Tag: SME

  • Microsoft 365 Backup Retention Explained for SA SMEs

    Microsoft 365 Backup Retention Explained for SA SMEs

    Introduction

    Understanding Microsoft 365 backup retention explained is essential for South African small and medium-sized businesses. Many organisations assume Microsoft fully protects their data, but the reality is more nuanced. This article explains what Microsoft covers, common gaps, recommended retention strategies for SMEs, and practical steps you can take in Gauteng and across South Africa to reduce risk and meet compliance needs.

    What Microsoft 365 covers — and what it doesn’t

    Microsoft provides a range of built-in data protection features across Exchange Online, SharePoint, OneDrive and Teams. These include versioning, retention policies, and basic recovery options. However, Microsoft’s shared responsibility model means customers retain responsibility for long-term retention, point-in-time recovery, and protecting against accidental deletion, malware and insider threats.

    Included features

    • Version history for files in OneDrive and SharePoint.
    • Recycle Bin retention for deleted items (limited timeframes).
    • Retention labels and policies for compliance scenarios.
    • Basic restore tools for administrators.

    Common gaps to be aware of

    • Microsoft is not a true backup provider — point-in-time restores beyond the retention windows can be difficult.
    • Deleted items may be purged after the recycle bin period, making recovery impossible without backups.
    • Ransomware and mass-deletion attacks can propagate through connected services.
    • Regulatory or contractual retention requirements may exceed Microsoft’s default settings.

    Key retention concepts explained

    To make sensible retention decisions, SMEs should understand a few core concepts:

    Retention policies vs backups

    Retention policies prevent deletion or preserve data for a set period to meet compliance needs. Backups create independent copies that allow point-in-time restores even if original items are modified or removed.

    Versioning and point-in-time recovery

    Versioning keeps prior versions of files, but it is not a substitute for backup because versions can be removed or become impractical for large-scale recovery.

    Retention periods

    Retention periods should reflect legal, tax and operational requirements. In South Africa, businesses may need to retain financial records or employment documents for several years — often longer than Microsoft’s default windows.

    Practical retention strategies for South African SMEs

    Apply a layered approach combining Microsoft capabilities with independent backups to achieve resilience and compliance.

    1. Assess legal and operational requirements

    • Identify documents and mailboxes that require long-term retention (e.g., tax records, contracts).
    • Confirm retention durations dictated by SARS, labour regulations or industry rules.

    2. Configure Microsoft 365 retention and labels

    • Use retention labels to classify content and apply minimum retention and deletion rules.
    • Apply policies to SharePoint sites, OneDrive accounts and Exchange mailboxes where appropriate.

    3. Implement third-party backups

    Choose a backup solution that offers:

    • Automated, scheduled backups of Exchange, SharePoint, OneDrive and Teams.
    • Point-in-time restore capability and long-term archival storage.
    • Encryption in transit and at rest, with reliable role-based access for restores.

    4. Define retention tiers and storage locations

    • Short-term tier: quick restores for operational continuity (days to months).
    • Long-term tier: archival storage for compliance (years). Consider on-prem or local region cloud storage for data sovereignty concerns.

    5. Test restore procedures regularly

    Backups are only useful if restores work. Schedule regular restore tests to validate procedures, timing and data integrity.

    Cost considerations for SMEs in South Africa

    Budget realistically. Backup costs vary by provider, retention period and storage class. For many SMEs the goal is to balance affordability with risk tolerance. Factor in:

    • Monthly subscription fees for backup software or services.
    • Storage costs for long-term archives.
    • Internal time to manage and test backups.

    Discuss options with your IT partner to compare local versus international storage, and any implications for data access speeds and compliance.

    Checklist: Implementing a robust Microsoft 365 retention plan

    1. Audit current Microsoft 365 settings and data types.
    2. Map legal and business retention requirements.
    3. Apply retention labels and policies where possible.
    4. Deploy an independent backup solution for point-in-time recovery.
    5. Define retention tiers and archival locations.
    6. Test restores quarterly and after major changes.
    7. Document procedures and assign responsibilities.

    FAQs

    Do I need a separate backup if I use Microsoft 365?

    Yes. Microsoft protects platform availability and provides some data retention tools, but it does not replace dedicated backups for long-term retention or comprehensive point-in-time recovery.

    How long does Microsoft keep deleted Exchange items?

    Retention for deleted items depends on mailbox settings and retention policies. Default recycle bins are time-limited and may not meet all compliance needs, so verify and extend retention where required.

    Can I meet SARS or labour retention rules with Microsoft retention policies?

    Possibly, but you should confirm that applied retention periods and auditability match statutory requirements. Independent backups provide stronger assurance for long-term legal holds.

    Is local (South African) storage necessary?

    Local storage can help address data sovereignty concerns and may reduce latency. Whether it’s necessary depends on your industry, contractual obligations and risk appetite.

    How often should I test restores?

    Test restores at least quarterly, and after any significant change to your environment or backup configuration.

    Conclusion

    Microsoft 365 backup retention explained shows that while Microsoft provides useful tools, SMEs must take active responsibility for long-term retention and recoverability. By combining retention policies with independent backups, clearly defined retention tiers, and regular restore testing, South African businesses can minimise risk and meet compliance requirements without disrupting operations.

    If you’d like practical help implementing or reviewing your Microsoft 365 retention and backup strategy, contact RandTech IT. Our experienced engineers provide fast, effective support so you get reliable protection without learning on your time.

  • Best Backup Strategy for a South African Small Business

    Best Backup Strategy for a South African Small Business

    Introduction

    Data loss can halt a small business in South Africa faster than most owners expect. Whether caused by ransomware, hardware failure, accidental deletion or a physical incident in your office in Johannesburg or elsewhere in Gauteng, the right backup strategy reduces downtime and financial risk. This guide explains practical, cost-effective steps for South African small and medium-sized businesses to develop a resilient backup and recovery plan.

    Why a tailored backup strategy matters for South African SMEs

    Small businesses have limited resources and less room for disruption. A generic backup approach often fails to meet local realities — inconsistent internet, intermittent power outages, and regulatory or client data requirements. A tailored strategy balances cost, speed of recovery and data protection while reflecting local operational constraints.

    Common local risks to consider

    • Ransomware and cybercrime targeting SMBs
    • Load shedding and unstable power affecting on-premises servers
    • Hardware failure without quick replacement options
    • Limited IT staff leading to delayed recovery

    Principles of an effective backup strategy

    Apply clear principles when building your plan. These guide tool selection and operational routines.

    1. The 3-2-1 rule

    Keep at least three copies of your data: the primary plus two backups. Store copies on two different media, and keep at least one copy offsite. For many South African SMEs, this means local on-site backup plus cloud backups hosted in a reputable region.

    2. Regular, automated backups

    Automation reduces human error. Schedule backups based on the criticality of data: daily or continuous for transactional systems, and less frequent for archival data.

    3. Secure and encrypted backups

    Encrypt data both in transit and at rest. Use strong key management and ensure cloud providers comply with security standards. This minimises exposure in case backups are accessed or intercepted.

    4. Test recovery regularly

    A backup that cannot be restored is useless. Regularly test restores to verify integrity and to ensure your team can execute recovery procedures quickly.

    Designing your backup layers

    An effective strategy uses multiple complementary layers to meet recovery time objectives (RTO) and recovery point objectives (RPO).

    Layer 1: Local backups for fast recovery

    Keep a local copy for quick restores. Options include external NAS devices or on-premises servers with RAID and regular snapshots. Local restores are fastest after simple incidents like accidental deletion.

