Frequently Asked Questions
Why is cybersecurity considered a business risk?
Cyber incidents can disrupt operations, damage reputation and impact revenue. Many global risk reports, including the Allianz Risk Barometer 2025, now rank cyber threats alongside the most serious risks facing businesses today. Treating cybersecurity as a business risk helps protect what keeps your business running.
What cybersecurity frameworks do you work with?
We align our services with internationally recognised frameworks including the NIST Cybersecurity Framework (CSF) 2.0. For South African FSPs we also address the requirements of Joint Standard 1 of 2023 and Joint Standard 2 of 2024 to support full compliance.
Can you help us prepare for a regulatory audit or assessment?
Yes. We assess your current posture, identify gaps and provide documentation and support to help you meet regulatory requirements. This includes preparation for audits under Joint Standards and alignment with risk-based controls and governance best practices.
How do I know which services my business actually needs?
If you’re not sure where to begin, let’s start with an obligation-free coffee or meeting. We take time to understand what you’re facing, what matters most to your business and how we can support you as a trusted advisor.
What is NIST Cybersecurity Framework 2.0?
NIST CSF 2.0 is an internationally recognised framework that helps businesses manage cybersecurity risk. It provides a structured way to govern, identify, protect, detect, respond to and recover from cyber threats with a strong focus on aligning security to business goals, operations and risk.
Why does NIST CSF 2.0 matter to my business?
It helps you take a proactive, structured approach to cybersecurity. By following the NIST CSF 2.0, your business can better prioritise risks, strengthen resilience and show stakeholders that you’re serious about protecting what matters most.
What is Joint Standard 1 of 2023?
Joint Standard 1 is a South African regulatory requirement that sets out how financial institutions must govern and manage IT risk. It focuses on IT governance, oversight, third-party risk, and ensuring that cybersecurity and IT systems are aligned with the business’s risk profile.
What is Joint Standard 2 of 2024?
Joint Standard 2 focuses on cybersecurity and cyber resilience. It requires financial institutions to implement controls, response plans, staff awareness and recovery capabilities to withstand and respond to cyber incidents effectively.
Why are Joint Standards 1 and 2 important?
They are mandatory for South African financial service providers. These standards ensure that your IT and cybersecurity practices are not just technically sound, but properly governed, risk-aligned and resilient. By having them in place it reduces exposure to operational disruptions and regulatory penalties.
We already have an IT service provider or MSP; do we still need this?
Yes. Most MSPs [Managed Service Providers] focus on technical support and day-to-day operations. Our services go deeper, addressing business risk, regulatory compliance, governance and strategic alignment. We work alongside your MSP or internal IT team to close the gaps that aren’t typically covered. If you don’t have an MSP, we can guide you in the right direction and recommend trusted service providers we’ve worked with before.
Can small businesses use the NIST Cybersecurity Framework?
Yes. NIST CSF 2.0 is designed to be flexible and applies to businesses of all sizes, across all industries. Whether you’re a small business or a large enterprise, the framework helps you understand your cyber risk, prioritise security actions and build resilience in a structured way. It can be scaled to fit your resources, systems, and business goals, making it just as relevant for small teams as it is for global organisations.