Knowledge Hub

Cybersecurity FAQs and Cyber Resilience Guidance

Cybersecurity questions rarely exist in isolation.

A ransomware concern may uncover governance gaps. A supplier assessment may raise questions about POPIA. A security audit may expose identity-related weaknesses or incident-response challenges.

This FAQ hub answers the questions organisations most commonly ask about cyber resilience, digital forensics, governance, managed security, compliance, and operational readiness.

On This PAge

General Cybersecurity

How do we know if our business is actually vulnerable to cyberattacks?

Most organisations are more exposed than they realise. Vulnerability usually comes from a combination of outdated systems, weak passwords, excessive user permissions, poor visibility, untested backups, exposed internet services, or gaps in supplier security. The only reliable way to understand your actual exposure is through structured assessments, security testing, and ongoing monitoring — not assumptions.

Do small and medium-sized businesses really get targeted?

Yes. SMEs are frequently targeted because attackers know they often have fewer security controls, smaller IT teams, weaker monitoring, and less formal governance. Many attacks are opportunistic rather than highly targeted. Automated phishing campaigns, credential attacks, and ransomware operations regularly affect smaller businesses.

What are the biggest cybersecurity risks facing organisations right now?

The most common risks currently include:

  • ransomware and extortion
  • phishing and business email compromise
  • identity and credential theft
  • cloud misconfiguration
  • supplier and third-party exposure
  • insider threats
  • weak privileged access management
  • poor incident readiness
  • inadequate monitoring and visibility

What’s the difference between cybersecurity and cyber resilience?

Cybersecurity focuses on preventing attacks.

Cyber resilience focuses on helping the organisation continue operating during an incident.

Resilience includes prevention, detection, response, recovery, governance, communication, continuity planning, and operational readiness.

Can antivirus software alone protect a business?

No.

Traditional antivirus is only one layer. Modern attacks often bypass signature-based tools using stolen credentials, phishing, legitimate administrative tools, or social engineering.

Effective protection combines identity controls, endpoint detection, monitoring, backups, segmentation, user awareness, and tested incident response.

How often should cybersecurity assessments be performed?

At a minimum, organisations should perform annual formal assessments.

Higher-risk organisations often perform:

  • quarterly reviews
  • continuous vulnerability monitoring
  • periodic penetration testing
  • supplier reassessments
  • ongoing risk reviews

Security posture changes continuously as environments, users, suppliers, and threats evolve.

What are the first signs a business may have been breached?

Common indicators include:

  • unusual login activity
  • unexpected MFA prompts
  • suspicious outbound traffic
  • locked user accounts
  • abnormal admin account activity
  • strange email forwarding rules
  • ransomware notes
  • unusually slow systems
  • supplier payment fraud attempts


Many breaches are initially discovered by users noticing unusual behaviour rather than automated tooling.

What is a cyber risk assessment?

A cyber risk assessment identifies critical assets, evaluates threats and vulnerabilities, reviews existing controls, and prioritises risks based on operational and business impact.

A good assessment produces a treatment plan that the organisation can realistically execute.

Why are boards becoming more involved in cybersecurity?

Cyber incidents now create operational, legal, reputational, regulatory, and financial consequences.

Boards are increasingly expected to understand cyber risk in the same way they understand financial or operational risk.

Cybersecurity is no longer purely an IT issue.

What frameworks are commonly used in cybersecurity?

Common frameworks include:

  • ISO/IEC 27001
  • NIST Cybersecurity Framework
  • CIS Controls
  • ISO 27005
  • MITRE ATT&CK
  • PCI DSS
  • POPIA requirements

 

Different frameworks solve different problems, and many organisations use several together.

Is cloud infrastructure more secure than on-premise infrastructure?

Not automatically.

Cloud platforms can be highly secure when configured correctly, but poor identity management, exposed storage, weak permissions, and misconfigurations still create significant risk.

Security depends more on governance and architecture than location.

What is an attack surface?

An attack surface refers to all the systems, users, applications, cloud services, suppliers, devices, APIs, and internet-facing assets that attackers could potentially exploit.

Can a business ever become 100% secure?

No.

The goal is not perfection.

The goal is to reduce risk, improve visibility, detect incidents early, respond effectively, and recover quickly when incidents occur.

