Tag: SME

  • Why Business Wi‑Fi Keeps Dropping (and How to Fix It)

    Why Business Wi‑Fi Keeps Dropping (and How to Fix It)

    Introduction

    Frequent Wi‑Fi dropouts can paralyse productivity in small and medium-sized businesses. Whether it’s slow checkout systems, interrupted VoIP calls or staff unable to access cloud apps, unstable wireless connectivity costs time and money. This article explains the common reasons why business Wi‑Fi keeps dropping, practical checks you can perform, and when to call RandTech IT for experienced, fast resolution.

    Common causes of business Wi‑Fi dropouts

    1. Interference from other devices

    Office environments are full of electronics that share the same frequencies as Wi‑Fi. Microwaves, Bluetooth devices, cordless phones and some security cameras can interfere with 2.4 GHz and 5 GHz channels, causing intermittent disconnections.

    2. Poor access point placement

    Access points (APs) placed too close to walls, metal cabinets or large machinery will have reduced coverage. Placing APs in ceilings or central, elevated positions improves range and reduces dead zones.

    3. Overloaded access points

    Consumer-grade routers and a single AP serving many devices will struggle. When too many users or IoT devices connect to the same AP, throughput drops and connections can time out.

    4. Channel congestion

    In dense office buildings or business parks in Gauteng, multiple Wi‑Fi networks overlap. If neighbouring networks use the same channels, they compete and cause packet loss and disconnects.

    5. Firmware and configuration issues

    Outdated firmware, incorrect power settings, or misconfigured security (WPA2/WPA3 mismatches) can produce unstable behaviour. APs and controllers require maintenance like any network device.

    6. ISP and WAN problems

    Sometimes the wireless is fine but the internet link is unstable. Packet loss, high latency or intermittent ISP outages will look like Wi‑Fi dropouts to users accessing cloud services.

    7. Hardware faults and ageing equipment

    Access points, switches and cabling degrade. Faulty PoE injectors, overheating APs or failing switches can cause intermittent network disruptions.

    Practical checks you can run now

    Quick on-site tests

    • Walk the office with a laptop or phone and note where disconnects occur.
    • Restart the problematic AP and check logs for repeated errors.
    • Switch a device to mobile data to confirm whether the issue is local Wi‑Fi or the internet link.

    Use basic diagnostic tools

    • Run a continuous ping to a reliable external IP (e.g. 8.8.8.8) to detect packet loss.
    • Use a Wi‑Fi analyser app to view channel usage and signal strength across 2.4 GHz and 5 GHz bands.
    • Check AP and controller firmware versions and upgrade if supported and tested.

    Quick configuration checks

    • Ensure SSID settings, authentication and encryption are consistent across APs.
    • Confirm auto-channel selection is working or manually set less congested channels.
    • Set appropriate transmit power to avoid co-channel interference between your own APs.

    When to upgrade or redesign your Wi‑Fi

    If dropouts persist after basic troubleshooting, it may be time to consider a professional redesign. Signs you need an upgrade include frequent congestion, many mobile users, VoIP/UC instability, expanding branch offices or ageing hardware.

    Enterprise-grade APs and controllers

    Business-grade APs handle more concurrent clients, offer better radios and advanced features such as band steering, airtime fairness and seamless roaming. A central controller or cloud-managed solution helps maintain consistent settings and visibility.

    Proper site survey and capacity planning

    A wireless site survey maps coverage, identifies interference sources and defines AP placement. Capacity planning ensures the network supports peak loads and the applications your team relies on.

    Segmentation and QoS

    Separate guest networks from business traffic and apply Quality of Service for VoIP and critical cloud apps. Segmentation improves security and ensures essential services remain usable during congestion.

    Cost considerations for South African SMEs

    Upgrading Wi‑Fi need not break the bank. Typical costs depend on scale: a small office might invest in a few quality APs and a managed service contract, while larger sites require a full site survey and controller licences. Factor in reduced downtime and productivity gains when evaluating return on investment. RandTech IT can provide clear, localised cost estimates in Rands and recommend solutions that suit your budget.

    When to call RandTech IT

    Some problems benefit from experienced engineers rather than piecemeal fixes. Call RandTech IT when:

    • Dropouts affect voice, payments or customer-facing services
    • You need a reliable site survey and capacity plan
    • Hardware replacement, firmware upgrades or network redesign are required
    • You prefer fast resolution by experienced engineers rather than learning on your time

    FAQ

    Why does Wi‑Fi drop more during peak hours?

    Peak periods see more devices actively using bandwidth, causing AP congestion, channel contention and higher latency. Proper capacity planning and AP density reduce peak-time dropouts.

    Can a single faulty device cause the network to drop?

    Yes. A malfunctioning device can flood the network or cause RF noise. Isolating and disconnecting suspicious devices helps identify the culprit.

    Is 5 GHz always better than 2.4 GHz?

    5 GHz offers higher throughput and less interference but shorter range. A mixed approach with band steering provides the best overall performance for most offices.

    Will upgrading to enterprise gear solve all issues?

    Enterprise hardware helps but must be deployed correctly. A professional site survey, proper configuration and ongoing management are essential to address root causes.

    How quickly can RandTech IT respond to Wi‑Fi outages?

    RandTech IT prioritises fast resolution. Response times depend on support level and location, but our approach focuses on practical fixes by experienced engineers to restore services quickly.

    Conclusion

    Intermittent Wi‑Fi dropouts are usually solvable with a mix of practical checks, better hardware and thoughtful network design. For South African SMEs, minimising downtime and restoring reliable connectivity is critical for productivity and customer service. If your business Wi‑Fi keeps dropping and internal troubleshooting hasn’t helped, RandTech IT provides experienced engineers, clear recommendations and fast resolution aligned with your budget and operational needs.

    Contact RandTech IT for practical, experienced assistance with Wi‑Fi troubleshooting, site surveys and managed networking solutions. Let us help you stop dropouts and keep your business connected.

  • How to Improve Wi‑Fi Coverage in an Office — Practical Steps

    How to Improve Wi‑Fi Coverage in an Office — Practical Steps

    Introduction

    Good Wi‑Fi is essential for productivity in small and medium-sized South African businesses. Slow or inconsistent wireless access wastes time, disrupts cloud services and undermines collaboration. This guide explains practical steps to improve Wi‑Fi coverage in an office, tailored for SMEs that need reliable performance without unnecessary expense. RandTech IT specialises in fast, experienced support so your network works from day one.

    Understand the problem: diagnose before you buy

    Effective improvement starts with diagnosis. Replacing hardware without understanding coverage gaps or interference often wastes money.

    Perform a basic site survey

    • Walk the office with a laptop or smartphone and note areas with slow speeds or dropped connections.
    • Record where devices are used (desks, meeting rooms, warehouse areas) and peak usage times.
    • Look for obvious physical barriers: concrete walls, server cabinets, lifts and kitchens can all attenuate signals.

    Measure signal and interference

    Use free apps or low-cost tools to check RSSI (signal strength) and channel congestion. In dense office blocks in Johannesburg or other Gauteng suburbs, neighbouring networks can cause interference—especially on the 2.4 GHz band.

    Key causes of poor office Wi‑Fi

    • Poor access point (AP) placement or too few APs for office size.
    • Interference from neighbouring networks, Bluetooth devices, microwave ovens or heavy machinery.
    • Obstructions such as thick walls, glass partitions with metallic films, and server racks.
    • Older consumer-grade routers that cannot handle many concurrent users.

    Practical steps to improve coverage

    1. Optimise access point placement

    Access points should be ceiling mounted or high on walls, centrally located relative to users. Avoid placing APs inside enclosed cupboards or behind monitors. For larger or multi-room offices, plan for multiple APs with overlapping coverage but not on the same channel.

