Cybersecurity June 2025 9 min read

The 2025 Cybersecurity Checklist for South African SMEs

South Africa ranks among the most cybercrime-targeted countries globally. Most attacks on SMEs exploit simple, preventable weaknesses. This checklist covers 40 controls across 8 categories - prioritised so you know what to do first.

You don't need enterprise-grade security tooling to be well-protected. You need to close the obvious gaps that attackers exploit most. This checklist is built around the controls that stop the highest volume of real-world attacks on South African SMEs - not theoretical risks, but the actual attack patterns that show up in incident reports every week.

Work through this with your IT provider or internal IT person. If you don't have either, use it to benchmark what you're missing before engaging an MSP.

Rating guide - ⚡ Critical (do this week) | 🔶 Important (do this month) | ✅ Good practice (do this quarter)

1. Identity and access management

  • ⚡ Multi-factor authentication (MFA) enabled on Microsoft 365 / Google Workspace for all users
  • ⚡ MFA enabled on all remote access (VPN, RDP, remote management tools)
  • ⚡ No shared accounts - every employee has a unique login
  • 🔶 Admin accounts used only for admin tasks - daily work done from standard accounts
  • 🔶 Offboarding process documented - accounts disabled same-day when an employee leaves
  • ✅ Annual access review - confirm each user only has access to what they need
  • ✅ Password manager deployed for all staff (Bitwarden, 1Password)

2. Endpoint security

  • ⚡ Antivirus or EDR (Endpoint Detection and Response) installed and active on all devices
  • ⚡ Windows automatic updates enabled - or managed patching in place
  • ⚡ No end-of-life operating systems in use (Windows 10 reaches EOL October 2025)
  • 🔶 Full-disk encryption enabled on all laptops (BitLocker for Windows, FileVault for Mac)
  • 🔶 Screen lock after 5 minutes inactivity on all devices
  • 🔶 Remote wipe capability on all company laptops and mobile devices
  • ✅ Software inventory maintained - you know what's installed on every device

3. Email security

  • ⚡ SPF record published and correctly configured for your domain
  • ⚡ DMARC policy published (minimum p=quarantine - ideally p=reject)
  • ⚡ DKIM signing enabled for all outbound mail
  • 🔶 Anti-phishing policy configured in Microsoft 365 Defender or Google Workspace
  • 🔶 Staff trained to identify phishing - at minimum, one training session per year
  • ✅ External email warning banner enabled (flags emails from outside your domain)
  • ✅ Blocked file extensions: .exe, .bat, .vbs, .ps1 in email attachments

4. Backups

  • ⚡ Daily automated backups in place for all critical business data
  • ⚡ At least one backup copy stored offsite or in a separate cloud account (not just the same OneDrive)
  • ⚡ Backups tested - you've actually restored from them in the last 3 months
  • 🔶 Backup retention of at least 30 days - so you can recover from a slow-burning attack
  • 🔶 Backup access is separate from production access - ransomware can't reach your backup credentials
  • ✅ Recovery Time Objective (RTO) defined - you know how long a full restore takes

5. Network security

  • ⚡ Default router/firewall admin passwords changed
  • ⚡ Remote Desktop Protocol (RDP) not exposed directly to the internet - if required, only via VPN
  • 🔶 Guest Wi-Fi network separate from business network
  • 🔶 Firewall rules reviewed - no unnecessary inbound ports open
  • ✅ DNS filtering in place (blocks access to known malicious domains)
  • ✅ Network monitoring - you'd know if an unusual device connected or unusual traffic occurred

6. Web and application security

  • ⚡ SSL/TLS certificate installed and valid on your website (HTTPS)
  • ⚡ Website CMS (WordPress etc.) and plugins kept up to date
  • 🔶 Web application firewall (WAF) in place - Cloudflare free tier covers the basics
  • 🔶 Contact forms and login pages protected against brute force
  • ✅ Security headers configured (Content Security Policy, X-Frame-Options, HSTS)
  • ✅ Third-party integrations and API keys reviewed annually - revoke unused ones

7. POPIA and data governance

  • ⚡ Information Officer appointed and registered with the Information Regulator
  • ⚡ Privacy Policy published on website
  • 🔶 Personal data inventory maintained - you know what personal data you hold and where
  • 🔶 Data retention policy in place - personal data deleted when no longer needed
  • ✅ Data breach response procedure documented and tested
  • ✅ Operator agreements in place with all third-party data processors

8. People and process

  • ⚡ IT incident contact numbers known by all staff - who do you call when something goes wrong?
  • 🔶 Security awareness training completed by all staff (at minimum annually)
  • 🔶 Acceptable use policy signed by all employees
  • ✅ Security reviewed as part of any new software or supplier onboarding
  • ✅ Annual internal security review against this checklist

How to use your results

If you found more than 5 unchecked items in the Critical (⚡) category, your business has significant active exposure. Prioritise those first - they represent the most commonly exploited attack surface for South African SMEs.

If your Critical items are covered and you have gaps in the Important (🔶) category, you have a reasonable security baseline but meaningful room to improve. Work through those systematically over the next 30-60 days.

A fully ticked checklist is not a guarantee against attack - attackers evolve. But it closes the doors that account for the overwhelming majority of successful breaches against businesses of your size.

Get a professional assessment

This checklist is a starting point, not a substitute for a proper security assessment. InfoServ Technologies offers a free IT and security audit for South African SMEs - covering your technical posture, POPIA compliance status, and a prioritised remediation plan. No sales pressure, just honest findings.

Book your free audit today.