What does “security maturity” actually mean?

Security maturity refers to how consistently and effectively an organisation manages cyber risk.

Mature organisations usually have:

  • defined governance
  • operational visibility
  • tested processes
  • executive reporting
  • regular assessments
  • documented response capability
  • continuous improvement programmes

Cyber Risk Assessments & Audits

What’s the difference between a cyber risk assessment and a security audit?

A risk assessment evaluates threats, vulnerabilities, likelihood, and business impact.

A security audit evaluates whether controls align with a specific framework or requirement, such as ISO 27001, POPIA, or NIST.

What does a cybersecurity audit actually include?

A typical audit may review:

  • governance and policies
  • access management
  • backup and recovery
  • incident response readiness
  • logging and monitoring
  • endpoint protection
  • supplier security
  • awareness training
  • evidence of control operation

 

The scope depends on the framework and business requirements.

How often should security audits be performed?

Most organisations should conduct annual full audits, with targeted quarterly or semiannual reviews for higher-risk areas.

Will an audit disrupt day-to-day operations?

A properly managed audit should create minimal disruption.

Most evidence gathering, interviews, and documentation reviews can be coordinated around operational schedules.

What happens after an audit is completed?

The organisation should receive:

  • findings
  • risk ratings
  • remediation recommendations
  • prioritised actions
  • roadmap guidance
  • executive reporting

 

The value comes from remediation and operational improvement, not just the report itself.

What frameworks can audits align to?

Common frameworks include:

  • ISO 27001
  • NIST CSF
  • CIS Controls
  • POPIA
  • PCI DSS
  • customer contractual requirements
  • internal governance requirements

 

What are the most common audit findings?

Common findings include:

  • weak privileged access management
  • incomplete asset inventories
  • poor visibility and logging
  • weak supplier oversight
  • outdated policies
  • lack of evidence for controls
  • untested incident response plans
  • inconsistent user access reviews

Can audits help with cyber insurance?

Yes.

Insurers increasingly require evidence of:

  • MFA
  • backup maturity
  • incident readiness
  • monitoring capability
  • governance structures
  • operational controls

Do we need both vulnerability assessments and audits?

Usually yes.

Audits validate governance and control alignment.

Vulnerability assessments identify technical weaknesses.

They answer different but complementary questions.

What makes an audit “defensible”?

A defensible audit uses recognised frameworks, documented methodology, evidence-based findings, and clear traceability between observations and conclusions.

What is meant by “evidence-based assurance”?

Evidence-based assurance means controls are validated through actual operational evidence rather than assumptions or undocumented statements.

Can security audits support procurement or customer due diligence?

Yes.

Many customers, insurers, and enterprise procurement teams now expect organisations to demonstrate operational security capability through audits, governance documentation, and evidence of control maturity.

Managed Security Services

What is SOC as a Service?

SOC as a Service provides organisations with outsourced Security Operations Centre capability without requiring them to build and staff a SOC internally. It combines continuous security monitoring with analyst-led triage, investigation, threat detection, threat hunting, incident handling and reporting.

What's the difference between SOC as a Service and MDR?

SOC as a Service provides the broader operational capability of a Security Operations Centre, including continuous monitoring, analyst triage, investigation, threat hunting, threat intelligence, escalation and reporting. MDR focuses specifically on detecting, investigating and responding to threats and may form part of a broader SOC as a Service engagement.

Can a managed SOC work alongside our internal IT or security team?

Yes. A managed SOC can operate as an extension of an existing IT or security team. Responsibilities, escalation paths, incident-response playbooks, communication protocols and service levels are agreed during onboarding.

What are managed security services?

Managed security services provide outsourced cybersecurity monitoring, detection, management, and response capabilities.

This may include:

  • MDR
  • SOC monitoring
  • vulnerability management
  • phishing awareness
  • reporting
  • threat intelligence
  • vCISO advisory

What’s the difference between MSS and traditional IT support?

Traditional IT support focuses on operational technology issues.

Managed security services focus specifically on cyber risk, threat detection, incident response, and resilience.

What does MDR mean?

Managed Detection and Response combines continuous monitoring, threat detection, investigation, and response support to quickly identify and contain threats.

