Page 1 of 14

Preliminary Cybersecurity Risk Self-Assessment

Are you concerned about the rising cybersecurity breaches in South Africa? Don't worry, you're not alone. Many small and medium-sized enterprises (SMEs) are facing similar challenges. The increase in breaches can be attributed to a combination of weak security measures at companies and the growing sophistication of hackers. In fact, the country's 2023 State of Ransomware report highlighted the alarming number of organisations that fell victim to ransomware attacks in 2022.

To address these risks, SMES must prioritise cybersecurity. The Allianz Risk Barometer 2023 reveals that cyber incidents and business interruption remain the top concerns for companies, indicating the significance of taking proactive measures. It's time for your organisation to assess its current cybersecurity posture and identify potential vulnerabilities.

At Storm Warning, we understand the unique risks faced by SMEs in South Africa. That's why we offer comprehensive cybersecurity risk assessment services. Our team of experts will help you evaluate your current security measures and tailor an assessment specifically for your industry, size, and cybersecurity requirements.

Don't let your organization fall victim to cyber threats. Take the first step towards a more secure future by partnering with Storm Warning for a thorough cybersecurity risk assessment. Together, we can safeguard your business and protect your valuable data.

For this free preliminary self-assessment, please answer the following basic cybersecurity risk-related questions:

This is an organisation Risk Assessment form please complete all the questions as accurately as possible.

Please enter the organisation's name
Please select the industry sector of this organisation!
If you selected "Other Industry" please specify which!
Please enter the name of the primary contact person at this organisation!
Please select the contact's job title!
Please specify other job title!
Please enter the contact's mobile number!
Invalid Input
Please enter the contact's valid email address!

Assets Management

1. Does the organisation identify and classify its critical assets and data that require protection:
Please make selection
2. Do you have processes or mechanisms in place to ensure the confidentiality, integrity, and availability of the organization's critical assets and data:
Please make selection
3. Are there specific regulatory or compliance requirements that dictate the protection of certain types of data or assets:
Please make selection
4. Do you frequently assess your critical assets and data to ensure their continued relevance and the effectiveness of their protection measures:
Please make selection
5. Do you have measures in place to prevent unauthorised access, loss, or theft of critical assets and data, such as access controls, encryption, or physical security measures:
Please make selection

Vulnerabilities

1. Does the organisation have a process in place to regularly identify and assess vulnerabilities in its systems and software:
Please make selection
2. Does the organisation prioritise vulnerabilities based on their severity and potential impact on its operations:
Please make selection
3. Does the organisation have a defined process for promptly applying security patches and updates to address identified vulnerabilities:
Please make selection
4. Does the organisation conduct periodic vulnerability scans or penetration tests to proactively identify weaknesses in its systems:
Please make selection
5. Does the organisation have a mechanism to track and monitor the resolution of identified vulnerabilities to ensure timely remediation:
Please make selection

 

Threats

1. Does the organisation have a process in place to regularly identify and assess potential threats to its systems and data:
Please make selection
2. Does the organisation have a mechanism to stay updated on the latest threat intelligence and emerging cybersecurity threats:
Please make selection
3. Does the organisation have documented procedures for promptly responding to and mitigating identified threats:
Please make selection
4. Does the organisation conduct periodic risk assessments to evaluate the likelihood and potential impact of different threats:
Please make selection
5. Does the organisation have a designated team or responsible individuals for monitoring and managing threats to its systems and data:
Please make selection

Policies and procedures

1. Does the organisation have documented cybersecurity policies and procedures in place:
Please make selection
2. Has the organisation communicated its cybersecurity policies and procedures to all employees and stakeholders:
Please make selection
3. Does the organisation regularly review and update its cybersecurity policies and procedures to address emerging threats and changes in the business environment?:
Please make selection
4. Does the organisation have a process for ensuring compliance with its cybersecurity policies and procedures:
Please make selection
5. Does the organisation provide regular training and awareness programs to educate employees about its cybersecurity policies and procedures:
Please make selection

Controls and safeguards

1. Does the organisation have controls and safeguards in place to protect sensitive data from unauthorized access:
Please make selection
2. Does the organisation enforce strong password policies, such as requiring complex passwords and regular password changes:
Please make selection
3. Does the organisation implement encryption measures to secure data during transmission and storage:
Please make selection
4. Does the organisation have firewalls and intrusion detection systems deployed to monitor and protect its network:
Please make selection
5. Does the organisation conduct regular security awareness training for employees to educate them about security controls and best practices:
Please make selection

Detection and response

1. Does the organisation have an incident detection system in place to identify potential security incidents:
Please make selection
2. Does the organisation have a defined process for reporting and escalating security incidents:
please make selection
3. Does the organisation conduct regular monitoring of its systems and networks for suspicious activities or anomalies:
please make selection
4. Does the organisation have a designated incident response team or individuals responsible for investigating and responding to security incidents:
please make selection
5. Does the organisation have documented incident response procedures to guide the steps to be taken in the event of a security breach or incident:
Please make selection

