Compliance is not a scramble when it is already done.

Most businesses experience compliance as a panic. A client sends a security questionnaire, or an auditor asks a question, and three people spend a week assembling answers that should already exist. Compliant by design means the opposite.

What does POPIA actually require of a small business?

POPIA applies to any South African business that holds personal information about customers, staff or suppliers, regardless of size. Section 19 requires that business to secure the integrity and confidentiality of that information using appropriate, reasonable technical and organisational measures, and to identify reasonably foreseeable risks. In practice that means documented access control, encryption, backup, monitoring and an incident response process. There is no small business exemption.

The word doing the work in Section 19 is reasonable. It is deliberately not a checklist, which is why an internationally recognised framework matters: it is how a business demonstrates that what it chose to do was reasonable, rather than asserting it after the fact.

What does the Cybercrimes Act add?

The Cybercrimes Act 19 of 2020 criminalises unlawful access to, interception of and interference with data and computer systems in South Africa. Its most serious offence category carries a maximum penalty of up to 15 years imprisonment under Section 11(1). For a business the practical consequences are hardened environments, documented evidence preservation so an incident can actually be investigated, and clear reporting paths.

The evidence preservation point is the one most businesses miss. If systems are wiped and rebuilt in the first hours of an incident, which is the natural instinct, the evidence of what happened goes with them.

Why does LANTEK use the NIST Cybersecurity Framework?

The NIST Cybersecurity Framework 2.0 organises security work into six functions: Govern, Identify, Protect, Detect, Respond and Recover. LANTEK uses it because POPIA requires reasonable measures without specifying them, and an internationally recognised framework is the accepted way to show what reasonable looks like. It also gives a business a plain structure for a conversation that otherwise becomes a list of products.

LANTEK is not certified against the framework and no such certification exists. The framework is a structure for delivering and evidencing the work, not a badge.

Can our data be hosted outside South Africa?

Yes, in defined circumstances. POPIA Section 72 permits the cross border transfer of personal information where the receiving jurisdiction has comparable protection, where the data subject consents, or where the transfer is necessary for performance of a contract. POPIA is not a South Africa only hosting law, which is a common misunderstanding that leads businesses to rule out perfectly lawful and better options.

What matters is that the position is documented and defensible, and that the data processing agreement with each vendor reflects it.

What we actually run in your environment

No hand waving. These are the same controls we evidence on our own compliance checklist, organised the way the NIST Cybersecurity Framework organises them.

FunctionIn plain wordsWhat LANTEK delivers
GOVERNPolicy and oversightSecurity and acceptable use policies, Information Officer support, compliance registers, and data processing agreements with every vendor that touches your data, so accountability is documented rather than assumed.
IDENTIFYKnow your riskAsset registers, data classification, quarterly reviewed risk registers, end of life software flagging and data flow mapping. You cannot protect what you cannot see, so we make sure you can see it.
PROTECTLock it downEnforced multi-factor authentication, least privilege access, endpoint detection and response on every device, proactive patch management, encryption, email security, DNS filtering, and backup that is routinely tested.
DETECTAlways watchingRound the clock monitoring, alerting on suspicious activity and ransomware indicators, dark web monitoring, and regular vulnerability scanning.
RESPONDAct fastDocumented incident response plans, tested containment, evidence preservation, clear client notification service levels, and support for POPIA and Cybercrimes Act reporting. Calm, fast and by the book.
RECOVERBounce backTested business continuity and disaster recovery, verified backups, rehearsed restores, and lessons that feed back into the plan, because getting back to work is what actually matters.
R10m

Maximum POPIA administrative fine

15 yrs

Maximum Cybercrimes Act penalty, Section 11(1)

Compliance is a competitive advantage. It is the reason you win work that slower suppliers lose.

When a large client asks whether you handle data responsibly, the policies exist, the asset register is current, the access reviews happened last quarter, and the evidence is filed because it was produced as a by-product of doing the work properly. You answer the same day.

Before you call

Does POPIA apply to a small business?
Yes. POPIA applies to any South African business that holds personal information about customers, staff or suppliers, regardless of how many people it employs. There is no small business exemption. A five person practice holding client identity numbers has the same Section 19 obligation to secure that information as a listed company does.
What is the maximum POPIA fine?
The Information Regulator can impose an administrative fine of up to R10 million. Enforcement has already been issued against the Department of Basic Education, the National Police Commissioner and the South African Police Service, the Department of Justice, Dis-Chem Pharmacies and WhatsApp, so this is an active enforcement regime rather than a theoretical one.
Do we have to report a breach within 72 hours?
Not every business does. A specific 72 hour reporting window applies to defined categories such as electronic communications service providers and financial institutions. POPIA itself requires notification to the Information Regulator and to affected data subjects as soon as reasonably possible after a compromise is discovered, without setting a universal fixed clock. Confirm which obligation applies to your sector rather than assuming the 72 hour figure.
Is LANTEK NIST certified?
No, and no such certification exists. LANTEK structures its security services around the NIST Cybersecurity Framework 2.0, which is the internationally recognised yardstick for the reasonable measures POPIA demands. Any provider claiming to be NIST certified is describing something that cannot be held.
Do you hold ISO 27001?
Not yet. LANTEK is on the journey to ISO 9001 and ISO 27001 certification and does not claim either as held. That distinction matters, and a provider that blurs it on its own website is showing you how it will describe your compliance position later.
What is an Information Officer, and do we need one?
Every South African business has an Information Officer by default, and unless another person is registered it is the head of the organisation, meaning the chief executive or the owner. The role is responsible for POPIA compliance, for handling data subject requests and for the PAIA manual. LANTEK provides the technical evidence and controls that an Information Officer needs in order to carry the role properly.

A free dark web scan
and thirty minutes.

We scan for your company email addresses, passwords and customer data in the places stolen and leaked data gets traded, then spend thirty minutes walking you through what came back and what it actually means. No pressure, no jargon, no obligation. You keep the report either way.

Worried about what it takes to move?

Changing IT provider is the single biggest reason businesses stay somewhere they have outgrown. We plan the move around your working week, and we help carry the cost of getting across. Ask us how that works when we speak.