Do we need a 24/7 SOC?

Not every organisation needs to build and operate its own 24/7 SOC. However, organisations with significant operational, regulatory, or security exposure can benefit from continuous monitoring because threats don't operate only during office hours. SOC as a Service provides this capability without requiring an organisation to build the people, processes and technology internally.

Is outsourcing cybersecurity safe?

Yes — when the provider follows proper governance, access control, monitoring, contractual protections, and operational transparency.

What should we ask before choosing an MSS provider?

Important questions include:

  • What are the response SLAs?
  • What telemetry is monitored?
  • Who responds to incidents?
  • What reporting is provided?
  • How is onboarding handled?
  • What happens if we terminate the engagement?

Can MSS work alongside our internal IT team?

Absolutely.

Most MSS engagements operate collaboratively with existing IT or infrastructure teams.

Is MSS only for large enterprises?

No.

SMEs often benefit most because they cannot usually justify building an in-house SOC or a specialist security capability.

What reporting should we expect from MSS?

Good reporting should include:

  • incident trends
  • vulnerabilities
  • threat activity
  • remediation progress
  • executive summaries
  • operational metrics
  • risk visibility

Does MSS help with compliance?

Yes.

MSS helps provide evidence of operational security capability for POPIA, ISO 27001, customer due diligence, and cyber insurance requirements.

What is a vCISO?

A Virtual CISO provides strategic cybersecurity leadership without requiring a full-time executive appointment.

A vCISO may support:

  • governance
  • board reporting
  • roadmap planning
  • regulator engagement
  • policy oversight
  • risk management

How long does MSS onboarding usually take?

This depends on the size and complexity of the environment.

Most onboarding projects involve:

  • environment discovery
  • telemetry integration
  • alert tuning
  • baseline establishment
  • escalation planning
  • reporting configuration

Incident Response & Ransomware

We think we’ve been hacked. What should we do first?

Do not panic and do not start deleting evidence.

Isolate affected systems where possible, preserve logs and evidence, involve legal and incident response specialists early, and avoid making changes that could destroy forensic artefacts.

Should we shut systems down during a cyber incident?

Not always.

Immediate shutdown can destroy volatile evidence and complicate forensic investigation.

Response actions should be guided by incident responders and forensic specialists.

How quickly should incident response begin?

Immediately.

The first few hours of a breach often determine whether evidence is preserved, attackers are contained, and regulatory obligations can be met.

What is ransomware?

Ransomware is malicious software that encrypts systems or steals data in exchange for payment.

Modern ransomware frequently includes data exfiltration and extortion.

Should businesses pay ransomware demands?

There is no universal answer.

Payment does not guarantee recovery or deletion of stolen data.

Decisions should involve legal counsel, forensic specialists, insurers, executives, and operational leadership.

Can backups alone stop ransomware damage?

No.

Backups help recovery, but they do not solve:

  • data theft
  • reputational damage
  • operational disruption
  • regulatory exposure
  • extortion pressure

What is a tabletop exercise?

A tabletop exercise walks leadership teams through a simulated cyber incident to test:

  • decision-making
  • escalation
  • communication
  • operational readiness
  • continuity planning

How long does a forensic investigation usually take?

This depends on complexity, scope, the availability of evidence, and the systems involved.

Some investigations take days. Larger breaches may take weeks or months.

When does POPIA breach notification apply?

POPIA Section 22 applies when a security compromise is likely to result in unauthorised access to personal information.

Notification obligations should be assessed immediately during incident response.

What is business email compromise?

Business email compromise involves attackers impersonating executives, suppliers, or trusted parties to manipulate payments, invoices, or sensitive information.

Who should be involved during a major cyber incident?

A serious incident may involve:

  • IT
  • security teams
  • executives
  • legal counsel
  • communications
  • HR
  • forensic specialists
  • insurers
  • external responders

What is meant by “containment” during an incident?

Containment refers to actions taken to stop the spread of an attack while preserving evidence and minimising operational damage.

What’s the biggest mistake organisations make during incidents?

Common mistakes include:

  • deleting evidence
  • delaying escalation
  • poor communication
  • failing to preserve logs
  • unclear decision authority
  • involving legal counsel too late

Digital Forensics

What is digital forensics?