Backup and disaster recovery plan

1. Does the organisation have a backup and disaster recovery plan in place:
please make selection
2. Is the backup and disaster recovery plan regularly tested to ensure its effectiveness:
please make selection
3. Does the organisation have redundant systems or off-site backups to mitigate the impact of a disaster or system failure:
please make selection
4. Does the organisation have a process to regularly update and maintain backups of critical data and systems:
Please make selection
5. Does the organisation have documented procedures to guide the restoration of systems and data in the event of a disaster or data loss:
Please make selection

Data security

1. Does the organisation have data security policies and procedures in place:
please make selection
2. Does the organisation encrypt sensitive data both in transit and at rest:
please make selection
3. Does the organisation have mechanisms to control access to sensitive data based on user roles and permissions:
please make selection
4. Does the organisation conduct regular assessments to identify and address vulnerabilities in data security measures:
please make selection
5. Does the organisation have measures in place to detect and respond to unauthorized access or breaches of sensitive data:
please make selection

Employees' and stakeholders’ awareness

1. Have all employees and stakeholders received cybersecurity awareness training:
Please make selection
2. Are employees and stakeholders aware of their roles and responsibilities in mitigating cybersecurity risks:
Please make selection
3. Does the organisation provide regular updates and reminders about cybersecurity best practices to employees and stakeholders:
Please make selection
4. Does the organization have a process in place to assess the level of cybersecurity awareness among employees and stakeholders:
Please make selection
5. Does the organization have mechanisms to encourage reporting of potential security incidents or concerns by employees and stakeholders:
Please make selection

Third-party vendors and service providers' security risks

1. Does the organisation have a process to assess the security risks posed by third-party vendors and service providers:
Please make selection
2. Does the organisation conduct due diligence to evaluate the cybersecurity posture of third-party vendors and service providers before engaging in business relationships:
Please make selection
3. Does the organisation have contractual agreements or security clauses in place to enforce cybersecurity requirements for third-party vendors and service providers:
Please make selection
4. Does the organisation regularly monitor and review the cybersecurity practices of third-party vendors and service providers:
Please make selection
5. Does the organisation have a process to respond to and mitigate security incidents or breaches involving third-party vendors and service providers:
Please make selection

Regulatory compliance, applicable cybersecurity standards and requirements

1. Does the organisation have a process in place to identify and understand the applicable cybersecurity standards and requirements:
Please make selection
2. Does the organisation have documented procedures to ensure compliance with the identified cybersecurity standards and requirements:
Please make selection
3. Does the organisation regularly assess its cybersecurity practices to ensure alignment with the applicable standards and requirements:
Please make selection
4. Does the organisation have mechanisms to track and monitor changes in cybersecurity regulations and standards:
Please make selection
5. Does the organisation have a designated individual or team responsible for overseeing and enforcing regulatory compliance in cybersecurity:
Please make selection
Please let us know who is submitting this form!

------------------------------------------------------------------------------------------------------------

Congratulations you have completed your Preliminary cybersecurity risk self-assessment!

 

 

 

 

 

 

 

 

 

----------------------------------------------------------------------------------------------------------

Invalid Input
Invalid Input

What is StormWarning! ?

 StormWarning! is a Cybersecurity consultancy. Our experienced team of cybersecurity experts provide cybersecurity assessments, cybersecurity training and cybersecurity solutions to organisations that have a high risk public profile. StormWarning! is your organisation's best defense against the ever growing cascade of innovative security threats raining down on all organisations with a public digital footprint.

What is Cybersecurity?

Cybersecurity is the practice of protecting critical systems and sensitive information from digital attacks. Also known as information technology (IT) security, cybersecurity measures are designed to combat threats against networked systems and applications, whether those threats originate from inside or outside of an organization. StormWarning! is constantly researching the latest cybersecurity threats and building innovative measures to prevent them.

 

NIST Audit & Targeted Cyber-Risk Training

StormWarning! offers comprehensive Cybersecurity Consulting, with a focus on its Automated Online Auditing Solutions, primarily the NIST CSF Readiness Audit. This audit is prioritized as its results directly inform the organization's needs for targeted cybersecurity training. By identifying specific gaps in risk management knowledge, they deliver precise education via Short Courses—like Cybersecurity Risk Management or Understanding Cybersecurity GRC—to ensure staff and leadership close deficiencies and maintain compliance.

Their full suite of services also includes robust Risk Management planning, development of essential Policies, impactful Cybersecurity Awareness Campaigns, and a security monitoring/incident response platform, StormFront. Additionally, we offer a resource library of Cybersecurity Books authored by our esteemed associate Dr. Zoran Mitrovic.