    2. Move to dual-band and use 5 GHz where possible

    Encourage devices and APs to use 5 GHz for bandwidth-sensitive applications. 5 GHz offers more channels and less interference, though with somewhat shorter range than 2.4 GHz. Reserve 2.4 GHz for legacy or IoT devices.

    3. Deploy a managed mesh or controller-based system

    Mesh Wi‑Fi or controller-managed APs simplify coverage across open-plan offices and multiple rooms. These systems provide automatic channel selection, power adjustment and handoff that reduce dead zones and improve roaming for mobile users.

    4. Replace consumer routers with business-grade equipment

    Consumer routers are cost-effective for homes but struggle under the concurrent device loads of a small office. Business-grade APs and switches offer better radios, load management and security features.

    5. Configure channels and power levels

    Avoid leaving APs on auto settings without verification. Manually set non-overlapping channels for 2.4 GHz (1, 6, 11) and select clear 5 GHz channels based on your survey. Adjust transmit power so APs don’t overpower adjacent cells and cause interference.

    6. Segment the network and prioritise traffic

    Create separate SSIDs or VLANs for guests, printers/IoT devices and business systems. Use Quality of Service (QoS) to prioritise VoIP, cloud backups or critical applications so slow connections don’t affect essential work.

    7. Use wired backhaul where possible

    Where APs are linked wirelessly, performance can degrade. Run Ethernet to AP locations when feasible—this provides reliable backhaul and frees wireless capacity for client devices.

    When to consider a professional site survey

    If basic steps don’t fix the problem, or your office supports many concurrent users, a professional RF site survey is worth the investment. A RandTech IT survey includes spectrum analysis, heatmaps of signal strength, and recommendations tailored to your office layout and business needs. This helps avoid over- or under-provisioning equipment.

    Cost considerations for South African SMEs

    Budget depends on office size, device density and performance expectations. Typical approaches include:

    • Low-cost improvements: move APs, change channels and update firmware—minimal cost.
    • Mid-range: add or replace APs with business-grade mesh units, run some Ethernet—R thousands depending on hardware and cabling.
    • High-end: full managed wireless deployment with controller, PoE switches and professional installation—higher upfront cost but better long-term ROI and support.

    RandTech IT can provide a clear estimate after a brief assessment so you understand the investment and likely benefits in Rands.

    Security and maintenance

    • Keep firmware and controller software up to date to address vulnerabilities.
    • Use strong WPA2/WPA3 encryption and unique passwords for employee and guest networks.
    • Schedule regular health checks and logs review to detect performance degradation early.

    Common office layouts and recommended approaches

    Small office (under 100 sqm)

    Often one or two business-grade APs ceiling-mounted will suffice. Prioritise a good central location and consider a small PoE switch.

    Open-plan space

    Multiple APs with managed roaming are advised. Use 5 GHz where device capabilities allow, and plan channels to avoid co-channel interference.

    Multi-floor or segmented office

    Deploy APs on each floor with wired backhaul. Avoid placing APs directly above/below each other where possible and coordinate channels carefully.

    Quick checklist to improve Wi‑Fi coverage

    1. Walk the office and map problem spots.
    2. Check device counts and peak usage.
    3. Move or add APs and choose 5 GHz for high-demand areas.
    4. Use business-grade APs and wired backhaul where possible.
    5. Segment networks and enable QoS for critical apps.
    6. Consider a professional site survey if issues persist.

    FAQ

    How many access points do I need for a small office?

    It depends on size, layout and device density. Many small offices can work with one to three well-placed APs; a short assessment will give an accurate recommendation.

    Can I use mesh Wi‑Fi at my office?

    Yes. Mesh systems suit open-plan spaces and where running Ethernet is difficult. For high device density, choose business-grade mesh with wired backhaul if possible.

    Will switching to 5 GHz solve my coverage problems?

    5 GHz reduces interference and provides higher throughput, but it has shorter range. Use it alongside 2.4 GHz and optimise AP placement for best results.

    Is a professional RF site survey necessary?

    Not always. Try basic fixes first. If problems persist, or you need reliable performance across many users, a professional survey saves time and money by producing targeted recommendations.

    How often should I update firmware and review settings?

    Check firmware quarterly and review network performance and logs at least twice a year, or more frequently if your business relies heavily on Wi‑Fi.

    Conclusion

    Improving Wi‑Fi coverage in an office requires a blend of practical actions—better AP placement, appropriate hardware, channel management—and, where necessary, professional assessment. Small and medium-sized businesses in South Africa can achieve reliable wireless performance without unnecessary expense by taking a methodical approach. RandTech IT focuses on experienced, fast resolutions so your team spends less time troubleshooting and more time working.

    Contact RandTech IT to arrange a quick assessment or a professional site survey. Our engineers deliver practical, experienced assistance to get your office Wi‑Fi working reliably.

  • Firewall Requirements for a Small Business in South Africa

    Firewall Requirements for a Small Business in South Africa

    Introduction

    For South African small and medium-sized businesses (SMEs), a firewall is a fundamental element of network defence. With increasing cyber threats and regulatory expectations, understanding firewall requirements for a small business helps protect customer data, maintain uptime and keep compliance efforts on track. This guide explains what SMEs in South Africa should consider when selecting, configuring and maintaining firewalls—presented in clear, practical terms for business owners and IT decision-makers.

    Why a firewall matters for small businesses

    Firewalls control the traffic between your internal network and external networks, reducing the risk of unauthorised access, data leakage and malware infections. For SMEs that operate in industries such as professional services, retail, or e-commerce, the consequences of a breach can include reputational damage, regulatory fines and operational disruption.

    Local context: South African risks and costs

    Threats are global but consequences are local. SMEs in Johannesburg and across Gauteng are frequent targets because of high business concentration. While exact breach costs vary, prevention through practical controls such as firewalls is generally far more cost-effective than remediation.

    Core firewall requirements for a small business

    Not every business needs an enterprise appliance. However, there are core capabilities every small business firewall should provide.

    • Stateful packet inspection: Basic traffic filtering that tracks connection state to block suspicious packets.
    • Network address translation (NAT): Hides internal IP addresses from the public internet.
    • VPN support: Secure remote access for staff working from home or on the road.
    • Application awareness: Ability to identify and control traffic by application (web, email, cloud services).
    • Intrusion prevention (IPS): Detects and blocks known attack patterns.
    • Web filtering: Block malicious or inappropriate sites to reduce risk.
    • Logging and reporting: Clear logs and simple reports for troubleshooting and compliance.

    Unified Threat Management (UTM) vs Next-Generation Firewall (NGFW)

    UTM appliances bundle multiple security features—AV, URL filtering, IPS—into an affordable package. NGFWs add stronger application control and deeper inspection. For many South African SMEs, a modern UTM with optional NGFW features strikes the right balance between cost and capability.

    Selecting the right firewall for your business

    Consider these factors when choosing hardware or a managed service.

    Business size and throughput

    Match the firewall’s throughput to your internet connection and typical usage. If your office uses a 100 Mbps connection and plans VoIP or cloud backups during business hours, factor in peak loads and growth projections.

    Number of users and remote access needs

    Licence-based models charge per user or VPN tunnel. Calculate concurrent remote users and ensure the solution supports secure mobile access without degrading performance.

    Budget and total cost of ownership

    Initial hardware cost is one part; include subscription fees for threat intelligence, antivirus updates and technical support. In South Africa, compare quotes in rand and factor transport and local support availability.

    Integration with existing systems

    Ensure the firewall integrates with your network switches, Wi-Fi controllers and any cloud services you use. Compatibility reduces configuration complexity and improves reliability.

