Security & Compliance

Security Assessments & POPIA Compliance for South African Businesses

AMEA Technologies is a South African cybersecurity and POPIA compliance provider, based in Johannesburg with partner teams covering Cape Town and Durban, offering risk assessments, monitoring, incident readiness and awareness training to South African organisations of all sizes.

IT Security Awareness Training
What We Offer

Which security and compliance services does AMEA offer?

AMEA offers security risk assessments, incident readiness, POPIA compliance, ISO 27001 alignment, CIS Controls mapping and continuous monitoring for South African organisations of every size.

Layered security: identity, network, devices and email around your dataYourdataIdentity and MFANetwork and firewallDevices and patchingEmail and staff training

How secure is your organisation?

The security posture check is 12 critical questions that produce an instant risk rating.

1Do you require Multi-Factor Authentication (MFA) for ALL remote access?
2Do you have offline or immutable backups that can survive ransomware?
3Is your email system configured to filter phishing and spoofing (SPF/DKIM/DMARC)?
4Do you have a written and tested Incident Response Plan?
5Are all staff devices (laptops/mobiles) encrypted (BitLocker/FileVault)?
6Do you restrict administrative privileges (no daily use of admin accounts)?
7Do you conduct security awareness training for employees at least annually?
8Do you patch critical software vulnerabilities within 14 days?
9Do you have visibility into what software is installed on every device?
10Is sensitive data (PII) segregated and access-controlled?
11Do you enforce a password policy (length, complexity, rotation)?
12Do you have endpoint protection (Antivirus/EDR) on all devices?

Please answer all questions to proceed

Standards We Follow

Which compliance frameworks does AMEA work with?

AMEA works with POPIA, ISO 27001, the CIS Controls and the NIST Cybersecurity Framework, mapping each to practical technical controls for your organisation.

POPIA

Protection of Personal Information Act

ISO 27001

Information Security Management

CIS Controls

Center for Internet Security

NIST

Cybersecurity Framework

POPIA, ISO 27001, CIS Controls and NIST: which one applies to you?

POPIA is the law; the other three are frameworks you choose to align to. The table shows what each is, whether it is mandatory in South Africa, and who typically needs it.

Security and compliance frameworks compared for South African organisations
FrameworkWhat it isMandatory in South Africa?Who typically needs it
POPIASouth Africa's data protection law governing personal informationYes, for every organisation that processes personal informationEvery business, nonprofit and public body
ISO 27001International standard for an information security management systemNo, voluntary certificationSuppliers to enterprises, financial services, organisations answering tenders
CIS ControlsPrioritised list of 18 practical safeguards from the Center for Internet SecurityNo, voluntary baselineSmall and mid-sized businesses that want a practical starting point (Implementation Group 1)
NIST Cybersecurity FrameworkUS framework organised around Identify, Protect, Detect, Respond and RecoverNo, voluntaryOrganisations with US customers or a mature security programme
Start with POPIA because it is the law, use CIS Controls as the technical baseline, and align to ISO 27001 when customers or tenders demand it.
FAQ

POPIA and security questions, answered

Start by auditing the personal data you hold. Then document your lawful basis for processing it, encrypt data at rest and in transit, appoint an Information Officer, and put a breach response plan in place. AMEA provides POPIA compliance assessments and documentation.

We review your defences against common attack paths: identity and MFA, patching, backups, endpoint protection, email security, access control and staff awareness. You receive a clear risk rating and a prioritised plan to close the gaps.

Don't wait for a breach

Get ahead of threats with a proactive security assessment