    Layer 2: Offsite cloud backups for disaster resilience

    Store encrypted backups in the cloud to protect against fire, theft or major hardware failure. Choose providers with data centres in compliant locations and strong SLAs. For limited internet bandwidth, consider hybrid approaches that seed initial backups physically and then replicate incremental changes.

    Layer 3: Immutable or air-gapped backups for ransomware protection

    Immutable backups cannot be altered or deleted for a defined period. Air-gapped solutions (physically disconnected copies) add another barrier against ransomware that seeks and destroys backups.

    Practical implementation steps

    1. Identify critical data and systems: Prioritise POS systems, accounting records, customer databases and core documents.
    2. Set RTOs and RPOs: Determine acceptable downtime and data loss for each system.
    3. Choose tools and vendors: Mix local NAS, cloud backup and immutable storage. Consider managed backup services if you lack internal expertise.
    4. Automate schedules and retention: Configure daily, weekly and monthly retention aligned with compliance or tax requirements.
    5. Encrypt and test: Ensure encryption, then run periodic restore drills and document procedures.

    Cost considerations for South African SMEs

    Budget choices often determine the balance between speed and expense. Cloud storage costs are typically charged monthly or by usage. Factor in:

    • Monthly cloud storage and egress fees
    • One-time hardware for local NAS or external drives
    • Managed service fees if outsourcing backups
    • Staff time for testing and maintenance

    Work with an IT partner to model costs in rand and choose the most cost-effective mix for your recovery objectives.

    Compliance and data sovereignty

    Ensure backups comply with relevant legislation and client contracts. While South Africa does not mandate local hosting for all data, some industries and clients do require data to remain within the country. When necessary, select cloud providers with South African datacentre options or ensure contractual controls around data handling.

    Choosing between in-house and managed backup services

    Small businesses often lack the time and specialised skills to maintain robust backup processes. Managed services provide experienced engineers, proactive monitoring and faster resolution — aligning with RandTech IT’s approach of resolving issues quickly rather than learning on the client’s time.

    Signs you should use a managed service

    • No dedicated IT staff or limited backup expertise
    • High reliance on critical business systems
    • Need for rapid recovery SLAs
    • Concern about ransomware and secure key management

    Checklist: Building your backup plan

    • Inventory critical systems and data
    • Define RTOs and RPOs per system
    • Implement 3-2-1 backup architecture
    • Enable encryption and access controls
    • Schedule automated backups and retention
    • Test restores quarterly or after major changes
    • Document procedures and escalation paths

    FAQ

    How often should a small business run backups?

    It depends on the system. Critical transactional systems should be backed up continuously or daily; less critical files can follow daily or weekly schedules. Define RPOs to decide frequency.

    Can I rely solely on cloud backups?

    Cloud backups are resilient but relying only on them can increase recovery time and costs if your internet is slow. A hybrid approach with a local copy for quick restores is usually better.

    What is an acceptable retention period?

    Retention depends on compliance and business needs. Common patterns include daily backups kept for 30 days, weekly for three months, and monthly for one year, with longer archiving as required for legal or tax reasons.

    How do I protect backups from ransomware?

    Use immutable or air-gapped backups, enforce strong access controls, keep backups offline when possible, and ensure backup credentials are separate from production accounts.

    How much will a proper backup strategy cost?

    Costs vary by data volume, chosen tools and whether you use managed services. Work with an IT partner to estimate monthly cloud and managed-service fees plus any one-off hardware expenses in rand.

    Conclusion

    A practical backup strategy protects your business against common risks in South Africa while balancing budget and recovery needs. Use the 3-2-1 principle, combine local and cloud layers, test restores regularly and consider a managed service if you lack in-house expertise. That approach reduces downtime and helps you recover quickly with minimal disruption.

    If you’d like practical, experienced assistance to design and implement the best backup strategy for your South African small business, contact RandTech IT. Our engineers prioritise fast, expert resolution so your business stays operational and secure.

  • How to Prevent Ransomware Attacks: Practical Steps for SMEs

    How to Prevent Ransomware Attacks: Practical Steps for SMEs

    Introduction

    Ransomware is a leading cyber threat for South African small and medium-sized businesses (SMEs). An attack can halt operations, expose sensitive data and lead to significant recovery costs. As a business owner or IT decision-maker, knowing how to prevent ransomware attacks is essential. This article offers clear, practical steps tailored to South African SMEs, with a focus on achievable controls, sensible investments and how managed IT support can reduce risk.

    Understand the threat and your risk

    Before implementing controls, assess where your business is most vulnerable. Ransomware typically gains access through phishing emails, unpatched systems, weak remote access configurations and poor backup practices.

    Conduct a basic risk assessment

    • List critical data and systems (financials, payroll, customer data).
    • Identify access points (email, remote desktop, cloud apps).
    • Evaluate business impact if each system became unavailable.

    Understanding impact helps prioritise protections and budget.

    Implement strong endpoint protection

    Endpoints—laptops, desktops and servers—are common ransomware entry points. Effective endpoint protection reduces the chance of successful infection.

    Use reputable antivirus and endpoint detection

    • Choose solutions with real-time protection and behavioural detection.
    • Ensure centralised management so policies and updates are consistent.

    Control administrative privileges

    Limit local admin rights. Users should run day-to-day tasks with standard accounts; elevate privileges only when necessary. Reduced privileges limit malware impact.

    Keep systems and software patched

    Unpatched software is a frequent attack vector. Regular patching prevents attackers exploiting known vulnerabilities.

    Establish a patch management routine

    • Prioritise critical systems and internet-facing services.
    • Schedule regular patch windows and use automated deployment where possible.
    • Test patches on non-critical devices before broad rollout.

    Secure remote access and network architecture

    As more staff use cloud services and remote access from Johannesburg, the Western Cape or elsewhere, securing connections and segmenting networks matters.

    Use VPNs and multi-factor authentication (MFA)

    • Require MFA for remote access, email and admin portals.
    • Use a reputable VPN or secure remote access solution for staff working offsite.

    Network segmentation and least privilege

    Segment your network so a breach in one area does not grant broad access. Keep guest Wi-Fi separate from business systems and isolate critical servers.

    Practice robust backup and recovery

    Backups are the most reliable defence against paying a ransom. A tested recovery plan gets you back to business quickly.

    Follow the 3-2-1 backup rule

    • Keep at least three copies of data.
    • Store backups on two different media types.
    • Keep one copy offsite and offline where possible.

    Test restores regularly

    Backups are only useful if you can restore them. Schedule periodic restore tests and document recovery steps, including estimated recovery time objectives (RTOs).

    Train staff and build a security culture

    Human error remains the top cause of incidents. Practical, role-focused training reduces risk and helps staff recognise attacks early.

    Provide targeted phishing awareness

    • Run short, regular training sessions rather than long annual workshops.
    • Simulate phishing attacks to measure and improve awareness.

    Define clear incident reporting processes

    Make it easy for employees to report suspicious emails or behaviour. Early reporting can stop an attack from spreading.

    Develop policies and incident response plans

    Preparation reduces confusion during an incident. Documented policies and tested response plans shorten downtime and preserve evidence for investigation.

    Key elements of an incident response plan

    • Roles and contact list, including external support (IT partner, legal, forensic).
    • Containment steps to isolate infected devices.
    • Communication templates for staff and customers.
    • Post-incident review and remediation actions.

    Consider cyber insurance and legal obligations

    Cyber insurance can help with recovery costs, but policies vary. Ensure your insurer recognises your security controls and understand requirements under POPIA for personal data breaches.

    Leverage managed IT and security services

    Many SMEs lack the capacity to maintain 24/7 security. A managed service provider (MSP) can deliver experienced, rapid response and continuous monitoring without hiring full-time specialists.