    Configuration best practices

    Correct configuration is as important as choosing the right device.

    • Least privilege principle: Only open ports and services that are strictly necessary.
    • Segment your network: Separate guest Wi‑Fi, POS systems and administrative networks to limit lateral movement if an endpoint is compromised.
    • Use strong VPN settings: Prefer modern protocols (IKEv2, OpenVPN, or WireGuard) and enforce multi-factor authentication for remote access.
    • Apply regular security policies: Schedule updates for signatures and firmware during maintenance windows.
    • Enable logging and alerts: Configure actionable alerts and retain logs for incident investigation.

    Example rule set for a small office

    A practical rule set might include:

    1. Allow outbound HTTP/HTTPS from internal VLANs to the internet.
    2. Deny inbound traffic from the internet unless explicitly required (e.g., port 443 to a published web server behind a DMZ).
    3. Allow VPN traffic to the internal admin VLAN with MFA enforced.
    4. Block known malicious IP ranges and risky URL categories.

    Maintenance and monitoring

    Firewalls are not set-and-forget devices. Regular maintenance prevents drift and ensures threats are mitigated.

    • Patch firmware: Apply vendor updates promptly but test them in a controlled window.
    • Renew subscriptions: Keep threat feeds and signatures current; expired subscriptions diminish protection.
    • Review rules quarterly: Remove obsolete rules and fine-tune policies based on logs.
    • Backup configurations: Store encrypted backups of configurations off-site for quick recovery.
    • Use monitoring tools: Simple uptime and security monitoring detect issues before they become incidents.

    When to consider managed firewall services

    Many SMEs benefit from handing firewall management to specialists. Managed services provide:

    • Experienced engineers who implement and maintain policies.
    • 24/7 monitoring and response for alerts.
    • Consolidated billing and predictable monthly costs in rand.
    • Faster resolution times—avoiding on-the-job learning during an incident.

    If your business lacks in-house networking skills, a trusted managed provider keeps systems secure while you focus on core operations.

    Compliance and legal considerations

    South African businesses must consider POPIA (the Protection of Personal Information Act) when storing or processing personal data. A correctly configured firewall contributes to reasonable technical safeguards under POPIA by preventing unauthorised access and recording access attempts for audit purposes.

    Practical checklist before deployment

    • Inventory network devices and endpoints.
    • Map services that require inbound or outbound access.
    • Define acceptable use and remote access policies.
    • Budget for subscriptions and support in rand.
    • Plan staged deployment with backup configuration and rollback steps.

    FAQ

    • How much should a small business spend on a firewall?

      Costs vary. Expect a modest initial outlay for hardware (or a small monthly fee for a managed service) plus subscription fees for threat feeds. Budget for both capital and recurring expenses in rand.

    • Can a cloud service replace an on-premises firewall?

      Cloud security services complement but do not always replace an on-premises firewall—especially where local network segregation, VPN termination or edge protection is required.

    • How often should firewall rules be reviewed?

      Review rules at least quarterly, or immediately after significant changes to your network or applications.

    • What is the minimum feature set for a POS-enabled business?

      Ensure VLAN segmentation, strict inbound/outbound rules, PCI-compatible logging, and web filtering to protect payment systems.

    • Is managed firewall support worth it for a 10-person company?

      Yes, if you lack dedicated IT staff. Managed support provides quicker, experienced responses that reduce risk and downtime.

    Conclusion

    Firewall requirements for a small business are practical and achievable. Focus on essential features—stateful inspection, VPNs, IPS, logging and web filtering—combined with sound configuration, regular maintenance and clear policies. Where internal expertise is limited, a managed firewall service gives you experienced engineers and predictable costs in rand, removing the need to learn on the client’s time.

    If you’d like a practical assessment of your current firewall posture or assistance selecting and managing a solution, contact RandTech IT. Our engineers deliver fast, experienced support so your business stays secure and productive.

  • IT setup checklist for a new business in South Africa

    IT setup checklist for a new business in South Africa

    Introduction

    Starting a new business in South Africa means juggling customers, compliance and cashflow. One critical area that’s often underestimated is IT. Getting your technology right from day one reduces costly downtime, protects client data and keeps your team productive. This IT setup checklist for a new business walks South African small and medium-sized businesses through practical steps to set up reliable, secure and scalable IT.

    1. Define your business needs

    A clear understanding of needs prevents over- or under-investment. Start by answering core questions:

    • What applications will staff use daily (email, accounting, CRM)?
    • How many users and devices will you support now and in 12–24 months?
    • What regulatory or industry requirements apply (POPIA, financial reporting)?

    Documenting these requirements informs choices on hardware, connectivity, cloud services and security.

    2. Hardware and devices

    Choose devices that match job roles and budget. Prioritise reliability and warranty support.

    Essential hardware

    • Business-grade laptops or desktops with adequate RAM and SSD storage.
    • Peripherals: monitors, keyboards, mice, headsets for remote calls.
    • Network hardware: a business-class router and managed switch if you have multiple wired devices.
    • Uninterruptible Power Supplies (UPS) for critical equipment like servers and core networking devices, especially in areas prone to load-shedding.

    Local considerations

    In Gauteng and Johannesburg, expect stable metropolitan connectivity but plan for load-shedding and occasional outages. UPS and graceful shutdown procedures protect data and hardware.

    3. Internet and networking

    Connectivity is business-critical. Treat your network as a priority, not an afterthought.

    Choose the right connection

    • Assess available links: fibre, fixed wireless, LTE. Fibre is ideal where available for its reliability and speed.
    • Consider a secondary backup connection (LTE) for failover during primary outages.

    Secure your network

    • Use business-class firewalls and enable regular firmware updates.
    • Separate guest Wi‑Fi from internal networks and use WPA3 if supported.

    4. Cloud services and software

    Cloud services reduce upfront costs and simplify management, but choose and configure them carefully.

    Common cloud choices

    • Email and collaboration: Microsoft 365 or Google Workspace for business email, calendars and document collaboration.
    • Accounting: cloud accounting software that integrates with your bank and tax workflows.
    • File storage and backups: choose a cloud storage provider with versioning and encryption.

    Licence and cost control

    Purchase business licences rather than consumer plans for support and compliance. Track licences centrally to avoid unexpected renewals or gaps.

    5. Security and compliance

    Security is not optional. Implement layered controls to protect data and reputation.

    Technical controls

    • Endpoint protection: install reputable antivirus/EDR on all devices.
    • Multi-factor authentication (MFA): enforce MFA for email, admin accounts and cloud services.
    • Patch management: ensure operating systems and applications receive timely updates.

    Policies and awareness

    • Create clear acceptable use, password and remote access policies.
    • Train staff on phishing, social engineering and safe data handling—regular short sessions are more effective than one-off training.

    6. Backup and disaster recovery

    Backups are your last line of defence against data loss and ransomware. Make a plan and test it.

    Backup best practices

    • 3-2-1 rule: keep at least three copies of data, on two different media, with one offsite copy.
    • Automate backups and verify restorability with periodic restore tests.
    • Consider cloud backups with immutable snapshots to protect against ransomware.

    7. User accounts and permissions

    Limit privileges and centralise account management.

    Account setup

    • Create individual user accounts—avoid shared logins for accountability.
    • Use role-based access controls (RBAC) to grant least privilege required for tasks.
    • Regularly review and deactivate accounts for former staff or contractors.

    8. Backup communications and continuity planning

    Prepare for scenarios where normal channels fail. A simple continuity plan reduces panic and enables faster recovery.

    Practical steps

    • Maintain an emergency contact list with vendors, ISP and key staff numbers.
    • Document recovery procedures for critical systems and store them securely offline.
    • Plan for remote work contingencies with VPN or secure remote desktop solutions.

