The practice
Seven interlocking practices, one orchestrated defence.
Each practice strengthens the others. Engage a single capability or the full system — every engagement plugs into one coherent operating picture.
The system
Data sits at the centre.
Every other discipline exists to protect, govern or enable it. Strategy decides what matters, identity decides who reaches it, architecture decides where it lives, and assessment proves whether any of that holds.
That is why we draw the practice as an interlock rather than a list. A control is only as good as the ones it depends on, and most failures we are called to happen in the joins.
Capabilities
What each practice does.
Most clients start with one and add others as the estate and the obligations grow.
- 01Cyber Strategy & TransformationArchitect a security posture that scales with ambition — from board-level strategy to operating model design.
- 02Managed Defence Services24/7 detection and response from our regional SOC. Threats answered in minutes, not days.
- 03Risk, Compliance & ResilienceNavigate POPIA, the Joint Standard and global frameworks with pragmatic, audit-ready controls.
- 04Data Protection & PrivacyGovern data across its lifecycle — classify, secure, and prove it, end to end.
- 05Identity & Privileged AccessZero-trust identity for people, machines and partners. Frictionless yet uncompromising.
- 06Architecture & Operational TechnologySecure cloud, OT and emerging technology by design — from blueprint to brownfield.
- 07Technical Security AssessmentsVAPT, red team, purple team and adversary simulation — pressure-tested by operators who think like attackers.
Start here
Not sure which practice you need?
Describe the situation and we'll tell you where we would start — including when the answer is that you do not need us yet.