    What a good MSP should provide

    • Proactive patching, endpoint management and security monitoring.
    • Regular backups with tested restores and documented RTOs.
    • Clear escalation procedures and fast incident response by experienced engineers.
    • Guidance on POPIA compliance and local regulatory expectations.

    Practical checklist for immediate action

    1. Enable MFA across email and remote access.
    2. Ensure daily backups with an offline copy and test restores.
    3. Update and patch operating systems and critical apps.
    4. Install centrally managed endpoint protection.
    5. Run quick staff awareness sessions and set an easy reporting channel.

    Conclusion

    Preventing ransomware attacks requires a mix of technology, processes and people-focused measures. For South African SMEs, sensible prioritisation—backups, patching, MFA, staff training and working with an experienced managed IT partner—delivers the best protection for limited budgets. Practical actions today reduce the chance of costly disruption tomorrow.

    FAQ

    1. Can I rely on backups alone to recover from ransomware?

    Backups are essential but must be correctly implemented and tested. Offsite and offline copies plus documented restore procedures are critical. Without tested restores, backups may not help.

    2. Should my business pay the ransom if hit?

    Paying is risky and often discouraged. Payment does not guarantee full recovery or data deletion. In many cases, recovery from verified backups and forensic help is a safer route.

    3. How much should an SME budget for ransomware protection?

    Budgets vary by size and risk profile. Focus on high-impact controls first: backups, MFA, patching and endpoint protection. Working with an MSP can convert fixed costs into predictable monthly fees.

    4. Is cyber insurance worth it for small businesses?

    Cyber insurance can help with costs related to recovery and legal exposure, but policies differ. Ensure your security posture meets insurer requirements and maintain documentation of controls.

    5. How often should we test our incident response plan?

    At minimum, test annually. More frequent tabletop exercises—every six months—are recommended for higher-risk operations or rapidly changing environments.

    6. How quickly can an MSP respond to a ransomware incident?

    Response times depend on the MSP contract. Choose a provider that guarantees fast escalation to experienced engineers and has local knowledge of South African business constraints.

    Contact RandTech IT for experienced, practical assistance. If you want to harden your systems, test your backups or set up an incident response plan, RandTech IT’s engineers can help quickly and professionally. Contact us to discuss a pragmatic security plan tailored to your SME’s needs.

  • Business email compromise warning signs for SMEs

    Business email compromise warning signs for SMEs

    Introduction

    Business email compromise (BEC) is a growing threat to South African small and medium-sized businesses. Unlike noisy ransomware or mass phishing campaigns, BEC is often targeted, quiet and financially damaging. For SMEs in Johannesburg, Pretoria and across Gauteng, recognising early warning signs is essential to prevent costly mistakes and downtime. This guide explains common indicators of BEC, practical prevention measures suitable for local businesses, and steps to take if you suspect compromise.

    What is business email compromise?

    Business email compromise is a type of cybercrime where attackers gain access to legitimate business email accounts or convincingly spoof them to defraud a company. Their typical goals include wire transfer fraud, invoice diversion, payroll manipulation or harvesting credentials for further access. Because BEC attacks frequently impersonate trusted colleagues, suppliers or executives, they can bypass basic defences.

    Common warning signs of BEC

    Timely detection often depends on staff vigilance. Teach your team to look for subtle anomalies rather than obvious malware alerts.

    Unusual payment requests or urgent financial demands

    • Requests to change banking details for recurring suppliers.
    • Emails demanding immediate payment or asking to bypass normal approval processes.
    • Last-minute “urgent” invoices with pressure to transfer funds.

    Sender anomalies and spoofing indicators

    • From addresses that look similar but contain slight misspellings (for example, finance@acme-co[.]za vs finance@acmeco[.]za).
    • Display names that match senior staff while the actual email domain differs.
    • Unexpected forwarding rules or auto-replies set by the sender.

    Requests for sensitive information

    Emails asking for employee tax numbers, ID details, banking credentials or password resets are red flags. BEC actors often harvest personal data to bypass two-factor authentication or social-engineer further access.

    Strange language, tone or writing style

    • Messages that deviate from the sender’s usual tone or contain awkward phrasing.
    • Generic greetings instead of personalised salutations.
    • Uncharacteristic urgency, threats, or over-politeness intended to manipulate.

    Irregular email behaviour and technical signs

    • Large volumes of outbound email from a user who normally sends few messages.
    • Unexpected login notifications, especially from foreign IP addresses or unusual locations.
    • New mail rules created to delete or divert responses.

    Why South African SMEs are attractive targets

    SMEs often have limited IT resources and mature processes, making them appealing to attackers. Additionally, local business practices—such as relying on email for payment instructions and informal approval chains—can be exploited. For companies operating in Gauteng, where many suppliers and clients are interconnected, fraud can spread quickly through networks of trust.

    Practical prevention steps for SMEs

    Protection doesn’t need to be complicated or expensive. Focus on layered controls, staff training and clear financial procedures.

    Technical controls

    • Enable multi-factor authentication (MFA) for all accounts, including administrators.
    • Use modern email filtering and anti-spoofing technologies: SPF, DKIM and DMARC.
    • Monitor login activity and implement conditional access where possible.
    • Keep systems patched and maintain device endpoint protection.

    Policy and process

    • Require dual authorisation for payments above defined thresholds—set thresholds in rand appropriate to your business size.
    • Verify bank account changes through a secondary channel such as a phone call to a known number.
    • Limit public exposure of staff email addresses and organisational charts on the website.

    Staff training and culture

    Regular, practical training helps staff recognise suspicious messages. Simulated tests are useful, but pair them with coaching and clear reporting paths so employees feel safe raising concerns without blame.

    How to respond if you suspect a compromise

    Act quickly to contain damage and gather evidence. A calm, methodical response improves chances of recovery.

    Immediate containment steps

    • Isolate affected accounts: force password resets and revoke active sessions.
    • Disable any suspicious mail forwarding rules and review send-as permissions.
    • Notify your bank immediately if payments were redirected and request a recall if possible.

    Investigate and document

    • Collect headers and logs to determine origin and timeline of the incident.
    • Identify any data exfiltration, credential theft or additional compromised accounts.
    • Preserve evidence for potential police or banking investigations.

    Report and recover

    • Report fraudulent transactions to your bank and file a case with the South African Police Service if funds were lost.
    • Notify affected clients or suppliers where appropriate, with factual guidance on next steps.
    • Review and update controls to prevent recurrence, including changes to policies and technical settings.

    Case scenario: invoice diversion in a small Gauteng supplier

    A Pretoria-based supplier received what appeared to be an email from a long-term customer requesting payment to a new account. The accounts clerk did not verify via phone and the supplier paid R120,000. The transaction was later flagged as fraudulent. Recovery depended on rapid bank engagement and a police case. The business then implemented mandatory two-person authorisation for all payments above R10,000 and enabled MFA for finance accounts.

    Key takeaways

    • BEC relies on trust and subtlety—train staff to question unusual requests.
    • Technical controls like MFA and SPF/DKIM/DMARC reduce risk significantly.
    • Clear financial procedures, verification steps and rapid incident response limit damage.

    FAQ

    1. Q: What immediate sign should trigger an investigation?

      A: Any unexpected request to change banking details or an urgent payment request that bypasses normal approvals should be investigated immediately.

    2. Q: Can email filtering stop all BEC attacks?

      A: No. Filtering helps but BEC often uses legitimate accounts or carefully crafted spoofing. Combine filtering with MFA, verification processes and staff training.

    3. Q: How quickly should we act if we detect suspicious activity?

      A: Immediately. Reset passwords, revoke sessions, notify your bank and preserve logs. Early action improves chances of stopping transfers and recovering funds.

