Good infrastructure is unremarkable by design. The systems are up, the backups restore, the person who left on Friday cannot log in on Monday, and nobody has an opinion about any of it. That state is not luck — it is a set of decisions taken before they were urgent.
What we actually do
Servers and networks, on-premise, cloud or the hybrid most businesses actually need. Backups that are tested, which is a different product from backups that exist. Access control, so permissions match roles and leavers lose access the same day. Firewalls and endpoint security sized to a real business rather than a brochure. And CCTV and physical security, including the modern camera systems that do more than record.
Built for local conditions
Anything designed for South African businesses has to survive power that goes away on a schedule and connectivity that goes away without one. That means ranking loads before pricing hardware, protecting the network equipment rather than only the desk, and building failover that actually switches rather than a second invoice for the same fibre route.
We have written both of these up in detail — load-shedding-proof IT and connectivity that does not drop — because the mistakes are consistent and expensive.
A restore is the only backup that counts
The single most common serious finding in our audits is a backup nobody has ever restored from. It runs, it reports success, and it has been quietly failing to include the one database that matters for fourteen months.
So we test restores, on a schedule, and we make sure more than one person has done it. A recovery procedure that only one person has performed is not a strategy, it is a hope with documentation. That is the argument in what happens when the server dies.
The five-minute audit
When did someone last restore a file from backup? Can the person who left last quarter still open their email? Is there a device on your network nobody can identify? What happens to the internet when the fibre goes down? And who has the password to the domain registrar? A shrug at any of these is worth a conversation.
Security sized to the business
Most small and mid-sized businesses are not breached by anything sophisticated. They are breached through a reused password, an unpatched machine, or an invoice email that looked close enough to real. So we start with the basics that stop the overwhelming majority of incidents — a password manager, multi-factor authentication, patching, and a clean offboarding process — before anyone proposes something with a dashboard.
Where you hold personal information, this is also a legal question rather than only a prudent one, which is where POPIA enters the conversation.