First actions
Enterprise priorities
Use governance and technical controls together, especially where business processes depend on suppliers.
Own critical services
Map the systems, people, third parties and data flows needed to deliver your most important services.
Prepare for ransomware
Test offline recovery, legal escalation, executive decision paths and communications before an incident.
Measure identity risk
Review privileged access, dormant accounts, service accounts, conditional access and emergency accounts.
Plan regulatory response
Include POPIA assessment, customer notifications, law enforcement contact and evidence handling in playbooks.
Sample guidance
Assurance areas
Use risk language leaders can act on
Report control health, incident readiness, recovery confidence and major supplier dependencies, not only vulnerability counts.
Control cloud drift
Track public exposure, privileged roles, encryption coverage, logging gaps and shadow SaaS use across business units.
Assure outsourced operations
Require incident notification timelines, access reviews, backup expectations and evidence of secure administration.
Prioritise useful telemetry
Collect identity, endpoint, email, cloud admin and network logs for the services that matter most to continuity.
Checklist
Executive resilience review
- Confirm the top business services and their maximum tolerable outage.
- Review ransomware recovery time evidence from a recent restore test.
- Check that incident roles include legal, privacy, communications and finance.
- Review critical suppliers with network, admin or data access.
- Track open control gaps with owners and target dates.
Resources
Enterprise resilience worksheets
Cyber incident intake and triage
Capture severity, evidence, decision paths and reporting routes for major incidents.
Web formPOPIA security compromise assessment
Assess breach scope, affected data categories, notification duties and deadline ownership.
Form + checklistRansomware first-hour triage
Structure isolation decisions, legal escalation, evidence capture, communications and recovery validation.
Excel + supplier formSupplier security questionnaire
Review access, data processing, logging, notification paths, contract follow-ups and exit plans.
Excel dashboardEnterprise executive resilience review
Prepare a board-ready view of top risks, service dependencies, control gaps and recovery confidence.
Excel checklistIdentity and privileged-access review
Identify stale access, high-risk accounts, missing MFA, suspicious rules and remediation owners.
Excel registerCloud shared-drive and SaaS access review
Track public exposure, external sharing, orphaned accounts, encryption coverage and logging gaps.