-incident review that informs configuration standards.

Vulnerability & patch posture

Vulnerability visibility and patch discipline across servers, endpoints and network devices — with evidence retained.

Identity & access governance

Role-based access aligned to the post rather than the person, with joiner, mover and leaver discipline.

Security awareness

Instruction for employees, since the preponderance of public-sector incidents still originates with a person rather than a protocol.

ICT governance advisory

ITIL 4 and COBIT 2019 alignment, POPIA-aligned data handling and policy development.

The discipline

Security advanced control by control

The sequence below is instantiated within our ISO 9001:2015 quality management system. Work does not advance until the preceding stage is evidenced, and each gate produces a document the client retains.

1
Baseline
Posture baseline report
Current-state posture assessment across perimeter, endpoint, identity and patch currency.
2
Harden
Change register
Rule review, segmentation, access control and configuration standards applied and recorded.
3
Monitor
Alert and incident log
Security monitoring and alert triage with defined escalation to the client’s delegated official.
4
Respond
Incident evidence pack
Structured incident response with containment, eradication, recovery and a written post-incident review.
5
Attest
Governance report
Periodic reporting on posture, patch currency and access conformance for audit and governance forums.
Enterprise-grade by construction

Assurance an auditor accepts

9001
Certified quality system governing the work
27001
Aligned information security management system
POPIA
Data handling alignment across every engagement
4
Vendor ecosystems supported in the security stack
Standards and frameworks applied ISO/IEC 27001 aligned ISMS POPIA ITIL 4 · COBIT 2019 Fortinet · Sophos · Kaspersky · Veeam PFMA and MFMA compliance context
Outcome

What a defensible posture changes

Exposure becomes measurable
Patch currency and vulnerability position are reported rather than assumed.
Access follows the post
Joiner, mover and leaver discipline removes the orphaned account problem.
Security is evidenced
Posture, access changes and incident history documented for audit.
Where it applies
National governmentDepartments, regulators and state-owned entities
Provincial governmentHealth, social development, agriculture and transport
Local governmentMetropolitan and local municipalities
Water & utilitiesWater boards and energy sector entities
Public healthAcademic, district and specialised hospitals
EnterprisePrivate-sector organisations with public-sector-grade governance needs

Invite us to examine the posture before an adversary does.

An honest assessment of the estate as it stands, a prioritised remediation plan — and no theatre about threats you do not face.