What is ISO/IEC 27001?

Information security and data privacy are becoming increasingly important for businesses of all sizes, and across all sectors. The rapid increase in cyber-related incidents in South Africa, particularly affecting smaller, more vulnerable organisations requires urgent attention. The purpose of information security is to protect information assets from unauthorised access, maintain accurate and complete records, and […]
Should you DIY your ISMS implementation?

Having made the decision to implement an information security management system (ISMS), your first big decision is on whether you should do it yourself or work with external specialist consultants. Key Takeaways It is possible to do this alone, but don’t underestimate the effort required to do so. There are a lot of resources available […]
ISO 27001 and the PDCA cycle

When it comes to improving your business’s information security, ISO/IEC 27001 is one of the most recognised standards in the world. But for many small or medium-sized organisations, the idea of implementing it can feel overwhelming. Where do you even start? That’s where the PDCA cycle comes in. Key Takeaways PDCA stands for Plan-Do-Check-Act, and […]
Should you use specialised GRC software?

So, you’ve decided to implement an Information Security Management System (ISMS)? Great move! It’s a proactive way to protect your business, earn customer trust, and maybe even land those bigger contracts that ask for ISO/IEC 27001 certification. You’ve come to a fork in the road, deciding how you will actually manage your ISMS? Should you […]
Continual Improvement Increases Business Value

The business world is seriously competitive, and the only way to survive and stay ahead is to adapt, innovate and keep up with rapidly changing trends and threats. To make these kinds of continual improvements, you not only need to refine processes, but also embed a mindset within the workforce that embraces change, adapts to […]