    4. Q: Is MFA enough to prevent BEC?

      A: MFA significantly reduces risk but is not foolproof. Attacks that use social engineering or SIM swapping underline the need for layered controls.

    5. Q: Who should handle BEC incidents in an SME?

      A: Ideally a small incident response team: a senior manager, the IT lead and a finance representative. External technical support can help preserve evidence and restore security.

    Conclusion

    Business email compromise is a realistic threat for South African SMEs, but it is manageable. By recognising warning signs, reinforcing technical defences and enforcing sound financial procedures, businesses can reduce risk and respond effectively when incidents occur. RandTech IT focuses on fast, experienced response and practical controls so your team can get back to business with minimal disruption.

    If you suspect a compromise or want to strengthen your email defences, contact RandTech IT for practical, experienced assistance tailored to South African SMEs.

  • Small-business cybersecurity checklist for South Africa

    Small-business cybersecurity checklist for South Africa

    Introduction

    Small and medium-sized businesses (SMBs) in South Africa face growing cyber threats: phishing, ransomware, stolen credentials and non-compliance with POPIA. Many attacks exploit basic gaps rather than sophisticated zero-day flaws. This checklist gives practical, prioritised steps that South African SMBs can apply immediately to reduce risk, protect customer data and keep operations running. RandTech IT brings experience resolving urgent incidents quickly — use this as a working guide and contact us if you need hands-on help.

    1. Establish basic cyber hygiene

    Cyber hygiene is the foundation. These measures are low cost and high impact.

    Use strong, unique passwords and a password manager

    Ensure all employees use strong passwords and unique credentials for work accounts. A business-grade password manager makes this manageable and enables secure sharing of logins.

    Enable multi-factor authentication (MFA)

    MFA should be enabled on email, cloud services, VPNs and remote admin tools. Even SMS-based MFA is better than none, but consider authenticator apps or hardware tokens for higher-risk accounts.

    Keep software and devices updated

    Apply operating system and application updates promptly. Configure Windows Update and macOS updates to install automatically, and patch network devices and printers.

    2. Protect email and communications

    Email is the most common attack vector for SMBs. Focus on prevention and detection.

    Train staff to recognise phishing

    Run short, regular awareness sessions and simulated phishing exercises. Teach employees to verify payment requests, check sender addresses and avoid clicking unexpected links or attachments.

    Deploy email filtering and anti-spam

    Use a reputable email gateway or cloud email security service to block malicious attachments and links. For Microsoft 365 users, enable Exchange Online Protection and Advanced Threat Protection if possible.

    3. Secure endpoints and networks

    Devices and networks are obvious targets. Implement layered controls.

    Install and manage endpoint security

    Use centrally managed antivirus/EDR (endpoint detection and response) on all desktops and laptops. Ensure it is configured to update signatures and report incidents to IT.

    Segment your network

    Separate guest Wi-Fi from corporate networks. Use VLANs to restrict access between departments and sensitive systems like accounting or servers.

    Use secure Wi-Fi and strong router settings

    Change default router credentials, use WPA3 or at minimum WPA2-PSK strong passphrases, and keep firmware current. For remote workers, consider company VPNs rather than open remote desktop exposure.

    4. Backup and recovery

    Backups are essential. Treat them as the last line of defence against ransomware and data loss.

    Implement the 3-2-1 backup rule

    • Keep at least three copies of important data
    • Store them on two different media (on-site NAS and cloud)
    • Keep one copy off-site or immutable (cloud archive or air-gapped)

    Test restores regularly

    Backups are only useful if you can restore. Schedule quarterly restore tests for critical systems and ensure recovery time objectives are realistic for your business.

    5. Limit access and manage privileges

    Restricting who can access what reduces the blast radius of an incident.

    Apply the principle of least privilege

    Users should have only the access needed to do their jobs. Regularly review permissions for file shares, cloud apps and admin accounts.

    Separate administrator accounts

    Admins should have distinct accounts for admin tasks and daily email/use. Monitor and audit privileged account activity.

    6. Prepare policies and incident plans

    Written policies and tested plans enable a faster, more organised response when things go wrong.

    Create clear IT and security policies

    Document acceptable use, remote work, device management and password rules. Make policies easy to find and enforce consistently.

    Develop an incident response plan

    Define who to contact, containment steps, backup access and communication templates. Include local partners (IT, legal, PR) and contact details for RandTech IT for rapid support if needed.

    7. Comply with POPIA and protect customer data

    POPIA sets expectations for lawful processing and safeguarding of personal information. Compliance reduces legal and reputational risk.

    Map personal data and justify processing

    Identify what personal data you hold, why you hold it and how long you retain it. Limit collection to what you need.

    Secure data in transit and at rest

    Use TLS/HTTPS for websites and email where appropriate. Encrypt backups and sensitive databases. Maintain records of processing activities.

    8. Consider managed security services

    Many SMBs benefit from outsourcing specialised security tasks to experienced providers.

    What managed services can help

    • Managed detection and response (MDR) for continuous threat monitoring
    • Patch management and software lifecycle services
    • Backup as a Service (BaaS) with tested restores
    • Security assessments and vulnerability scans

    Managed services translate into predictable costs and access to experienced engineers who resolve incidents quickly rather than learning on your time.

    9. Practical roadmap for the next 90 days

    1. Week 1–2: Enforce MFA, update critical systems and change default passwords.
    2. Week 3–4: Enable business password manager, deploy endpoint protection and configure email filtering.
    3. Month 2: Implement regular backups, segment networks and run staff phishing training.
    4. Month 3: Review access rights, finalise incident response and test restores.

    FAQ

    How much will basic cybersecurity cost for a small business?

    Costs vary by size and complexity. Many baseline protections (MFA, software updates, basic email filtering) are low cost. Managed services and advanced monitoring increase monthly spend but can be more cost-effective than dealing with an incident.

    Does POPIA require full encryption of all data?

    POPIA does not mandate specific technologies but requires appropriate security measures. Encryption is commonly recommended for protecting sensitive personal information.

    Can I handle cybersecurity in-house?

    Some basic measures can be managed internally if you have skilled staff. For continuous monitoring, rapid incident response and complex threats, partnering with a managed security provider gives access to experienced engineers.

    What should I do if I suspect a breach?

    Contain the incident (disconnect affected devices), preserve logs and ask employees to change credentials. Contact your IT provider immediately to investigate and start recovery steps.

    How often should we run security training?

    Short refresher sessions and phishing simulations every quarter are effective. Reinforce with concise tips and real-world examples relevant to your team.

    Conclusion

    Small-business cybersecurity in South Africa is achievable with practical, prioritised steps: enforce MFA, maintain updates, secure backups, train staff and consider managed services for specialist tasks. RandTech IT focuses on fast resolution by experienced engineers, helping clients reduce risk without lengthy learning curves on their time.

    If you want a tailored cybersecurity checklist, an on-site assessment in Johannesburg/Gauteng or managed protection for your business systems, contact RandTech IT for practical, experienced assistance.

  • Why Microsoft 365 Still Needs Independent Backup

    Why Microsoft 365 Still Needs Independent Backup

    Introduction

    Microsoft 365 is the backbone of many South African small and medium-sized businesses. It offers email, collaboration, file storage and productivity tools in a single subscription — a compelling value for organisations in Johannesburg and beyond. However, Microsoft’s shared responsibility model means that some critical aspects of data protection remain the customer’s responsibility.

    This article explains why Microsoft 365 still needs independent backup, the common risks businesses face, compliance and recovery considerations in a South African context, and practical steps to implement a resilient backup strategy.