Digital forensics involves preserving, collecting, analysing, and presenting digital evidence in a legally defensible manner.

When should digital forensics be used?

Forensics may be needed after:

  • ransomware
  • insider misconduct
  • fraud
  • email compromise
  • IP theft
  • data leakage
  • regulatory investigations
  • litigation

What is the chain of custody?

Chain-of-custody documents how evidence was collected, handled, stored, analysed, and transferred to preserve evidentiary integrity.

Can deleted files still be recovered?

Sometimes.

Recovery depends on overwrite behaviour, encryption, storage activity, and timing.

Can forensic evidence be used in court?

Yes — if evidence was collected and preserved correctly using accepted forensic methodology.

Why should legal counsel be involved early?

Legal involvement helps:

  • preserve privilege
  • guide investigative scope
  • manage regulatory exposure
  • coordinate response strategy

What standards guide forensic investigations?

Common standards include:

  • ISO/IEC 27037
  • ISO/IEC 27041
  • ISO/IEC 27042
  • ACPO Good Practice Guide
  • NIST SP 800-86

What’s the difference between incident response and forensics?

Incident response focuses on containment and recovery.

Forensics focuses on evidence preservation, reconstruction, investigation, and defensibility.

Can cloud environments be investigated forensically?

Yes.

Cloud forensic investigations may include:

  • identity activity
  • API logs
  • audit trails
  • mailbox analysis
  • storage review
  • endpoint telemetry

What makes a forensic report credible?

A credible report uses:

  • documented methodology
  • evidence traceability
  • reproducible findings
  • structured analysis
  • defensible conclusions

Security Testing & Ethical Hacking

What’s the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment identifies weaknesses.

A penetration test attempts to exploit weaknesses to demonstrate real-world impact.

What is ethical hacking?

Ethical hacking is authorised security testing performed using attacker-style techniques to identify exploitable weaknesses.

Will penetration testing disrupt our systems?

Most testing is designed to minimise disruption, but certain aggressive tests may require maintenance windows or scoped controls.

How often should penetration testing be performed?

Typically, annually or after major infrastructure, cloud, or application changes.

What is red teaming?

Red teaming simulates realistic attacker behaviour to test detection, response, and organisational resilience.

What is included in a vulnerability assessment?

Assessments may cover:

  • internet-facing exposure
  • internal infrastructure
  • cloud systems
  • applications
  • APIs
  • configuration weaknesses
  • outdated software

Are automated scanners enough?

No.

Automated tools are important, but manual validation and expert analysis remain essential.

What certifications matter for testers?

Relevant certifications may include:

  • OSCP
  • CEH
  • CREST
  • CISSP
  • GPEN

 

Experience and methodology matter as much as certifications.

What should a penetration testing report include?

A good report should contain:

  • executive summary
  • risk prioritisation
  • technical findings
  • evidence
  • remediation guidance
  • retesting results where applicable

Can phishing simulations be part of security testing?

Yes.

Phishing simulations help assess awareness, reporting behaviour, and organisational response capability.

What is the difference between black-box and white-box testing?

Black-box testing simulates an attacker with no prior knowledge.

White-box testing provides testers with internal knowledge, credentials, or visibility into the architecture.

Why does scope matter in penetration testing?

A clear scope protects both the client and the testing team.

It defines:

  • authorised systems
  • approved techniques
  • testing windows
  • emergency procedures

 

operational constraints

Identity & Password Security

Why are passwords still such a major security risk?

Most breaches still involve compromised credentials.

Weak passwords, password reuse, phishing, and poor identity management remain common attack paths.

What is password security assurance?

Password security assurance involves testing whether real passwords and identity controls can resist realistic attack techniques.

Is MFA enough to protect accounts?

MFA is essential, but it is not sufficient on its own.

Attackers may still use:

  • token theft
  • MFA fatigue attacks
  • session hijacking
  • social engineering
  • compromised devices

What are privileged accounts?

Privileged accounts have elevated access to systems, applications, or infrastructure.

These accounts are often targeted because they provide broad access and administrative control.

Why are dormant accounts dangerous?

Dormant accounts are frequently overlooked, poorly monitored, and sometimes still retain active permissions.

