CybersecurityPOPIA Compliance

Complete Cybersecurity Checklist for South African SMEs: 2026 Edition

Published: January 28, 2026 | Updated: September 19, 2026 | By Code Masters

January 27, 202615 min readCode Masters Security Team

Protect Your Business from Cyber Threats

Why This Matters: SA Cyber Threat Reality

85%

of SA SMEs experienced cyber attack in 2025

R2.3M

average cost of data breach for SA businesses

60%

of breached SMEs close within 6 months

R10M

maximum POPIA fine for non-compliance

Cybersecurity isn't just for big corporations. South African SMEs in Pretoria, Johannesburg, and across Gauteng are prime targets for cybercriminals precisely because they often lack adequate protection. This comprehensive checklist covers everything you need to protect your business.

Section 1: Password & Access Security

Enforce strong password policy

Minimum 12 characters, mix of upper, lower, numbers, symbols. No dictionary words or personal info.

Implement Multi-Factor Authentication (MFA)

Required for email, financial systems, and any remote access. SMS 2FA is better than nothing, but authenticator apps are more secure.

Use a business password manager

LastPass, 1Password, or Bitwarden. No more shared spreadsheets of passwords.

Regular access reviews

Quarterly review of who has access to what. Remove access for departed staff immediately.

Limit admin privileges

Users should not run as administrators. IT admins should use separate accounts for admin tasks.

Section 2: Network & Infrastructure Security

Business-grade firewall configured

Not just your ISP's router. Properly configured firewall with intrusion detection.

WiFi security updated

WPA3 encryption, hidden SSID for business network, separate guest network, strong password.

Regular network monitoring

Know what devices are on your network. Alert on unusual activity.

Segment your network

Sensitive systems (finance, HR) isolated from general staff access.

VPN for remote workers

All remote access must go through encrypted VPN tunnel, not direct internet.

Section 3: Endpoint Protection

Enterprise antivirus/EDR on all devices

Consumer antivirus isn't enough. Business solutions provide centralised management and better protection.

Automatic updates enabled

Windows, MacOS, and all applications set to auto-update. Patch within 72 hours of critical updates.

Full disk encryption

BitLocker (Windows) or FileVault (Mac) enabled on all laptops. Lost device = encrypted data.

Mobile device management (MDM)

If staff use phones for work email, implement MDM to remotely wipe if lost.

USB device policy

Disable or control USB ports. No random flash drives allowed.

Section 4: Staff Training & Awareness

Security awareness training

Annual training for all staff. Cover phishing, social engineering, password hygiene, physical security.

Phishing simulation tests

Regular fake phishing emails to test awareness. Follow up with training for those who click.

Clear security policies

Written, signed acceptable use policy. What's allowed, what's not, consequences.

Incident reporting procedure

Staff know who to call if they click something suspicious or notice something wrong.

Onboarding/offboarding checklists

Security steps included in hiring and termination procedures.

Section 5: POPIA Compliance Requirements

POPIA Reminder

The Protection of Personal Information Act applies to ALL businesses handling personal data. Non-compliance can result in fines up to R10 million and/or imprisonment up to 10 years.

Data inventory completed

Document what personal data you collect, where it's stored, who has access, why you have it.

Privacy policy published

Clear privacy policy on website explaining data collection, use, and retention.

Consent mechanisms in place

Proper consent obtained before collecting personal information.

Data breach response plan

Written procedure for what to do if data is compromised. Includes notification requirements.

Information Officer appointed

Required by POPIA. Registered with Information Regulator.

Your Security Action Plan

Feeling overwhelmed? Here's how to prioritise:

Week 1

Enable MFA on email and critical systems. Run antivirus scan on all computers.

Week 2

Verify backups work. Update all operating systems and software.

Month 1

Deploy business antivirus. Implement password manager. Review user access.

Quarter 1

Staff security training. POPIA compliance review. Network security audit.

Get a Professional Security Assessment

Code Masters

Building 5, Central Office Park

257 Jean Avenue, Centurion

Gauteng, South Africa

Download Complete Checklist PDF

Get the full 20-point cybersecurity checklist as a printable PDF to share with your team.