KuTh Consultants (Pty) Ltd

Corporate & Business · NPO & Social Impact · Telecommunications & Technology

An existing control reported as insufficient is worth more than one reported as present

A compromised mailbox, weak remote-access path, exposed service or unverified backup becomes a financial, operational, data-protection and trust problem quickly. For an organisation whose income depends on donor confidence, trust is not the secondary consequence.

4
assessment domains reviewed
7
control priorities identified
8
measures defined for ongoing governance

Proof context: An anonymised NPO technology environment

The situation

Not only an IT issue

A compromised mailbox, a weak remote-access path, an exposed service, an unverified backup or a poorly monitored critical system becomes a financial, operational, data-protection and trust problem quickly. For an organisation whose income depends on donor and funder confidence, the trust component is not secondary.

This engagement produced findings rather than savings. The supporting document is a findings sheet, and nothing in it is presented as a post-remediation outcome.

Scope

Four domains

  • Identity, email and users. Phishing exposure, authentication, privileged access, user practices, and payment or donor-communication risk.
  • Endpoints and network. Device protection, central visibility, network access, internet exposure, remote working and infrastructure resilience.
  • Cloud, data and critical systems. Backup and recovery assurance, cloud controls, business-critical applications, supplier dependencies and data protection.
  • Detection and response. Logging, vulnerability management, threat detection, escalation, incident response and recovery readiness.

Findings

What was absent, what existed, and what needed validating

Scroll table sideways →

AreaEvidenceStatus
Central monitoringNo SIEM or equivalent central security-event capability was identified in the assessed environment.Identified control gap
Threat and vulnerability detectionDedicated threat, intrusion and vulnerability-detection capability was not evidenced.Identified control gap
Critical financial systemPublicly reachable ports and services around a critical finance platform were flagged for specialist validation.Exposure requiring validation
Endpoint protectionAntivirus was present, but managed per device rather than through a central operational view.Existing control, management gap
Cloud backup and recoveryIndependent backup coverage and recovery assurance for cloud services were not clearly evidenced.Assurance gap
Critical application recoveryA third party supported the finance platform, but backup reporting and ownership of recovery assurance required deeper scrutiny.Governance gap
Phishing awarenessA phishing-simulation and awareness capability existed.Existing control

Two findings that were deliberately not overstated

An open port is not automatically a vulnerability. Unnecessary or weakly protected public exposure increases attack surface and has to be justified, restricted and monitored — but the finding was recorded as requiring specialist validation, not as a breach.

The phishing-awareness tool was recorded as an existing control, and then qualified. Awareness is useful and does not replace MFA, mail security, identity controls, logging, verification procedures and incident response. Reporting a control as present but insufficient is more useful than reporting it as present.

Approach

Not buying technology for its own sake

The method starts with the operating environment, critical systems, information flows and existing controls; identifies and prioritises the most credible exposures; brings in specialist capability where deeper testing is required; and translates findings into a remediation programme management can govern and evidence.

Scale matters to the recommendation. Central visibility might mean a SIEM, managed detection and response, or a managed service — the point is right-sized logging and monitoring, not an enterprise platform bought because enterprises buy them.

Governance context

What the law already requires

POPIA requires appropriate, reasonable technical and organisational measures to secure personal information, and an ongoing process of identifying risks, maintaining safeguards, verifying that they are effectively implemented, and updating them. Where a qualifying security compromise occurs, section 22 places notification duties on the responsible party, and the Information Regulator provides an eServices channel for reporting.

The Cybercrimes Act 19 of 2020 separately criminalises core forms of unlawful access, interference and related conduct.

The control model used is consistent with the NIST Cybersecurity Framework 2.0 functions — Govern, Identify, Protect, Detect, Respond, Recover — and with the risk-management orientation of ISO/IEC 27001:2022. Neither framework requires a particular technology stack. The question is whether controls are proportionate, implemented and evidenced.

Could this be recoverable in your own operating spend?

Request a confidential category diagnostic