Attackers often exploit these accounts because they attract less attention.

How often should password security be reviewed?

Identity and password security should be reviewed continuously.

Periodic testing, monitoring, and access reviews help prevent privilege drift and credential exposure.

What is privilege creep?

Privilege creep occurs when users accumulate access rights over time that are no longer required for their role.

What is meant by identity hygiene?

Identity hygiene refers to the ongoing management of:

  • accounts
  • permissions
  • authentication methods
  • password health
  • administrative access
  • account lifecycle controls

ISO 27001 & Governance

What is ISO 27001?

ISO/IEC 27001 is an internationally recognised framework for building and managing an Information Security Management System (ISMS).

What is an ISMS?

An Information Security Management System combines governance, policies, controls, processes, and continuous improvement practices to manage information security risk.

Does ISO 27001 guarantee security?

No.

ISO 27001 helps organisations implement structured governance and control management, but security still depends on operational effectiveness.

How long does ISO 27001 implementation usually take?

Implementation timelines vary depending on:

  • organisational size
  • maturity
  • scope
  • resources
  • complexity

Medium-sized organisations often require several months to reach certification readiness.

What is a Statement of Applicability?

The Statement of Applicability identifies which Annex A controls apply to the organisation and explains why.

What is the difference between ISO 27001 and NIST?

ISO 27001 provides a certifiable management system.

NIST CSF provides a flexible operational framework for organising cybersecurity activities.

Many organisations use both together.

What are the six NIST CSF functions?

The six functions are:

  • Govern
  • Identify
  • Protect
  • Detect
  • Respond
  • Recover

What is a vCISO?

A vCISO provides strategic cybersecurity leadership and governance support without requiring a full-time executive appointment.

Why does governance matter in cybersecurity?

Governance creates accountability, structure, oversight, reporting, and decision-making discipline.

Without governance, security initiatives often become fragmented and inconsistent.

What is continuous improvement in ISO 27001?

Continuous improvement involves regularly reviewing, refining, testing, and enhancing the ISMS over time.

Do we need ISO 27001 certification?

Not every organisation requires formal certification.

However, many customers, procurement teams, insurers, and regulators increasingly expect structured governance and evidence of security maturity.

What is management review in an ISMS?

Management review is the formal executive-level evaluation of ISMS performance, risk posture, incidents, audit findings, and improvement priorities.

POPIA & Data Privacy

What is POPIA?

POPIA is South Africa’s Protection of Personal Information Act.

It governs how organisations collect, process, store, protect, and manage personal information.

Does POPIA apply to small businesses?

Yes.

POPIA applies to organisations of any size that process personal information.

What are “reasonable security measures” under POPIA?

Reasonable security measures depend on:

  • the sensitivity of the data
  • operational risk
  • available safeguards
  • industry expectations
  • technical and organisational controls

What is POPIA Section 19?

Section 19 requires organisations to implement appropriate technical and organisational safeguards to protect personal information.

What is POPIA Section 21?

Section 21 governs operator obligations and third-party processing relationships.

What is POPIA Section 22?

Section 22 governs notification obligations following a security compromise involving personal information.

Who is responsible for POPIA compliance?

The responsible party remains accountable for the processing of personal information, even when third parties or operators are involved.

What is an Information Officer?

An Information Officer is responsible for overseeing POPIA compliance and engagement with the Information Regulator.

Can cloud providers affect POPIA obligations?

Yes.

Organisations remain responsible for protecting personal information even when cloud platforms or external providers are used.

What happens if a business fails to comply with POPIA?

Potential consequences may include:

  • regulatory investigation
  • enforcement action
  • reputational damage
  • contractual disputes
  • operational disruption
  • legal exposure

What is personal information under POPIA?

Personal information includes any information that can identify an individual directly or indirectly.

How does POPIA relate to cybersecurity?

Cybersecurity controls support POPIA compliance by helping protect the confidentiality, integrity, and availability of personal information.

Third-Party Risk Management

What is third-party risk management?

Third-party risk management evaluates and manages the risks introduced by suppliers, service providers, operators, and external partners.

Why is supplier security becoming more important?

Attackers increasingly target suppliers because they can provide indirect access into customer environments.