    What Microsoft 365 protects — and what it doesn’t

    Microsoft protects the availability of the Microsoft 365 infrastructure and provides built-in recovery tools for certain scenarios. But that protection is not the same as a comprehensive backup designed for long-term retention, point-in-time restores and legal discovery.

    Microsoft’s strengths

    • High availability and geographically distributed infrastructure.
    • Redundancy to keep services running during outages.
    • Basic restore capabilities for deleted items within retention windows.

    Where independent backup is needed

    • Accidental deletion beyond retention periods.
    • Malicious insider actions or compromised accounts.
    • Ransomware that encrypts or deletes cloud-hosted files.
    • Legal and compliance requirements for long-term retention and eDiscovery.
    • Retention gaps when subscriptions or licences change.

    Common data loss scenarios for South African SMEs

    Understanding typical failure modes helps prioritise backup decisions.

    Human error

    Employees frequently delete emails or documents accidentally. If the deletion passes Microsoft’s retention window or version history, the content can be gone for good without an independent backup.

    Security incidents

    Compromised accounts and ransomware attacks are rising in South Africa. Attackers who gain access to Microsoft 365 can delete or alter content across Exchange, SharePoint and OneDrive. An immutable, independent backup helps recover clean copies without paying ransom.

    Compliance and litigation

    SMEs working with regulated industries or on public contracts may need to retain records for specific periods. A third-party backup provides defensible retention policies and easier eDiscovery than relying on native tools alone.

    Key benefits of independent Microsoft 365 backup

    • Point-in-time restores for mailboxes, SharePoint sites and OneDrive files.
    • Longer, custom retention schedules to meet legal requirements.
    • Protection against account compromise and ransomware.
    • Operational simplicity for restores — less downtime and faster recovery.
    • Separation of duties: backups isolated from the primary tenant reduce single points of failure.

    What to look for in a Microsoft 365 backup solution

    Not all backup offerings are equal. When evaluating options for a South African SME, prioritise these capabilities:

    Comprehensive coverage

    Ensure the solution covers Exchange Online, SharePoint Online, OneDrive for Business, Teams and group mailboxes. Verify it preserves metadata, permissions and version history where possible.

    Retention flexibility and immutability

    Choose solutions that allow custom retention periods and support immutable storage to defend against tampering or accidental deletion.

    Efficient storage and cost control

    Look for deduplication, incremental backups and pricing that aligns with your budget. For SMEs, predictable monthly costs in ZAR (Rands) make planning easier.

    Fast, granular restore options

    Ability to restore single items, full mailboxes, or entire SharePoint sites quickly is crucial to reduce business disruption.

    Local expertise and support

    Work with a partner who understands South African business conditions, compliance expectations and can offer hands-on support when you need it.

    Implementing a practical backup strategy

    Below is a practical approach tailored for South African SMEs that balances protection with cost and operational needs.

    1. Assess your data and risk

    Identify critical data stores in Microsoft 365 and classify them by business impact. Prioritise mailboxes of key personnel, financial records, contracts and project documents stored in SharePoint.

    2. Define retention and recovery objectives

    • Recovery Time Objective (RTO): how quickly you need data restored.
    • Recovery Point Objective (RPO): how much data loss is acceptable.
    • Retention periods driven by compliance and business needs.

    3. Choose the right backup product

    Select a solution that covers your selected workloads, supports immutability and fits your budget. Prefer vendors with local or regional support partners.

    4. Test backups and restores regularly

    Schedule periodic restore tests to confirm recoverability. Testing reduces surprises during real incidents and keeps your team confident in the process.

    5. Combine with strong security practices

    Backups are part of a broader security posture. Implement MFA, least privilege access, conditional access policies and effective endpoint protection to reduce attack surfaces.

    Cost considerations for South African SMEs

    Budgeting for independent backup need not be prohibitive. Many backup providers offer tiered plans suitable for SMEs, with predictable monthly pricing in ZAR. Factor in:

    • Licence and per-user costs.
    • Storage consumption driven by retention and change rates.
    • Support and managed services if you prefer offloading administration.

    Working with a trusted local MSP can simplify procurement, implementation and ongoing support — avoiding costly mistakes and time spent on in-house management.

    Frequently asked questions

    Does Microsoft not back up my data automatically?

    Microsoft maintains infrastructure availability and short-term recovery capabilities, but it does not take responsibility for long-term retention, point-in-time restores beyond native retention windows, or protection against deliberate deletion by users.

    How long does Microsoft retain deleted items?

    Retention varies by service and configuration. Native recovery windows may be short or dependent on specific retention policies — which can leave gaps for organisations needing longer-term archives.

    Will having a backup protect me from ransomware?

    An independent, immutable backup is a key defence against ransomware because it enables recovery to a clean state without paying a ransom. Backups must be properly secured and tested to be effective.

    Can I manage backups myself or should I use a managed service?

    SMEs can use self-managed solutions, but many benefit from a managed service that brings experienced engineers, local support and faster resolution — freeing internal teams to focus on core business activities.

    Is independent backup required for compliance?

    Depending on your industry and contractual obligations, independent backup may be necessary to meet retention and eDiscovery requirements. Consult your legal or compliance adviser to confirm obligations.

    Conclusion

    Microsoft 365 provides robust infrastructure and useful native recovery features, but it is not a substitute for independent backup. South African SMEs face specific risks — accidental deletion, ransomware and compliance demands — that call for a deliberate backup strategy.

    Implementing independent backups with clear retention policies, immutable storage and regular restore testing will reduce downtime, protect your data and help meet regulatory obligations. Partnering with a local MSP can simplify the process and provide experienced support when it matters most.

    Contact RandTech IT — if you’d like practical, experienced help protecting your Microsoft 365 data, our engineers prioritise fast resolution and understand the needs of South African SMEs. Reach out to RandTech IT for a straightforward assessment and tailored backup solution.

  • How much does business IT support cost in South Africa?

    How much does business IT support cost in South Africa?

    Introduction

    Understanding how much business IT support costs in South Africa is one of the first steps for small and medium-sized businesses planning their IT budgets. Costs vary widely depending on the services you need, the provider’s expertise, service levels and whether you prefer ad hoc or managed support. This guide explains common pricing models, typical ranges in rand, the factors that influence price and how to choose the right provider for your business.

    Common pricing models for IT support

    IT providers usually offer one or more standard ways to charge. Each model suits different business needs and budgets.

    Hourly or ad-hoc support

    Pay-as-you-go support is charged by the hour and suits businesses with infrequent IT needs or one-off projects. Hourly rates reflect the engineer’s experience and the task complexity.

    Block hours

    Buying blocks of hours in advance provides a discount over pure hourly rates and ensures priority access to engineers. This is useful for businesses with predictable occasional needs.

    Monthly managed services (retainer)

    Managed services packages provide proactive maintenance, monitoring, patching and helpdesk support for a fixed monthly fee. This model reduces surprise costs and is popular with SMEs that need consistent uptime and rapid response.

    Project-based pricing

    For migrations, network installations or bespoke development, providers quote a fixed project fee based on scope. Clear scoping and milestones reduce scope creep and unexpected costs.

    Typical cost ranges in South Africa (indicative)

    Below are approximate ranges to help with budgeting. Actual costs depend on location, provider skill and contract terms.

    • Hourly/ad-hoc: R400 to R1,200 per hour for standard engineer work. Senior engineers or specialists such as security consultants can charge more.
    • Block hours: Often sold in 10–100 hour bundles with discounts of 10–25% versus ad-hoc rates.
    • Basic managed service: R1,500 to R4,000 per user/device per month for small businesses with standard monitoring and helpdesk.
    • Comprehensive managed service: R4,000 to R10,000+ per user/device per month where advanced security, full management and on-site support are included.
    • Network installation and cabling: Project-based: R10,000 to R150,000+ depending on site size and complexity.
    • Cybersecurity assessments: From R7,500 for basic reviews to R50,000+ for full penetration tests and remediation roadmaps.