    9. Vendor selection and contracts

    Choose suppliers who understand SME needs and offer clear SLAs.

    What to look for

    • Fast response times and experienced engineers—avoid suppliers that learn on your time.
    • Clear pricing and scope for installation, support and maintenance.
    • References from local businesses and experience with South African compliance (POPIA).

    10. Ongoing management and monitoring

    IT setup is not a one-time task. Continuous management keeps systems healthy.

    Recommended activities

    • Implement remote monitoring and management (RMM) for proactive alerts.
    • Schedule regular maintenance windows for updates and reviews.
    • Conduct annual IT reviews aligned to business growth plans and budgets in ZAR.

    FAQ

    How much should a small business budget for initial IT setup?

    Costs vary by requirements. Budget for reliable hardware, business internet, licensing and a basic security stack. Get quotes tailored to your user count and services rather than relying on off-the-shelf estimates.

    Do I need an on-premises server?

    Most new SMEs can use cloud services instead of on-premises servers. Consider local servers only if you have specific latency, compliance or legacy application needs.

    How often should backups be tested?

    Test backups at least quarterly, or more frequently for critical systems. A verified restore is the only proof a backup strategy works.

    Can I use consumer-grade Wi‑Fi and equipment?

    Consumer devices may be cheaper but lack business features, security and support. For reliability and manageability, choose business-grade networking equipment.

    What is the minimum security I should implement on day one?

    At minimum: enforce MFA, install endpoint protection, keep systems patched, and implement secure passwords and account controls.

    Conclusion

    An organised IT setup protects your new business from avoidable downtime, security incidents and unnecessary costs. Addressing hardware, connectivity, cloud choices, security and backups from the start makes IT an enabler for growth, not a recurring headache.

    If you need practical, experienced help to implement this IT setup checklist for your South African business, RandTech IT can assist. Our engineers prioritise fast, expert resolution so you can focus on running your business—contact RandTech IT to get started.

  • Microsoft 365 Backup Retention Explained for SA SMEs

    Microsoft 365 Backup Retention Explained for SA SMEs

    Introduction

    Understanding Microsoft 365 backup retention explained is essential for South African small and medium-sized businesses. Many organisations assume Microsoft fully protects their data, but the reality is more nuanced. This article explains what Microsoft covers, common gaps, recommended retention strategies for SMEs, and practical steps you can take in Gauteng and across South Africa to reduce risk and meet compliance needs.

    What Microsoft 365 covers — and what it doesn’t

    Microsoft provides a range of built-in data protection features across Exchange Online, SharePoint, OneDrive and Teams. These include versioning, retention policies, and basic recovery options. However, Microsoft’s shared responsibility model means customers retain responsibility for long-term retention, point-in-time recovery, and protecting against accidental deletion, malware and insider threats.

    Included features

    • Version history for files in OneDrive and SharePoint.
    • Recycle Bin retention for deleted items (limited timeframes).
    • Retention labels and policies for compliance scenarios.
    • Basic restore tools for administrators.

    Common gaps to be aware of

    • Microsoft is not a true backup provider — point-in-time restores beyond the retention windows can be difficult.
    • Deleted items may be purged after the recycle bin period, making recovery impossible without backups.
    • Ransomware and mass-deletion attacks can propagate through connected services.
    • Regulatory or contractual retention requirements may exceed Microsoft’s default settings.

    Key retention concepts explained

    To make sensible retention decisions, SMEs should understand a few core concepts:

    Retention policies vs backups

    Retention policies prevent deletion or preserve data for a set period to meet compliance needs. Backups create independent copies that allow point-in-time restores even if original items are modified or removed.

    Versioning and point-in-time recovery

    Versioning keeps prior versions of files, but it is not a substitute for backup because versions can be removed or become impractical for large-scale recovery.

    Retention periods

    Retention periods should reflect legal, tax and operational requirements. In South Africa, businesses may need to retain financial records or employment documents for several years — often longer than Microsoft’s default windows.

    Practical retention strategies for South African SMEs

    Apply a layered approach combining Microsoft capabilities with independent backups to achieve resilience and compliance.

    1. Assess legal and operational requirements

    • Identify documents and mailboxes that require long-term retention (e.g., tax records, contracts).
    • Confirm retention durations dictated by SARS, labour regulations or industry rules.

    2. Configure Microsoft 365 retention and labels

    • Use retention labels to classify content and apply minimum retention and deletion rules.
    • Apply policies to SharePoint sites, OneDrive accounts and Exchange mailboxes where appropriate.

    3. Implement third-party backups

    Choose a backup solution that offers:

    • Automated, scheduled backups of Exchange, SharePoint, OneDrive and Teams.
    • Point-in-time restore capability and long-term archival storage.
    • Encryption in transit and at rest, with reliable role-based access for restores.

    4. Define retention tiers and storage locations

    • Short-term tier: quick restores for operational continuity (days to months).
    • Long-term tier: archival storage for compliance (years). Consider on-prem or local region cloud storage for data sovereignty concerns.

    5. Test restore procedures regularly

    Backups are only useful if restores work. Schedule regular restore tests to validate procedures, timing and data integrity.

    Cost considerations for SMEs in South Africa

    Budget realistically. Backup costs vary by provider, retention period and storage class. For many SMEs the goal is to balance affordability with risk tolerance. Factor in:

    • Monthly subscription fees for backup software or services.
    • Storage costs for long-term archives.
    • Internal time to manage and test backups.

    Discuss options with your IT partner to compare local versus international storage, and any implications for data access speeds and compliance.

    Checklist: Implementing a robust Microsoft 365 retention plan

    1. Audit current Microsoft 365 settings and data types.
    2. Map legal and business retention requirements.
    3. Apply retention labels and policies where possible.
    4. Deploy an independent backup solution for point-in-time recovery.
    5. Define retention tiers and archival locations.
    6. Test restores quarterly and after major changes.
    7. Document procedures and assign responsibilities.

    FAQs

    Do I need a separate backup if I use Microsoft 365?

    Yes. Microsoft protects platform availability and provides some data retention tools, but it does not replace dedicated backups for long-term retention or comprehensive point-in-time recovery.

    How long does Microsoft keep deleted Exchange items?

    Retention for deleted items depends on mailbox settings and retention policies. Default recycle bins are time-limited and may not meet all compliance needs, so verify and extend retention where required.

    Can I meet SARS or labour retention rules with Microsoft retention policies?

    Possibly, but you should confirm that applied retention periods and auditability match statutory requirements. Independent backups provide stronger assurance for long-term legal holds.

    Is local (South African) storage necessary?

    Local storage can help address data sovereignty concerns and may reduce latency. Whether it’s necessary depends on your industry, contractual obligations and risk appetite.

    How often should I test restores?

    Test restores at least quarterly, and after any significant change to your environment or backup configuration.

    Conclusion

    Microsoft 365 backup retention explained shows that while Microsoft provides useful tools, SMEs must take active responsibility for long-term retention and recoverability. By combining retention policies with independent backups, clearly defined retention tiers, and regular restore testing, South African businesses can minimise risk and meet compliance requirements without disrupting operations.

    If you’d like practical help implementing or reviewing your Microsoft 365 retention and backup strategy, contact RandTech IT. Our experienced engineers provide fast, effective support so you get reliable protection without learning on your time.

  • Best Backup Strategy for a South African Small Business

    Best Backup Strategy for a South African Small Business

    Introduction

    Data loss can halt a small business in South Africa faster than most owners expect. Whether caused by ransomware, hardware failure, accidental deletion or a physical incident in your office in Johannesburg or elsewhere in Gauteng, the right backup strategy reduces downtime and financial risk. This guide explains practical, cost-effective steps for South African small and medium-sized businesses to develop a resilient backup and recovery plan.