What is a supplier security assessment?

A supplier security assessment evaluates the security posture, governance, controls, and operational maturity of a third party.

Does outsourcing reduce our accountability under POPIA?

No.

Organisations remain responsible for protecting personal information processed by operators or suppliers.

What should high-risk suppliers be assessed for?

High-risk suppliers may be assessed for:

  • access controls
  • governance maturity
  • incident response capability
  • certifications
  • monitoring capability
  • subcontractor risk
  • breach notification processes

What is meant by continuous supplier monitoring?

Continuous monitoring provides ongoing visibility into supplier risk posture, rather than relying solely on annual questionnaires.

Why is supplier inventory important?

Organisations cannot manage supplier risk effectively without a complete understanding of who has access to systems, data, or operational dependencies.

What contractual controls matter most in supplier agreements?

Important clauses often include:

  • breach notification obligations
  • security requirements
  • audit rights
  • data handling obligations
  • subcontractor controls
  • liability provisions

How often should suppliers be reassessed?

Assessment frequency should align with supplier criticality and risk exposure.

Higher-risk suppliers often require more frequent review.

What is supply-chain cyber risk?

Supply-chain cyber risk refers to the operational and security risks introduced through interconnected suppliers, vendors, platforms, and service providers.

Threat Intelligence & Emerging Threats

What is threat intelligence?

Threat intelligence helps organisations understand emerging threats, attacker behaviour, indicators of compromise, and operational risks.

Why is threat intelligence important?

Threat intelligence helps organisations prioritise controls, improve monitoring, and adapt security operations to evolving attack patterns.

What are the biggest emerging cyber threats currently?

Common emerging threats include:

  • ransomware extortion
  • AI-assisted phishing
  • identity attacks
  • supply-chain compromise
  • cloud identity abuse
  • credential theft

Are attackers using AI?

Yes.

Attackers increasingly use AI to improve phishing, reconnaissance, social engineering, and automation.

What is meant by “identity-based attacks”?

Identity-based attacks focus on compromising user accounts, credentials, sessions, or authentication systems rather than directly exploiting software vulnerabilities.

What is threat hunting?

Threat hunting involves proactively searching environments for suspicious behaviour or indicators that automated systems may have missed.

How should organisations respond to evolving threats?

Strong organisations continuously improve:

  • monitoring
  • governance
  • visibility
  • response capability
  • identity controls
  • user awareness
  • resilience planning

Is threat intelligence only useful for large enterprises?

No.

Threat intelligence benefits organisations of all sizes because threat patterns affect businesses across sectors and environments.

TOTALIS Platform

What is TOTALIS?

TOTALIS is Cyber Resilience’s platform for visibility and operational oversight.

What does TOTALIS help organisations do?

TOTALIS helps organisations improve visibility into:

  • cyber risk
  • operational posture
  • governance maturity
  • security trends
  • incident exposure
  • supplier risk

Is TOTALIS a SIEM platform?

TOTALIS is designed to support resilience, visibility, and operational oversight rather than acting purely as a traditional SIEM.

Who is TOTALIS designed for?

TOTALIS supports:

  • executives
  • IT leadership
  • governance teams
  • operational security teams
  • risk stakeholders

Can TOTALIS support governance reporting?

Yes.

TOTALIS is designed to help organisations improve operational visibility and reporting alignment.

Can TOTALIS integrate into existing environments?

Integration capability depends on the environment, telemetry sources, and operational requirements.

Does TOTALIS replace existing security tools?

No.

TOTALIS is intended to support visibility, governance, and operational understanding alongside existing security tooling.

What operational insights can TOTALIS provide?

Operational insights may include:

  • visibility trends
  • risk posture indicators
  • governance maturity visibility
  • operational exposure trends
  • monitoring insights

Is TOTALIS only for large organisations?

No.

Operational visibility and governance insight are valuable for organisations of all sizes.

Why is visibility so important in cybersecurity?

Organisations cannot respond effectively to risks they cannot see.

Visibility supports:

  • detection
  • governance
  • prioritisation
  • response
  • reporting
  • operational resilience

Still have a question?

If your question isn’t answered here, our team will help you understand your environment and identify the most practical next step.