Complete Cybersecurity Checklist for South African SMEs: 2026 Edition
Published: January 28, 2026 | Updated: September 19, 2026 | By Code Masters
Protect Your Business from Cyber Threats
Why This Matters: SA Cyber Threat Reality
85%
of SA SMEs experienced cyber attack in 2025
R2.3M
average cost of data breach for SA businesses
60%
of breached SMEs close within 6 months
R10M
maximum POPIA fine for non-compliance
Cybersecurity isn't just for big corporations. South African SMEs in Pretoria, Johannesburg, and across Gauteng are prime targets for cybercriminals precisely because they often lack adequate protection. This comprehensive checklist covers everything you need to protect your business.
Section 1: Password & Access Security
Enforce strong password policy
Minimum 12 characters, mix of upper, lower, numbers, symbols. No dictionary words or personal info.
Implement Multi-Factor Authentication (MFA)
Required for email, financial systems, and any remote access. SMS 2FA is better than nothing, but authenticator apps are more secure.
Use a business password manager
LastPass, 1Password, or Bitwarden. No more shared spreadsheets of passwords.
Regular access reviews
Quarterly review of who has access to what. Remove access for departed staff immediately.
Limit admin privileges
Users should not run as administrators. IT admins should use separate accounts for admin tasks.
Section 2: Network & Infrastructure Security
Business-grade firewall configured
Not just your ISP's router. Properly configured firewall with intrusion detection.
WiFi security updated
WPA3 encryption, hidden SSID for business network, separate guest network, strong password.
Regular network monitoring
Know what devices are on your network. Alert on unusual activity.
Segment your network
Sensitive systems (finance, HR) isolated from general staff access.
VPN for remote workers
All remote access must go through encrypted VPN tunnel, not direct internet.
Section 3: Endpoint Protection
Enterprise antivirus/EDR on all devices
Consumer antivirus isn't enough. Business solutions provide centralised management and better protection.
Automatic updates enabled
Windows, MacOS, and all applications set to auto-update. Patch within 72 hours of critical updates.
Full disk encryption
BitLocker (Windows) or FileVault (Mac) enabled on all laptops. Lost device = encrypted data.
Mobile device management (MDM)
If staff use phones for work email, implement MDM to remotely wipe if lost.
USB device policy
Disable or control USB ports. No random flash drives allowed.
Section 4: Staff Training & Awareness
Security awareness training
Annual training for all staff. Cover phishing, social engineering, password hygiene, physical security.
Phishing simulation tests
Regular fake phishing emails to test awareness. Follow up with training for those who click.
Clear security policies
Written, signed acceptable use policy. What's allowed, what's not, consequences.
Incident reporting procedure
Staff know who to call if they click something suspicious or notice something wrong.
Onboarding/offboarding checklists
Security steps included in hiring and termination procedures.
Section 5: POPIA Compliance Requirements
POPIA Reminder
The Protection of Personal Information Act applies to ALL businesses handling personal data. Non-compliance can result in fines up to R10 million and/or imprisonment up to 10 years.
Data inventory completed
Document what personal data you collect, where it's stored, who has access, why you have it.
Privacy policy published
Clear privacy policy on website explaining data collection, use, and retention.
Consent mechanisms in place
Proper consent obtained before collecting personal information.
Data breach response plan
Written procedure for what to do if data is compromised. Includes notification requirements.
Information Officer appointed
Required by POPIA. Registered with Information Regulator.
Your Security Action Plan
Feeling overwhelmed? Here's how to prioritise:
Enable MFA on email and critical systems. Run antivirus scan on all computers.
Verify backups work. Update all operating systems and software.
Deploy business antivirus. Implement password manager. Review user access.
Staff security training. POPIA compliance review. Network security audit.
Get a Professional Security Assessment
Code Masters
Building 5, Central Office Park
257 Jean Avenue, Centurion
Gauteng, South Africa
Download Complete Checklist PDF
Get the full 20-point cybersecurity checklist as a printable PDF to share with your team.