South Africa's cybersecurity constraints, stated plainly
Published 3 August 2026 · Editorial update 6 September 2026 · 2 min read · Enternovate

Security plans must fit the organisation that will operate them. For a small South African business, the limiting factor may be time, specialist support or the cost of maintaining another system. A tool that nobody owns is not an effective control.
Start with the basics that support the business: an asset inventory, multifactor authentication, protected backups, tested recovery and clear joiner-leaver processes. Prioritise based on the information and operations you cannot afford to lose.
Plan for power and connectivity interruptions without assuming any particular outage schedule. Keep response contacts and recovery instructions available offline. Test whether monitoring resumes correctly after a connection or machine returns.
Email impersonation, ransomware and exposed services deserve attention, but a universal threat ranking is not a substitute for a risk assessment. Confirm payment-detail changes through an independent channel and train staff to report suspicious activity early.
POPIA duties need accountable owners and evidence. Gavaza supports that work; Mhangani supports web audits, Nyarhi organises knowledge and Xavani coordinates approved actions. Open-source access reduces some barriers, but installation, interpretation and remediation still require care.
Enternovate brings software, automation, security and IT hardware supply into the same scoping conversation. Start with one concrete business problem, agree the deliverable and support terms, and verify the outcome before expanding the work.