    Why a tailored backup strategy matters for South African SMEs

    Small businesses have limited resources and less room for disruption. A generic backup approach often fails to meet local realities — inconsistent internet, intermittent power outages, and regulatory or client data requirements. A tailored strategy balances cost, speed of recovery and data protection while reflecting local operational constraints.

    Common local risks to consider

    • Ransomware and cybercrime targeting SMBs
    • Load shedding and unstable power affecting on-premises servers
    • Hardware failure without quick replacement options
    • Limited IT staff leading to delayed recovery

    Principles of an effective backup strategy

    Apply clear principles when building your plan. These guide tool selection and operational routines.

    1. The 3-2-1 rule

    Keep at least three copies of your data: the primary plus two backups. Store copies on two different media, and keep at least one copy offsite. For many South African SMEs, this means local on-site backup plus cloud backups hosted in a reputable region.

    2. Regular, automated backups

    Automation reduces human error. Schedule backups based on the criticality of data: daily or continuous for transactional systems, and less frequent for archival data.

    3. Secure and encrypted backups

    Encrypt data both in transit and at rest. Use strong key management and ensure cloud providers comply with security standards. This minimises exposure in case backups are accessed or intercepted.

    4. Test recovery regularly

    A backup that cannot be restored is useless. Regularly test restores to verify integrity and to ensure your team can execute recovery procedures quickly.

    Designing your backup layers

    An effective strategy uses multiple complementary layers to meet recovery time objectives (RTO) and recovery point objectives (RPO).

    Layer 1: Local backups for fast recovery

    Keep a local copy for quick restores. Options include external NAS devices or on-premises servers with RAID and regular snapshots. Local restores are fastest after simple incidents like accidental deletion.

    Layer 2: Offsite cloud backups for disaster resilience

    Store encrypted backups in the cloud to protect against fire, theft or major hardware failure. Choose providers with data centres in compliant locations and strong SLAs. For limited internet bandwidth, consider hybrid approaches that seed initial backups physically and then replicate incremental changes.

    Layer 3: Immutable or air-gapped backups for ransomware protection

    Immutable backups cannot be altered or deleted for a defined period. Air-gapped solutions (physically disconnected copies) add another barrier against ransomware that seeks and destroys backups.

    Practical implementation steps

    1. Identify critical data and systems: Prioritise POS systems, accounting records, customer databases and core documents.
    2. Set RTOs and RPOs: Determine acceptable downtime and data loss for each system.
    3. Choose tools and vendors: Mix local NAS, cloud backup and immutable storage. Consider managed backup services if you lack internal expertise.
    4. Automate schedules and retention: Configure daily, weekly and monthly retention aligned with compliance or tax requirements.
    5. Encrypt and test: Ensure encryption, then run periodic restore drills and document procedures.

    Cost considerations for South African SMEs

    Budget choices often determine the balance between speed and expense. Cloud storage costs are typically charged monthly or by usage. Factor in:

    • Monthly cloud storage and egress fees
    • One-time hardware for local NAS or external drives
    • Managed service fees if outsourcing backups
    • Staff time for testing and maintenance

    Work with an IT partner to model costs in rand and choose the most cost-effective mix for your recovery objectives.

    Compliance and data sovereignty

    Ensure backups comply with relevant legislation and client contracts. While South Africa does not mandate local hosting for all data, some industries and clients do require data to remain within the country. When necessary, select cloud providers with South African datacentre options or ensure contractual controls around data handling.

    Choosing between in-house and managed backup services

    Small businesses often lack the time and specialised skills to maintain robust backup processes. Managed services provide experienced engineers, proactive monitoring and faster resolution — aligning with RandTech IT’s approach of resolving issues quickly rather than learning on the client’s time.

    Signs you should use a managed service

    • No dedicated IT staff or limited backup expertise
    • High reliance on critical business systems
    • Need for rapid recovery SLAs
    • Concern about ransomware and secure key management

    Checklist: Building your backup plan

    • Inventory critical systems and data
    • Define RTOs and RPOs per system
    • Implement 3-2-1 backup architecture
    • Enable encryption and access controls
    • Schedule automated backups and retention
    • Test restores quarterly or after major changes
    • Document procedures and escalation paths

    FAQ

    How often should a small business run backups?

    It depends on the system. Critical transactional systems should be backed up continuously or daily; less critical files can follow daily or weekly schedules. Define RPOs to decide frequency.

    Can I rely solely on cloud backups?

    Cloud backups are resilient but relying only on them can increase recovery time and costs if your internet is slow. A hybrid approach with a local copy for quick restores is usually better.

    What is an acceptable retention period?

    Retention depends on compliance and business needs. Common patterns include daily backups kept for 30 days, weekly for three months, and monthly for one year, with longer archiving as required for legal or tax reasons.

    How do I protect backups from ransomware?

    Use immutable or air-gapped backups, enforce strong access controls, keep backups offline when possible, and ensure backup credentials are separate from production accounts.

    How much will a proper backup strategy cost?

    Costs vary by data volume, chosen tools and whether you use managed services. Work with an IT partner to estimate monthly cloud and managed-service fees plus any one-off hardware expenses in rand.

    Conclusion

    A practical backup strategy protects your business against common risks in South Africa while balancing budget and recovery needs. Use the 3-2-1 principle, combine local and cloud layers, test restores regularly and consider a managed service if you lack in-house expertise. That approach reduces downtime and helps you recover quickly with minimal disruption.

    If you’d like practical, experienced assistance to design and implement the best backup strategy for your South African small business, contact RandTech IT. Our engineers prioritise fast, expert resolution so your business stays operational and secure.

  • How to Prevent Ransomware Attacks: Practical Steps for SMEs

    How to Prevent Ransomware Attacks: Practical Steps for SMEs

    Introduction

    Ransomware is a leading cyber threat for South African small and medium-sized businesses (SMEs). An attack can halt operations, expose sensitive data and lead to significant recovery costs. As a business owner or IT decision-maker, knowing how to prevent ransomware attacks is essential. This article offers clear, practical steps tailored to South African SMEs, with a focus on achievable controls, sensible investments and how managed IT support can reduce risk.

    Understand the threat and your risk

    Before implementing controls, assess where your business is most vulnerable. Ransomware typically gains access through phishing emails, unpatched systems, weak remote access configurations and poor backup practices.

    Conduct a basic risk assessment

    • List critical data and systems (financials, payroll, customer data).
    • Identify access points (email, remote desktop, cloud apps).
    • Evaluate business impact if each system became unavailable.

    Understanding impact helps prioritise protections and budget.

    Implement strong endpoint protection

    Endpoints—laptops, desktops and servers—are common ransomware entry points. Effective endpoint protection reduces the chance of successful infection.

    Use reputable antivirus and endpoint detection

    • Choose solutions with real-time protection and behavioural detection.
    • Ensure centralised management so policies and updates are consistent.

    Control administrative privileges

    Limit local admin rights. Users should run day-to-day tasks with standard accounts; elevate privileges only when necessary. Reduced privileges limit malware impact.

    Keep systems and software patched

    Unpatched software is a frequent attack vector. Regular patching prevents attackers exploiting known vulnerabilities.

    Establish a patch management routine

    • Prioritise critical systems and internet-facing services.
    • Schedule regular patch windows and use automated deployment where possible.
    • Test patches on non-critical devices before broad rollout.

    Secure remote access and network architecture

    As more staff use cloud services and remote access from Johannesburg, the Western Cape or elsewhere, securing connections and segmenting networks matters.