    Use these ranges as a starting point. A small 10-person office with cloud-hosted services will pay very differently to a 50-person firm with on-premise servers and specialised compliance needs.

    Key factors that influence IT support cost

    Several variables determine what you’ll pay. Understanding them helps you get accurate quotes and avoid surprises.

    Scope of services

    Basic helpdesk and patching cost less than full network management, security monitoring, cloud administration and application development. Include only what you need, then scale services over time.

    Service level requirements

    Faster response times, guaranteed uptime and on-site visits raise costs. A 24/7 service desk and rapid on-site SLA will be pricier than business-hours remote support.

    Complexity and existing infrastructure

    Older or custom systems, multiple sites, complex networks and specialised software increase the time and expertise needed, raising fees.

    Security and compliance needs

    Industries with regulatory requirements (financial services, healthcare) require additional security controls, audits and documentation, which add to cost.

    Provider expertise and location

    Experienced engineers and local presence in Gauteng can command a premium, but they also resolve problems faster and reduce downtime — often saving money overall.

    How to compare quotes and avoid hidden costs

    When you receive proposals, evaluate them on more than price. Consider these practical checks:

    • Ask for clear scope and deliverables: what’s included and what’s extra.
    • Clarify response and resolution SLAs for different severities.
    • Check whether monitoring, backups and patching are part of the fee.
    • Confirm licence and third-party costs: software or cloud subscriptions are often separate.
    • Understand escalation: who does complex troubleshooting and how quickly?
    • Request client references and case examples relevant to SMEs in South Africa.

    Cost-saving strategies for SMEs

    Smart choices can lower ongoing IT spend without compromising reliability.

    • Consolidate vendors: fewer suppliers mean simpler support and often lower overall fees.
    • Use cloud services: shifting to cloud-hosted systems can reduce on-premise maintenance costs.
    • Standardise devices and software: fewer configurations speed support and reduce errors.
    • Negotiate predictable billing: fixed monthly managed services make budgeting easier than variable ad-hoc fees.
    • Invest in basic security hygiene: routine patching and backups prevent costly incidents.

    When cheaper can cost more

    Low hourly rates or deeply discounted contracts can hide risks: inexperienced engineers, slow resolution or poor documentation. For SMEs, downtime and data loss have direct business impact. Prioritise fast resolution by experienced engineers over cheaper, slower options — that’s the approach RandTech IT follows.

    Choosing the right IT support partner

    Selecting a provider is as important as price. Look for these signals of a reliable partner:

    • Clear SLAs and escalation paths
    • Experienced engineers with demonstrable SME experience
    • Proactive monitoring and maintenance capabilities
    • Transparent pricing and scope
    • Local presence or rapid on-site capability in Gauteng where relevant

    Questions to ask potential providers

    • How quickly do you resolve high-severity incidents?
    • What’s included in your managed service package?
    • How do you handle vendor licences and third-party costs?
    • Can you provide references from similar-sized businesses?

    FAQ

    How much should a small office budget per user per month?

    Budget R1,500–R4,000 per user per month for typical managed services. Exact figures depend on security needs, on-site requirements and included services.

    Are there upfront costs I should expect?

    Yes. Initial setup, migrations, documentation and remedial work to bring systems to a supported state are often charged separately as project fees.

    Can I mix ad-hoc support with a managed service?

    Yes. Many SMEs buy a managed package for core services and add block hours or ad-hoc support for projects outside the standard scope.

    How do IT support contracts handle software licences?

    Most providers either manage licences on your behalf (charged through the bill) or advise and assist you to purchase directly. Confirm the approach and cost handling up front.

    Will moving to the cloud reduce my support costs?

    Cloud services can reduce hardware maintenance costs but may introduce subscription fees and require skilled cloud management. Overall savings depend on your current infrastructure and migration plan.

    What if I’m unsure of my IT needs?

    Ask for an assessment or discovery project. A short engagement to map systems and risks helps produce accurate quotes and a sensible roadmap.

    Conclusion

    There’s no single answer to “How much does business IT support cost in South Africa?” — costs depend on services, SLAs, infrastructure complexity and provider skill. Use the ranges and questions in this guide to evaluate quotes and focus on experienced engineers who resolve issues quickly. For SMEs, predictable managed services combined with project-based work often deliver the best balance of cost and reliability.

    Need practical, experienced IT support? Contact RandTech IT to discuss a tailored proposal for your business. Our engineers prioritise fast resolution and clear pricing so you can get on with running your business.

  • Seven Signs Your IT Support Company Is Failing Your Business

    Seven Signs Your IT Support Company Is Failing Your Business

    Introduction

    For South African small and medium-sized businesses, dependable IT support is critical. Disruptions cost time and money, damage customer confidence and expose companies to security risks. Yet many organisations tolerate underperforming IT providers until a major incident forces a change.

    This article explains seven signs your IT support company is failing your business, how each issue affects operations, and what practical steps you can take to regain control. The guidance is aimed at SMEs across Gauteng and the rest of South Africa who rely on outsourced IT, managed services or mixed in‑house and external teams.

    1. Slow or inconsistent response times

    When problems occur, the first expectation is a prompt, clear response. If your provider regularly misses response targets or gives no estimate for resolution, that’s a red flag.

    Why it matters

    • Delays increase downtime and reduce employee productivity.
    • Unpredictable responses make planning impossible for sales, finance and operations.

    What to check

    • Review your service-level agreement (SLA) for response and resolution times.
    • Log and compare recent ticket times to SLA expectations.
    • Ask for a clear incident communication plan — who updates you and when.

    2. Repeatedly recurring issues

    If the same fault returns despite fixes, your provider may be treating symptoms rather than root causes. This leads to higher long-term costs and erodes trust.

    Indicators

    • Patchwork fixes without change management.
    • Problems labelled “closed” but reappearing within days or weeks.

    How to address it

    • Request root-cause analysis for recurring incidents.
    • Insist on documented remediation plans and preventive measures.
    • Prioritise providers that include proactive maintenance in their scope.

    3. Lack of proactive management

    Good IT support goes beyond break/fix. Proactive monitoring, patch management and capacity planning prevent many incidents before they affect users.

    Signs of reactive service

    • No routine vulnerability scanning or patch schedules.
    • Minimal reporting or strategic reviews.

    What you should expect

    • Regular health reports and improvement roadmaps.
    • Scheduled maintenance windows communicated in advance.
    • Security patching and backup testing as standard practice.

    4. Poor communication and transparency

    Transparent communication is essential for trust. If your provider gives vague answers, hides costs or fails to provide documentation, it undermines the relationship.

    Red flags

    • Unclear billing or surprise invoices in rand without prior discussion.
    • No documentation of system changes, licences or network diagrams.

    Remedies

    • Ask for a clear monthly report showing work completed and upcoming tasks.
    • Ensure asset and licence inventories are maintained and accessible.

    5. Low technical expertise and staff turnover

    High engineer turnover, frequent use of junior staff without senior oversight, or repeated escalation loops indicate a skills gap.

    How this affects you

    • Longer resolution times and inconsistent fixes.
    • Higher risk during complex incidents like ransomware or server failures.

    Questions to ask your provider

    • What is the team structure and who handles escalations?
    • Do they use experienced engineers for urgent incidents?
    • Can they provide client references for similar-sized businesses?

    6. Inadequate cybersecurity practices

    Cyber risk is a reality for South African businesses. If your provider neglects basic cybersecurity — multi-factor authentication, backups, patching and endpoint protection — your company is exposed.

