Compliance is not a scramble when it is already done.
Most businesses experience compliance as a panic. A client sends a security questionnaire, or an auditor asks a question, and three people spend a week assembling answers that should already exist. Compliant by design means the opposite.
What does POPIA actually require of a small business?
POPIA applies to any South African business that holds personal information about customers, staff or suppliers, regardless of size. Section 19 requires that business to secure the integrity and confidentiality of that information using appropriate, reasonable technical and organisational measures, and to identify reasonably foreseeable risks. In practice that means documented access control, encryption, backup, monitoring and an incident response process. There is no small business exemption.
The word doing the work in Section 19 is reasonable. It is deliberately not a checklist, which is why an internationally recognised framework matters: it is how a business demonstrates that what it chose to do was reasonable, rather than asserting it after the fact.
What does the Cybercrimes Act add?
The Cybercrimes Act 19 of 2020 criminalises unlawful access to, interception of and interference with data and computer systems in South Africa. Its most serious offence category carries a maximum penalty of up to 15 years imprisonment under Section 11(1). For a business the practical consequences are hardened environments, documented evidence preservation so an incident can actually be investigated, and clear reporting paths.
The evidence preservation point is the one most businesses miss. If systems are wiped and rebuilt in the first hours of an incident, which is the natural instinct, the evidence of what happened goes with them.
Why does LANTEK use the NIST Cybersecurity Framework?
The NIST Cybersecurity Framework 2.0 organises security work into six functions: Govern, Identify, Protect, Detect, Respond and Recover. LANTEK uses it because POPIA requires reasonable measures without specifying them, and an internationally recognised framework is the accepted way to show what reasonable looks like. It also gives a business a plain structure for a conversation that otherwise becomes a list of products.
LANTEK is not certified against the framework and no such certification exists. The framework is a structure for delivering and evidencing the work, not a badge.
Can our data be hosted outside South Africa?
Yes, in defined circumstances. POPIA Section 72 permits the cross border transfer of personal information where the receiving jurisdiction has comparable protection, where the data subject consents, or where the transfer is necessary for performance of a contract. POPIA is not a South Africa only hosting law, which is a common misunderstanding that leads businesses to rule out perfectly lawful and better options.
What matters is that the position is documented and defensible, and that the data processing agreement with each vendor reflects it.
What we actually run in your environment
No hand waving. These are the same controls we evidence on our own compliance checklist, organised the way the NIST Cybersecurity Framework organises them.
| Function | In plain words | What LANTEK delivers |
|---|---|---|
| GOVERN | Policy and oversight | Security and acceptable use policies, Information Officer support, compliance registers, and data processing agreements with every vendor that touches your data, so accountability is documented rather than assumed. |
| IDENTIFY | Know your risk | Asset registers, data classification, quarterly reviewed risk registers, end of life software flagging and data flow mapping. You cannot protect what you cannot see, so we make sure you can see it. |
| PROTECT | Lock it down | Enforced multi-factor authentication, least privilege access, endpoint detection and response on every device, proactive patch management, encryption, email security, DNS filtering, and backup that is routinely tested. |
| DETECT | Always watching | Round the clock monitoring, alerting on suspicious activity and ransomware indicators, dark web monitoring, and regular vulnerability scanning. |
| RESPOND | Act fast | Documented incident response plans, tested containment, evidence preservation, clear client notification service levels, and support for POPIA and Cybercrimes Act reporting. Calm, fast and by the book. |
| RECOVER | Bounce back | Tested business continuity and disaster recovery, verified backups, rehearsed restores, and lessons that feed back into the plan, because getting back to work is what actually matters. |
Maximum POPIA administrative fine
Maximum Cybercrimes Act penalty, Section 11(1)
Compliance is a competitive advantage. It is the reason you win work that slower suppliers lose.
When a large client asks whether you handle data responsibly, the policies exist, the asset register is current, the access reviews happened last quarter, and the evidence is filed because it was produced as a by-product of doing the work properly. You answer the same day.
Before you call
Does POPIA apply to a small business?
What is the maximum POPIA fine?
Do we have to report a breach within 72 hours?
Is LANTEK NIST certified?
Do you hold ISO 27001?
What is an Information Officer, and do we need one?
A free dark web scan
and thirty minutes.
We scan for your company email addresses, passwords and customer data in the places stolen and leaked data gets traded, then spend thirty minutes walking you through what came back and what it actually means. No pressure, no jargon, no obligation. You keep the report either way.
Worried about what it takes to move?
Changing IT provider is the single biggest reason businesses stay somewhere they have outgrown. We plan the move around your working week, and we help carry the cost of getting across. Ask us how that works when we speak.