    Use VPNs and multi-factor authentication (MFA)

    • Require MFA for remote access, email and admin portals.
    • Use a reputable VPN or secure remote access solution for staff working offsite.

    Network segmentation and least privilege

    Segment your network so a breach in one area does not grant broad access. Keep guest Wi-Fi separate from business systems and isolate critical servers.

    Practice robust backup and recovery

    Backups are the most reliable defence against paying a ransom. A tested recovery plan gets you back to business quickly.

    Follow the 3-2-1 backup rule

    • Keep at least three copies of data.
    • Store backups on two different media types.
    • Keep one copy offsite and offline where possible.

    Test restores regularly

    Backups are only useful if you can restore them. Schedule periodic restore tests and document recovery steps, including estimated recovery time objectives (RTOs).

    Train staff and build a security culture

    Human error remains the top cause of incidents. Practical, role-focused training reduces risk and helps staff recognise attacks early.

    Provide targeted phishing awareness

    • Run short, regular training sessions rather than long annual workshops.
    • Simulate phishing attacks to measure and improve awareness.

    Define clear incident reporting processes

    Make it easy for employees to report suspicious emails or behaviour. Early reporting can stop an attack from spreading.

    Develop policies and incident response plans

    Preparation reduces confusion during an incident. Documented policies and tested response plans shorten downtime and preserve evidence for investigation.

    Key elements of an incident response plan

    • Roles and contact list, including external support (IT partner, legal, forensic).
    • Containment steps to isolate infected devices.
    • Communication templates for staff and customers.
    • Post-incident review and remediation actions.

    Consider cyber insurance and legal obligations

    Cyber insurance can help with recovery costs, but policies vary. Ensure your insurer recognises your security controls and understand requirements under POPIA for personal data breaches.

    Leverage managed IT and security services

    Many SMEs lack the capacity to maintain 24/7 security. A managed service provider (MSP) can deliver experienced, rapid response and continuous monitoring without hiring full-time specialists.

    What a good MSP should provide

    • Proactive patching, endpoint management and security monitoring.
    • Regular backups with tested restores and documented RTOs.
    • Clear escalation procedures and fast incident response by experienced engineers.
    • Guidance on POPIA compliance and local regulatory expectations.

    Practical checklist for immediate action

    1. Enable MFA across email and remote access.
    2. Ensure daily backups with an offline copy and test restores.
    3. Update and patch operating systems and critical apps.
    4. Install centrally managed endpoint protection.
    5. Run quick staff awareness sessions and set an easy reporting channel.

    Conclusion

    Preventing ransomware attacks requires a mix of technology, processes and people-focused measures. For South African SMEs, sensible prioritisation—backups, patching, MFA, staff training and working with an experienced managed IT partner—delivers the best protection for limited budgets. Practical actions today reduce the chance of costly disruption tomorrow.

    FAQ

    1. Can I rely on backups alone to recover from ransomware?

    Backups are essential but must be correctly implemented and tested. Offsite and offline copies plus documented restore procedures are critical. Without tested restores, backups may not help.

    2. Should my business pay the ransom if hit?

    Paying is risky and often discouraged. Payment does not guarantee full recovery or data deletion. In many cases, recovery from verified backups and forensic help is a safer route.

    3. How much should an SME budget for ransomware protection?

    Budgets vary by size and risk profile. Focus on high-impact controls first: backups, MFA, patching and endpoint protection. Working with an MSP can convert fixed costs into predictable monthly fees.

    4. Is cyber insurance worth it for small businesses?

    Cyber insurance can help with costs related to recovery and legal exposure, but policies differ. Ensure your security posture meets insurer requirements and maintain documentation of controls.

    5. How often should we test our incident response plan?

    At minimum, test annually. More frequent tabletop exercises—every six months—are recommended for higher-risk operations or rapidly changing environments.

    6. How quickly can an MSP respond to a ransomware incident?

    Response times depend on the MSP contract. Choose a provider that guarantees fast escalation to experienced engineers and has local knowledge of South African business constraints.

    Contact RandTech IT for experienced, practical assistance. If you want to harden your systems, test your backups or set up an incident response plan, RandTech IT’s engineers can help quickly and professionally. Contact us to discuss a pragmatic security plan tailored to your SME’s needs.

  • Business email compromise warning signs for SMEs

    Business email compromise warning signs for SMEs

    Introduction

    Business email compromise (BEC) is a growing threat to South African small and medium-sized businesses. Unlike noisy ransomware or mass phishing campaigns, BEC is often targeted, quiet and financially damaging. For SMEs in Johannesburg, Pretoria and across Gauteng, recognising early warning signs is essential to prevent costly mistakes and downtime. This guide explains common indicators of BEC, practical prevention measures suitable for local businesses, and steps to take if you suspect compromise.

    What is business email compromise?

    Business email compromise is a type of cybercrime where attackers gain access to legitimate business email accounts or convincingly spoof them to defraud a company. Their typical goals include wire transfer fraud, invoice diversion, payroll manipulation or harvesting credentials for further access. Because BEC attacks frequently impersonate trusted colleagues, suppliers or executives, they can bypass basic defences.

    Common warning signs of BEC

    Timely detection often depends on staff vigilance. Teach your team to look for subtle anomalies rather than obvious malware alerts.

    Unusual payment requests or urgent financial demands

    • Requests to change banking details for recurring suppliers.
    • Emails demanding immediate payment or asking to bypass normal approval processes.
    • Last-minute “urgent” invoices with pressure to transfer funds.

    Sender anomalies and spoofing indicators

    • From addresses that look similar but contain slight misspellings (for example, finance@acme-co[.]za vs finance@acmeco[.]za).
    • Display names that match senior staff while the actual email domain differs.
    • Unexpected forwarding rules or auto-replies set by the sender.

    Requests for sensitive information

    Emails asking for employee tax numbers, ID details, banking credentials or password resets are red flags. BEC actors often harvest personal data to bypass two-factor authentication or social-engineer further access.

    Strange language, tone or writing style

    • Messages that deviate from the sender’s usual tone or contain awkward phrasing.
    • Generic greetings instead of personalised salutations.
    • Uncharacteristic urgency, threats, or over-politeness intended to manipulate.

    Irregular email behaviour and technical signs

    • Large volumes of outbound email from a user who normally sends few messages.
    • Unexpected login notifications, especially from foreign IP addresses or unusual locations.
    • New mail rules created to delete or divert responses.

    Why South African SMEs are attractive targets

    SMEs often have limited IT resources and mature processes, making them appealing to attackers. Additionally, local business practices—such as relying on email for payment instructions and informal approval chains—can be exploited. For companies operating in Gauteng, where many suppliers and clients are interconnected, fraud can spread quickly through networks of trust.

    Practical prevention steps for SMEs

    Protection doesn’t need to be complicated or expensive. Focus on layered controls, staff training and clear financial procedures.

    Technical controls

    • Enable multi-factor authentication (MFA) for all accounts, including administrators.
    • Use modern email filtering and anti-spoofing technologies: SPF, DKIM and DMARC.
    • Monitor login activity and implement conditional access where possible.
    • Keep systems patched and maintain device endpoint protection.

    Policy and process

    • Require dual authorisation for payments above defined thresholds—set thresholds in rand appropriate to your business size.
    • Verify bank account changes through a secondary channel such as a phone call to a known number.
    • Limit public exposure of staff email addresses and organisational charts on the website.

    Staff training and culture

    Regular, practical training helps staff recognise suspicious messages. Simulated tests are useful, but pair them with coaching and clear reporting paths so employees feel safe raising concerns without blame.

    How to respond if you suspect a compromise

    Act quickly to contain damage and gather evidence. A calm, methodical response improves chances of recovery.