    Key checks

    • Confirm backup frequency and test restore procedures.
    • Verify use of multi-factor authentication for remote access and critical systems.
    • Ask about patch management cadence and vulnerability assessments.

    When to escalate

    If security controls are missing or only partially implemented, treat it as urgent. A security incident can quickly multiply costs far beyond short-term savings.

    7. No strategic IT planning or business alignment

    IT should enable business goals. If your provider focuses only on firefighting and offers no strategic input — for example on cloud adoption, cost optimisation or compliance — you’re missing value.

    What strategic support looks like

    • Regular technology roadmap discussions aligned to business priorities.
    • Cost-benefit analysis for cloud, licensing and infrastructure decisions (with costs shown in rand).
    • Advice on regulatory compliance relevant to your sector.

    Practical steps to take now

    If you recognise one or more of these signs, act deliberately rather than switching impulsively. Steps to consider:

    1. Conduct an internal audit of tickets, SLAs and recent outages.
    2. Request a remediation plan and timeline from your provider.
    3. Obtain at least two competitive proposals focused on outcomes and response times.
    4. Check references from similar South African SMEs and ask for engineer CVs or bios.

    FAQ

    How quickly should an SME expect a response from an IT provider?

    Response times depend on SLA tiers. For critical incidents, expect initial response within one hour and ongoing updates until resolution. Review your SLA to confirm specific targets.

    Is it normal for issues to recur after a fix?

    No. Recurring issues usually mean the root cause wasn’t addressed. Ask for a root-cause analysis and a permanent remediation plan.

    Can I keep some IT tasks in-house and outsource others?

    Yes. Hybrid models are common. Clarify responsibilities, escalation paths and who manages security controls to avoid gaps.

    What should I look for in a new IT partner?

    Look for experienced engineers, clear SLAs, proactive reporting, tested backup and security processes, and a track record with similar SMEs in South Africa.

    How can I protect my business while changing providers?

    Ensure full documentation of systems and credentials, verify backups and restore capability, and run overlap periods where both providers coordinate handover.

    Conclusion

    IT support failures show up as slow responses, recurring outages, poor communication, skill gaps, weak security and lack of strategic alignment. For South African SMEs, these issues harm productivity and increase risk.

    Address problems with evidence-based conversations, demand transparency and consider alternative providers when necessary. Experienced engineers who prioritise fast resolution — rather than learning on your time — will save you money and protect your operations.

    Contact RandTech IT for practical, experienced assistance. Our team led by Tash Bhairo specialises in fast, reliable support, managed services, cybersecurity and cloud solutions tailored to South African SMEs. Reach out today to discuss how we can stabilise and strengthen your IT environment.

  • Questions to Ask Before Signing an IT Support Contract

    Questions to Ask Before Signing an IT Support Contract

    Introduction

    Signing an IT support contract is a major decision for South African small and medium-sized businesses. The right provider can reduce downtime, protect data and free your team to focus on core work. The wrong choice can mean slow response times, hidden costs and exposure to cyber risk. This guide lists practical, targeted questions to ask before you commit so you can select a partner that delivers experienced engineers, clear responsibilities and measurable outcomes.

    Understand the scope and responsibilities

    Start by clarifying what the contract covers and who is responsible for what. Ambiguity here creates gaps in support and unexpected charges.

    What services are included and excluded?

    Ask for a clear list of included services (helpdesk, on-site visits, backups, patching, monitoring) and explicit exclusions (hardware replacement, third-party software licences). Ensure deliverables are written into the contract rather than left to verbal assurances.

    Who will handle ongoing maintenance?

    Identify whether routine tasks—OS and application patching, antivirus updates, backup verification—are included and how often they occur. Regular maintenance prevents incidents and should not be an add-on.

    Is there a formal Service Level Agreement (SLA)?

    An SLA sets response and resolution expectations. Ask about:

    • Response times for different priority levels (urgent, high, normal)
    • Resolution time targets or escalation procedures
    • Availability windows (business hours vs 24/7 support)

    Check the team’s experience and approach

    SMEs need experienced engineers who can resolve issues quickly, not people learning on the job. Verify the provider’s team composition and escalation model.

    Who will be working on our systems?

    Ask whether you’ll have dedicated engineers, a named account manager, or a rotating support pool. For smaller businesses, a small team familiar with your environment reduces onboarding time and recurring delays.

    What are the engineers’ qualifications and experience?

    Request information on the engineers’ backgrounds—years of experience, certifications and specialisations relevant to your stack (e.g., Microsoft 365, network security, cloud platforms). Focus on practical experience rather than marketing claims.

    How does the provider avoid learning on the client’s time?

    Probe their onboarding and knowledge transfer process. Good providers maintain up-to-date documentation, use sandbox environments for testing, and keep runbooks for recurring tasks. These practices speed resolution and reduce risk.

    Costs, billing and contract terms

    Understand pricing structure and hidden costs. Contracts should be transparent about what you pay for and how price changes are handled.

    What is the pricing model?

    Common models include fixed monthly fees, per-user pricing and pay-as-you-go for ad hoc work. Ask which model suits your business profile and how scaling (adding users, offices) affects fees.

    Are there any additional or variable charges?

    Clarify charges for on-site visits, after-hours work, emergency call-outs, hardware procurement and third-party licences. Request examples or a price list so you can budget realistically.

    What are the contract length and exit terms?

    Confirm the minimum term, renewal process and notice period. Also ask about exit assistance—data handover, transfer documentation and support during migration to a new provider. These reduce disruption if you decide to change vendors.

    Security, compliance and data protection

    Security and compliance are non-negotiable. Your IT support provider should demonstrate practical controls and clear responsibilities for data protection.

    How is client data protected and backed up?

    Ask about backup frequency, retention policies, encryption at rest and in transit, and where backups are stored (on-premises, cloud region). For South African businesses, confirm if data residency is relevant to your industry or compliance needs.

    What cybersecurity measures are included?

    Confirm whether services include anti-malware management, patching, firewall administration, vulnerability scanning and incident response. Ask for examples of how they detect and contain breaches, and whether cyber insurance is recommended or supported.

    Do they support regulatory compliance?

    If you handle personal data or regulated information, ensure the provider understands relevant South African legislation and sector-specific rules. Ask how they help with audits, logging and evidence for compliance.

    Performance measurement and reporting

    Transparent reporting lets you judge the provider’s effectiveness. Agree on metrics and review cadence upfront.

    What KPIs and reports will we receive?

    Useful KPIs include ticket volumes, average response and resolution times, uptime metrics, patch compliance rates and backup test results. Ask for a sample report and the reporting frequency (monthly, quarterly).

    How are incidents communicated and reviewed?

    Understand notification processes for major incidents and scheduled post-incident reviews. Regular service reviews with actionable recommendations demonstrate continuous improvement.

    Practical and local considerations

    Local knowledge matters. Consider factors specific to South African SMEs and the Johannesburg/Gauteng business environment.

    Do they have local support capacity?

    Confirm the provider can send engineers on-site in Gauteng within agreed windows. Local presence reduces travel delays and can be critical for hardware issues.

    Can they work with our existing vendors?

    Ask whether they’ll liaise with your ISP, cloud providers or software vendors. Clear third-party coordination prevents finger-pointing when issues cross domains.

    Questions to ask before signing — quick checklist

    • What exactly is included and excluded in the service?
    • What are the SLA response and resolution times?
    • Who will be the engineers and account contacts?
    • How are backups, security and compliance handled?
    • What are the fees, extras and contract exit terms?
    • What KPIs and reporting will we receive?

    FAQ

    How long should an IT support contract be?

    Contract length varies. Many SMEs start with 12 or 24 months. Shorter terms give flexibility, longer terms can offer better pricing. Ensure exit terms and handover provisions are clear.

