Security checklist
POPIA security readiness checklist
POPIA expects businesses to put reasonable technical measures in place to protect the personal information they hold. This checklist covers the security side of that: the twelve controls we look at first in a South African small business, why each one matters, and how to check whether you actually have it.
This is practical security guidance from an IT perspective, not legal advice. For questions about your obligations as a responsible party, speak to a suitably qualified advisor.
The twelve controls
1. Multi-factor authentication on all accounts
Why it matters: Stolen or guessed passwords are the most common route into a business mailbox or cloud tenancy holding personal information.
How to verify: In Microsoft 365 or Google Workspace, list users and confirm MFA is enforced for every account, including shared and admin accounts.
2. Least-privilege user access
Why it matters: The fewer people who can reach personal information, the smaller the impact of any single compromised account.
How to verify: Review who has admin rights and who can access HR, payroll, and customer folders. Remove access that is not needed for someone's job.
3. Joiner and leaver process
Why it matters: Accounts left active after someone leaves are a standing, unmonitored way into your data.
How to verify: Compare your active user list against your current staff list. Every account should map to a current employee or a documented service account.
4. Managed endpoint protection
Why it matters: Laptops and desktops hold local copies of documents and are where malware usually lands first.
How to verify: Confirm every device appears in a central protection console and reported in within the last week — not just that antivirus is 'installed somewhere'.
5. Patching of operating systems and software
Why it matters: Most successful attacks use known vulnerabilities that a patch already exists for.
How to verify: Check the oldest outstanding update across your devices. Anything unpatched for months is your weakest point.
6. Encryption on devices and in transit
Why it matters: A lost or stolen laptop should be an inconvenience, not a data breach.
How to verify: Confirm disk encryption (BitLocker or FileVault) is on for every laptop, and that internal systems and your website use HTTPS.
7. Monitored, restore-tested backups
Why it matters: Availability of personal information matters as much as confidentiality — ransomware takes both.
How to verify: Ask for the date of the last successful test restore. If nobody can answer, you have backups you cannot rely on.
8. Email filtering and phishing awareness
Why it matters: Phishing is the most common way staff are tricked into handing over credentials or data.
How to verify: Confirm mail filtering is active and that staff have been shown recent, realistic examples of phishing aimed at your industry.
9. Logging and alerting
Why it matters: You cannot report on or contain an incident you never detected.
How to verify: Confirm sign-in and admin activity logs are retained and that someone is alerted to unusual sign-ins or mass file access.
10. A written incident response plan
Why it matters: Under pressure, people need to know who to call and in what order — decisions made in the moment are usually the wrong ones.
How to verify: Check there is a one-page document naming who is contacted, who can isolate systems, and how affected parties are notified.
11. Vendor and third-party access review
Why it matters: Suppliers with remote access to your systems inherit your risk and extend it.
How to verify: List every third party with remote or system access, confirm each is still required, and that access is individually named rather than shared.
12. Data inventory and retention
Why it matters: Personal information you no longer need is pure risk with no upside.
How to verify: Identify where personal information is stored (systems, shared drives, mailboxes) and confirm old records are archived or removed on a schedule.
How to use this list
Work down it once and mark each control as in place, partly in place, or missing. Do not try to fix everything at once — multi-factor authentication, patching, and a tested backup close the majority of real-world risk on their own. Then revisit the list every six months, and whenever staff or systems change significantly.
Want us to run through it with you?
Book a free 20-minute readiness call. We will go through the checklist against your actual setup and tell you honestly where you stand and what to tackle first.
Need hands-on help? See our cyber security services for South African businesses.