
Takeaways
Cybersecurity & POPIA
- MFA and EDR as the baseline
- FortiGate SOC watching the edge
- POPIA evidence you can show
- A playbook before you need it
What's included
- Security baseline assessment
- Endpoint detection and response deployment
- Identity hardening (MFA, privileged access)
- FortiGate and network security operations
- Security awareness and phishing simulations
- POPIA-oriented policy and control evidence packs
Cybersecurity included: Security baseline assessment; Endpoint detection and response deployment; Identity hardening (MFA, privileged access); FortiGate and network security operations; Security awareness and phishing simulations; POPIA-oriented policy and control evidence packs
1Security baseline assessment
2Endpoint detection and response deployment
3Identity hardening (MFA, privileged access)
4FortiGate and network security operations
5Security awareness and phishing simulations
6POPIA-oriented policy and control evidence packs
Antivirus-only or layered defence
Antivirus only
- One product, no one watching after hours.
- Admin passwords shared in a spreadsheet.
- No evidence when the insurer or Regulator asks.
Layered defence
- Endpoint, identity, firewall and mailbox controls.
- SOC alerts triaged in minutes.
- Logs, backups and incident notes ready.
Indicative scope
Cybersecurity services calculator
Choose the estate and extras that match how you need to be protected. We confirm monthly ZAR pricing after a short call.
Your brief
Scope summary
Indicative only — we'll confirm after a short call.
Cybersecurity scope (indicative — not a quote) Service: Cybersecurity & POPIA Users / endpoints: 15 Servers: 2 Sites / offices: 1 Email mailboxes: 15 Optional extras: - EDR / endpoint protection - MFA and privileged access - FortiGate firewall / UTM - FortiGate SOC / alerting - Microsoft 365 security This is an indicative scope. Monthly ZAR pricing is confirmed after a short call.
Protect your business from the inside out.
We secure endpoints, Microsoft 365 and your network with layered protection including EDR, MFA, privileged access controls and FortiGate firewalls, with SOC services where they add value. We also help your team become part of the defence through phishing awareness and simulations. If an incident happens, a documented response plan is already in place — from containment and recovery to preserving evidence and supporting the required reporting.
Practical security with predictable costs and local expertise.
One monthly ZAR fee gives you a layered security solution without the complexity of managing multiple dollar-based tools and hoping someone is monitoring them. We provide security reporting and evidence that can support your board, insurers and assessments, while keeping legal advice with your appointed counsel. Our Centurion-based SOC and engineering team provides support in SAST, with on-site assistance when required and clear monthly reporting on your security posture.
SLA
| Metric | Commitment |
|---|---|
| Critical security alert triage | Within 15 minutes |
| High-severity incident response | Within 1 hour |
| Vulnerability remediation (critical) | Within 7 days |
| Monthly security reporting | Included |
| Awareness campaign cadence | Quarterly typical |
| Policy review cycle | Annual or after major change |
Frequently asked questions
Straight answers for decision-makers evaluating IT partners in South Africa.
How does NovaCloud Africa support POPIA compliance?
We implement and operate technical measures such as access control, encryption, logging, backups and incident processes, and assist with documentation that supports Responsible Party obligations. Legal advice remains with your counsel.
Do you provide SOC monitoring?
Yes. We expand security with FortiGate SOC capability for advanced threat detection, real-time monitoring and rapid response.
Can you harden Microsoft 365 tenants?
Yes. We implement MFA, conditional access patterns, privileged access controls, secure baselines and mailbox protection.
What happens if we experience a cyber incident?
We follow an agreed incident response playbook: contain, eradicate, recover, preserve evidence where required, and support post-incident reporting.