The perimeter is assumed
Firewall rules accumulate over years without review, and nobody can say which are still required.
Protect the estate, and demonstrate that it is protected. Patch posture, access changes and incident history documented in the form an auditor expects to receive them — because in the public sector, an undocumented control is an absent control.
Firewall rules accumulate over years without review, and nobody can say which are still required.
Servers, endpoints and network devices drift out of currency with no visibility of the exposure.
A breach is handled informally, and the organisation cannot demonstrate what was done or when.
Firewall alignment and rule review, network access control, secure remote access and segmentation to contain lateral movement.
Security monitoring, alert triage, incident response and post-incident review that informs configuration standards.
Vulnerability visibility and patch discipline across servers, endpoints and network devices — with evidence retained.
Role-based access aligned to the post rather than the person, with joiner, mover and leaver discipline.
Instruction for employees, since the preponderance of public-sector incidents still originates with a person rather than a protocol.
ITIL 4 and COBIT 2019 alignment, POPIA-aligned data handling and policy development.
The sequence below is instantiated within our ISO 9001:2015 quality management system. Work does not advance until the preceding stage is evidenced, and each gate produces a document the client retains.
An honest assessment of the estate as it stands, a prioritised remediation plan — and no theatre about threats you do not face.