Client stories
Comments from organisations that asked us to assess, draft, refresh, or brief around internal security policies.
“They rewrote our acceptable-use and access policies after we moved to a new identity provider. The drafts were short enough for managers to brief teams the same week, though we still needed an extra pass on contractor clauses.”
“The gap assessment listed which policies we could keep, which to merge, and which were missing for POPIA-related access questions. It saved us from commissioning a full rewrite we did not need.”
“Our board pack finally connected each policy to an owner and a review date. Approval took one meeting instead of another quarter of circulating drafts.”
“The incident response policy workshop forced us to name decision-makers before a crisis. We still struggle with after-hours contact trees, but the written escalation path is clearer than anything we had.”
“Staff briefings used our own examples — shared drives, guest Wi-Fi, supplier USB sticks — so acknowledgement felt grounded rather than theatrical.”
Extended note: wholesale group policy suite
A Cape wholesale group approached us after an insurer questionnaire exposed conflicting access and data-handling rules across three business units. We mapped owners, merged duplicate acceptable-use clauses, and produced a board pack with a ninety-day rollout checklist. The company secretary later used the same pack for EXCO refresher training without rewriting the core documents.
Discuss a similar engagement