    Immediate containment steps

    • Isolate affected accounts: force password resets and revoke active sessions.
    • Disable any suspicious mail forwarding rules and review send-as permissions.
    • Notify your bank immediately if payments were redirected and request a recall if possible.

    Investigate and document

    • Collect headers and logs to determine origin and timeline of the incident.
    • Identify any data exfiltration, credential theft or additional compromised accounts.
    • Preserve evidence for potential police or banking investigations.

    Report and recover

    • Report fraudulent transactions to your bank and file a case with the South African Police Service if funds were lost.
    • Notify affected clients or suppliers where appropriate, with factual guidance on next steps.
    • Review and update controls to prevent recurrence, including changes to policies and technical settings.

    Case scenario: invoice diversion in a small Gauteng supplier

    A Pretoria-based supplier received what appeared to be an email from a long-term customer requesting payment to a new account. The accounts clerk did not verify via phone and the supplier paid R120,000. The transaction was later flagged as fraudulent. Recovery depended on rapid bank engagement and a police case. The business then implemented mandatory two-person authorisation for all payments above R10,000 and enabled MFA for finance accounts.

    Key takeaways

    • BEC relies on trust and subtlety—train staff to question unusual requests.
    • Technical controls like MFA and SPF/DKIM/DMARC reduce risk significantly.
    • Clear financial procedures, verification steps and rapid incident response limit damage.

    FAQ

    1. Q: What immediate sign should trigger an investigation?

      A: Any unexpected request to change banking details or an urgent payment request that bypasses normal approvals should be investigated immediately.

    2. Q: Can email filtering stop all BEC attacks?

      A: No. Filtering helps but BEC often uses legitimate accounts or carefully crafted spoofing. Combine filtering with MFA, verification processes and staff training.

    3. Q: How quickly should we act if we detect suspicious activity?

      A: Immediately. Reset passwords, revoke sessions, notify your bank and preserve logs. Early action improves chances of stopping transfers and recovering funds.

    4. Q: Is MFA enough to prevent BEC?

      A: MFA significantly reduces risk but is not foolproof. Attacks that use social engineering or SIM swapping underline the need for layered controls.

    5. Q: Who should handle BEC incidents in an SME?

      A: Ideally a small incident response team: a senior manager, the IT lead and a finance representative. External technical support can help preserve evidence and restore security.

    Conclusion

    Business email compromise is a realistic threat for South African SMEs, but it is manageable. By recognising warning signs, reinforcing technical defences and enforcing sound financial procedures, businesses can reduce risk and respond effectively when incidents occur. RandTech IT focuses on fast, experienced response and practical controls so your team can get back to business with minimal disruption.

    If you suspect a compromise or want to strengthen your email defences, contact RandTech IT for practical, experienced assistance tailored to South African SMEs.

  • Small-business cybersecurity checklist for South Africa

    Small-business cybersecurity checklist for South Africa

    Introduction

    Small and medium-sized businesses (SMBs) in South Africa face growing cyber threats: phishing, ransomware, stolen credentials and non-compliance with POPIA. Many attacks exploit basic gaps rather than sophisticated zero-day flaws. This checklist gives practical, prioritised steps that South African SMBs can apply immediately to reduce risk, protect customer data and keep operations running. RandTech IT brings experience resolving urgent incidents quickly — use this as a working guide and contact us if you need hands-on help.

    1. Establish basic cyber hygiene

    Cyber hygiene is the foundation. These measures are low cost and high impact.

    Use strong, unique passwords and a password manager

    Ensure all employees use strong passwords and unique credentials for work accounts. A business-grade password manager makes this manageable and enables secure sharing of logins.

    Enable multi-factor authentication (MFA)

    MFA should be enabled on email, cloud services, VPNs and remote admin tools. Even SMS-based MFA is better than none, but consider authenticator apps or hardware tokens for higher-risk accounts.

    Keep software and devices updated

    Apply operating system and application updates promptly. Configure Windows Update and macOS updates to install automatically, and patch network devices and printers.

    2. Protect email and communications

    Email is the most common attack vector for SMBs. Focus on prevention and detection.

    Train staff to recognise phishing

    Run short, regular awareness sessions and simulated phishing exercises. Teach employees to verify payment requests, check sender addresses and avoid clicking unexpected links or attachments.

    Deploy email filtering and anti-spam

    Use a reputable email gateway or cloud email security service to block malicious attachments and links. For Microsoft 365 users, enable Exchange Online Protection and Advanced Threat Protection if possible.

    3. Secure endpoints and networks

    Devices and networks are obvious targets. Implement layered controls.

    Install and manage endpoint security

    Use centrally managed antivirus/EDR (endpoint detection and response) on all desktops and laptops. Ensure it is configured to update signatures and report incidents to IT.

    Segment your network

    Separate guest Wi-Fi from corporate networks. Use VLANs to restrict access between departments and sensitive systems like accounting or servers.

    Use secure Wi-Fi and strong router settings

    Change default router credentials, use WPA3 or at minimum WPA2-PSK strong passphrases, and keep firmware current. For remote workers, consider company VPNs rather than open remote desktop exposure.

    4. Backup and recovery

    Backups are essential. Treat them as the last line of defence against ransomware and data loss.

    Implement the 3-2-1 backup rule

    • Keep at least three copies of important data
    • Store them on two different media (on-site NAS and cloud)
    • Keep one copy off-site or immutable (cloud archive or air-gapped)

    Test restores regularly

    Backups are only useful if you can restore. Schedule quarterly restore tests for critical systems and ensure recovery time objectives are realistic for your business.

    5. Limit access and manage privileges

    Restricting who can access what reduces the blast radius of an incident.

    Apply the principle of least privilege

    Users should have only the access needed to do their jobs. Regularly review permissions for file shares, cloud apps and admin accounts.

    Separate administrator accounts

    Admins should have distinct accounts for admin tasks and daily email/use. Monitor and audit privileged account activity.

    6. Prepare policies and incident plans

    Written policies and tested plans enable a faster, more organised response when things go wrong.

    Create clear IT and security policies

    Document acceptable use, remote work, device management and password rules. Make policies easy to find and enforce consistently.

    Develop an incident response plan

    Define who to contact, containment steps, backup access and communication templates. Include local partners (IT, legal, PR) and contact details for RandTech IT for rapid support if needed.

    7. Comply with POPIA and protect customer data

    POPIA sets expectations for lawful processing and safeguarding of personal information. Compliance reduces legal and reputational risk.

    Map personal data and justify processing

    Identify what personal data you hold, why you hold it and how long you retain it. Limit collection to what you need.

    Secure data in transit and at rest

    Use TLS/HTTPS for websites and email where appropriate. Encrypt backups and sensitive databases. Maintain records of processing activities.

    8. Consider managed security services

    Many SMBs benefit from outsourcing specialised security tasks to experienced providers.

    What managed services can help

    • Managed detection and response (MDR) for continuous threat monitoring
    • Patch management and software lifecycle services
    • Backup as a Service (BaaS) with tested restores
    • Security assessments and vulnerability scans

    Managed services translate into predictable costs and access to experienced engineers who resolve incidents quickly rather than learning on your time.

    9. Practical roadmap for the next 90 days

    1. Week 1–2: Enforce MFA, update critical systems and change default passwords.
    2. Week 3–4: Enable business password manager, deploy endpoint protection and configure email filtering.
    3. Month 2: Implement regular backups, segment networks and run staff phishing training.
    4. Month 3: Review access rights, finalise incident response and test restores.

    FAQ

    How much will basic cybersecurity cost for a small business?

    Costs vary by size and complexity. Many baseline protections (MFA, software updates, basic email filtering) are low cost. Managed services and advanced monitoring increase monthly spend but can be more cost-effective than dealing with an incident.