    Is it better to have 24/7 support or business hours only?

    Choose based on your operating hours and risk tolerance. If your staff or services run outside standard hours, 24/7 support reduces downtime. For typical office-hour businesses, business-hours support with defined emergency after-hours response may suffice.

    How do I verify a provider’s claims about experience?

    Ask for client references, case studies relevant to your industry, and examples of similar technical environments they support. Practical examples are more valuable than marketing language.

    Will my existing hardware and software be supported?

    Request an inventory review during procurement or onboarding. Ensure the contract lists supported platforms and any required upgrades to meet security or performance standards.

    What happens if we outgrow the service?

    Discuss scalability upfront. A good provider will have clear processes and pricing for adding users, offices or services and will recommend architecture changes to support growth.

    Can the provider help with one-off projects?

    Many managed service providers offer project work—migrations, network upgrades, cloud deployments—either bundled or as separate billable services. Clarify how project scope, timelines and pricing are handled.

    Conclusion

    Asking the right questions before signing an IT support contract protects your business, budget and data. Focus on scope, experienced personnel, transparent pricing, security and measurable outcomes. For South African SMEs, local responsiveness and practical experience are essential—avoid vendors who learn on your time.

    If you’d like a straightforward conversation about your needs, contact RandTech IT. Our team prioritises speedy resolution by experienced engineers who understand SME realities in Johannesburg and Gauteng. We’ll help you assess proposals and negotiate clear, practical contracts.

  • Cybersecurity Checklist for Small Businesses in South Africa

    Cybersecurity Checklist for Small Businesses in South Africa

    Introduction

    Small and medium-sized businesses (SMBs) in South Africa face increasing cyber risk. Attackers target organisations that lack dedicated security teams. This cybersecurity checklist for small businesses South Africa outlines practical, prioritised steps to reduce exposure, protect customer and employee data, and keep operations running. The guidance is tailored for South African SMEs, with realistic, cost-effective measures and referral to experienced help where needed.

    Why cybersecurity matters for South African SMEs

    SMEs are vital to the South African economy but often operate with limited IT resources. A single breach can cause reputational damage, regulatory headaches and direct financial loss. Additionally, compliance with local data protection expectations — and, where relevant, contractual obligations — means businesses must manage risk proactively.

    Quick-start checklist (high priority)

    Begin here if you have limited time or budget. These controls stop the most common attacks.

    1. Backup regularly and test restores

    • Implement automated backups for critical data and systems (on-site and off-site/cloud).
    • Schedule routine restore tests to confirm backups work.
    • Keep at least one offline or immutable copy to resist ransomware.

    2. Patch and update systems

    • Enable automatic updates for operating systems, productivity software and network devices where feasible.
    • Maintain a simple inventory of servers, workstations and network gear to track patch status.

    3. Use strong, unique passwords and multi-factor authentication (MFA)

    • Enforce strong password policies and discourage password reuse.
    • Deploy MFA for email, VPN, cloud services and administrative accounts.

    4. Secure email and web access

    • Enable spam filtering and basic anti-phishing protections at the email gateway.
    • Restrict access to risky websites using web filtering or DNS protections.

    Operational controls (next level)

    Once high-priority controls are in place, add these operational measures to improve resilience and response capability.

    1. Endpoint protection and monitoring

    • Install reputable endpoint protection on all laptops and desktops.
    • Use centralised management to ensure coverage and apply policy consistently.
    • Consider basic endpoint detection and response (EDR) where budget allows.

    2. Network segmentation and secure Wi‑Fi

    • Separate guest Wi‑Fi from corporate networks and use strong WPA2/3 encryption.
    • Segment critical systems (financial, HR) from general user devices to limit lateral movement.

    3. Secure remote access

    • Require VPN or secure access gateways for remote connections.
    • Limit remote administrative access and log sessions for audit.

    Policy and people (culture and governance)

    Technology helps, but people and processes matter most. Establish clear policies and train staff to spot threats.

    1. Acceptable use and incident response policies

    • Create concise policies covering device use, BYOD, data handling and remote work.
    • Develop a simple incident response plan that defines roles, communication and escalation steps.

    2. Staff awareness training

    • Run regular phishing simulations and short, relevant training sessions.
    • Encourage reporting of suspicious emails or behaviour and make reporting easy.

    3. Access control and least privilege

    • Grant employees only the access they need for their role; review permissions periodically.
    • Disable accounts promptly when staff leave or change roles.

    Compliance and data protection in South Africa

    South African businesses must handle personal information responsibly. While this checklist is practical rather than legal advice, consider the following:

    • Identify what personal data you process and why.
    • Apply appropriate technical and organisational measures to protect that data.
    • Keep basic records of data flows and security measures to demonstrate good governance.

    Technical controls and improvements to consider

    For businesses ready to invest further, these controls provide stronger detection and recovery capabilities.

    1. Managed detection and response (MDR)

    MDR services provide 24/7 monitoring and expert investigation. For SMEs without a full security team, it’s a cost-effective way to reduce dwell time and contain incidents quickly.

    2. Regular vulnerability scanning and penetration testing

    Schedule scans to find exposed systems and fix critical issues. Penetration testing every 12–18 months, or after major changes, helps validate defences.

    3. Secure configuration and hardening

    Harden servers, network devices and cloud services by disabling unnecessary services, applying secure baselines and reviewing default settings.

    Practical budget tips for South African SMEs

    • Prioritise backups, patching and MFA before expensive tools; these offer high return on investment.
    • Use cloud services with built-in security controls to reduce infrastructure overhead.
    • Consider managed services to get experienced engineers without hiring full-time security staff — often more cost-effective than an internal hire.

    Checklist summary (quick reference)

    1. Automated, tested backups with an offline copy.
    2. Enable automatic updates and maintain an asset inventory.
    3. Strong passwords and MFA everywhere critical.
    4. Email filtering and basic DNS/web protections.
    5. Endpoint protection and centralised management.
    6. Policy for acceptable use, incident response and staff training.
    7. Network segmentation, secure Wi‑Fi and controlled remote access.
    8. Assess next steps: MDR, vulnerability scanning and hardening.

    FAQ

    How much should a small business spend on cybersecurity?

    There’s no one-size-fits-all answer. Prioritise core controls — backups, patching, MFA and endpoint protection — then allocate remaining budget to monitoring or managed services. Focus on risk reduction rather than buying the latest tools.

    Do small South African businesses need a formal incident response plan?

    Yes. Even a simple plan that lists key contacts, steps to isolate affected systems and how to communicate with customers can reduce downtime and limit damage.

    Is cloud hosting safer than on-premises for SMEs?

    Cloud providers invest heavily in security, so moving to reputable cloud services can improve security for many SMEs. However, shared responsibility applies: you must still configure services securely and protect user credentials.

    What are the most common threats to expect?

    Phishing, ransomware, credential theft and misconfigured cloud services are common. Many incidents start with a compromised email or an unpatched system.

    When should I call an external IT/security provider?

    If you lack in-house expertise, contact a trusted provider when setting up backups, configuring network security, responding to an incident or evaluating managed detection services. Experienced engineers speed resolution and reduce business disruption.

    Conclusion

    Protecting your business doesn’t require perfection — it requires sensible, prioritized steps. Start with reliable backups, patching, MFA and employee awareness. From there, add monitoring, segmentation and managed services as your needs and budget grow. RandTech IT specialises in practical, experienced support for South African SMEs, delivering fast resolution by senior engineers rather than learning on your time.

    Need help implementing this checklist? Contact RandTech IT for practical, experienced assistance to secure your business and keep your operations running with minimal disruption.