    Does POPIA require full encryption of all data?

    POPIA does not mandate specific technologies but requires appropriate security measures. Encryption is commonly recommended for protecting sensitive personal information.

    Can I handle cybersecurity in-house?

    Some basic measures can be managed internally if you have skilled staff. For continuous monitoring, rapid incident response and complex threats, partnering with a managed security provider gives access to experienced engineers.

    What should I do if I suspect a breach?

    Contain the incident (disconnect affected devices), preserve logs and ask employees to change credentials. Contact your IT provider immediately to investigate and start recovery steps.

    How often should we run security training?

    Short refresher sessions and phishing simulations every quarter are effective. Reinforce with concise tips and real-world examples relevant to your team.

    Conclusion

    Small-business cybersecurity in South Africa is achievable with practical, prioritised steps: enforce MFA, maintain updates, secure backups, train staff and consider managed services for specialist tasks. RandTech IT focuses on fast resolution by experienced engineers, helping clients reduce risk without lengthy learning curves on their time.

    If you want a tailored cybersecurity checklist, an on-site assessment in Johannesburg/Gauteng or managed protection for your business systems, contact RandTech IT for practical, experienced assistance.

  • Why Microsoft 365 Still Needs Independent Backup

    Why Microsoft 365 Still Needs Independent Backup

    Introduction

    Microsoft 365 is the backbone of many South African small and medium-sized businesses. It offers email, collaboration, file storage and productivity tools in a single subscription — a compelling value for organisations in Johannesburg and beyond. However, Microsoft’s shared responsibility model means that some critical aspects of data protection remain the customer’s responsibility.

    This article explains why Microsoft 365 still needs independent backup, the common risks businesses face, compliance and recovery considerations in a South African context, and practical steps to implement a resilient backup strategy.

    What Microsoft 365 protects — and what it doesn’t

    Microsoft protects the availability of the Microsoft 365 infrastructure and provides built-in recovery tools for certain scenarios. But that protection is not the same as a comprehensive backup designed for long-term retention, point-in-time restores and legal discovery.

    Microsoft’s strengths

    • High availability and geographically distributed infrastructure.
    • Redundancy to keep services running during outages.
    • Basic restore capabilities for deleted items within retention windows.

    Where independent backup is needed

    • Accidental deletion beyond retention periods.
    • Malicious insider actions or compromised accounts.
    • Ransomware that encrypts or deletes cloud-hosted files.
    • Legal and compliance requirements for long-term retention and eDiscovery.
    • Retention gaps when subscriptions or licences change.

    Common data loss scenarios for South African SMEs

    Understanding typical failure modes helps prioritise backup decisions.

    Human error

    Employees frequently delete emails or documents accidentally. If the deletion passes Microsoft’s retention window or version history, the content can be gone for good without an independent backup.

    Security incidents

    Compromised accounts and ransomware attacks are rising in South Africa. Attackers who gain access to Microsoft 365 can delete or alter content across Exchange, SharePoint and OneDrive. An immutable, independent backup helps recover clean copies without paying ransom.

    Compliance and litigation

    SMEs working with regulated industries or on public contracts may need to retain records for specific periods. A third-party backup provides defensible retention policies and easier eDiscovery than relying on native tools alone.

    Key benefits of independent Microsoft 365 backup

    • Point-in-time restores for mailboxes, SharePoint sites and OneDrive files.
    • Longer, custom retention schedules to meet legal requirements.
    • Protection against account compromise and ransomware.
    • Operational simplicity for restores — less downtime and faster recovery.
    • Separation of duties: backups isolated from the primary tenant reduce single points of failure.

    What to look for in a Microsoft 365 backup solution

    Not all backup offerings are equal. When evaluating options for a South African SME, prioritise these capabilities:

    Comprehensive coverage

    Ensure the solution covers Exchange Online, SharePoint Online, OneDrive for Business, Teams and group mailboxes. Verify it preserves metadata, permissions and version history where possible.

    Retention flexibility and immutability

    Choose solutions that allow custom retention periods and support immutable storage to defend against tampering or accidental deletion.

    Efficient storage and cost control

    Look for deduplication, incremental backups and pricing that aligns with your budget. For SMEs, predictable monthly costs in ZAR (Rands) make planning easier.

    Fast, granular restore options

    Ability to restore single items, full mailboxes, or entire SharePoint sites quickly is crucial to reduce business disruption.

    Local expertise and support

    Work with a partner who understands South African business conditions, compliance expectations and can offer hands-on support when you need it.

    Implementing a practical backup strategy

    Below is a practical approach tailored for South African SMEs that balances protection with cost and operational needs.

    1. Assess your data and risk

    Identify critical data stores in Microsoft 365 and classify them by business impact. Prioritise mailboxes of key personnel, financial records, contracts and project documents stored in SharePoint.

    2. Define retention and recovery objectives

    • Recovery Time Objective (RTO): how quickly you need data restored.
    • Recovery Point Objective (RPO): how much data loss is acceptable.
    • Retention periods driven by compliance and business needs.

    3. Choose the right backup product

    Select a solution that covers your selected workloads, supports immutability and fits your budget. Prefer vendors with local or regional support partners.

    4. Test backups and restores regularly

    Schedule periodic restore tests to confirm recoverability. Testing reduces surprises during real incidents and keeps your team confident in the process.

    5. Combine with strong security practices

    Backups are part of a broader security posture. Implement MFA, least privilege access, conditional access policies and effective endpoint protection to reduce attack surfaces.

    Cost considerations for South African SMEs

    Budgeting for independent backup need not be prohibitive. Many backup providers offer tiered plans suitable for SMEs, with predictable monthly pricing in ZAR. Factor in:

    • Licence and per-user costs.
    • Storage consumption driven by retention and change rates.
    • Support and managed services if you prefer offloading administration.

    Working with a trusted local MSP can simplify procurement, implementation and ongoing support — avoiding costly mistakes and time spent on in-house management.

    Frequently asked questions

    Does Microsoft not back up my data automatically?

    Microsoft maintains infrastructure availability and short-term recovery capabilities, but it does not take responsibility for long-term retention, point-in-time restores beyond native retention windows, or protection against deliberate deletion by users.

    How long does Microsoft retain deleted items?

    Retention varies by service and configuration. Native recovery windows may be short or dependent on specific retention policies — which can leave gaps for organisations needing longer-term archives.

    Will having a backup protect me from ransomware?

    An independent, immutable backup is a key defence against ransomware because it enables recovery to a clean state without paying a ransom. Backups must be properly secured and tested to be effective.

    Can I manage backups myself or should I use a managed service?

    SMEs can use self-managed solutions, but many benefit from a managed service that brings experienced engineers, local support and faster resolution — freeing internal teams to focus on core business activities.

    Is independent backup required for compliance?

    Depending on your industry and contractual obligations, independent backup may be necessary to meet retention and eDiscovery requirements. Consult your legal or compliance adviser to confirm obligations.

    Conclusion

    Microsoft 365 provides robust infrastructure and useful native recovery features, but it is not a substitute for independent backup. South African SMEs face specific risks — accidental deletion, ransomware and compliance demands — that call for a deliberate backup strategy.

    Implementing independent backups with clear retention policies, immutable storage and regular restore testing will reduce downtime, protect your data and help meet regulatory obligations. Partnering with a local MSP can simplify the process and provide experienced support when it matters most.

    Contact RandTech IT — if you’d like practical, experienced help protecting your Microsoft 365 data, our engineers prioritise fast resolution and understand the needs of South African SMEs. Reach out to RandTech IT for a straightforward assessment and tailored backup solution.