← All FAQs
Cybersecurity

How often should I run a security assessment?

For most SMEs, a formal, documented security risk assessment should be performed at least annually, with continuous monitoring filling the gaps between formal assessments, rather than treating security as a once-off project that's "done" after the first review.

Why Annual Is a Sensible Baseline, Not Just an Arbitrary Number

POPIA Section 19(2) specifically requires identifying reasonably foreseeable risks to personal information and establishing safeguards against them, with an expectation this is reviewed regularly, not assessed once and left static. Your business's actual risk profile changes constantly, new systems get added, staff turn over, new remote work arrangements begin, third-party vendors change, an assessment from two years ago may no longer reflect your genuine current exposure.

What Triggers an Assessment Outside the Regular Annual Cycle

  • Significant system changes, migrating to a new cloud platform, deploying a new customer-facing application
  • After a security incident, near-miss or actual, to understand what allowed it and close the specific gap
  • Before major compliance milestones, tender submissions or client due diligence often require recent assessment evidence
  • Significant team or structural changes, mergers, new departments, substantial headcount growth
  • New regulatory requirements, changes in POPIA guidance or sector-specific regulation affecting your obligations

What a Proper Assessment Actually Involves

A structured assessment goes beyond a superficial checklist: mapping where personal and business-critical data actually lives, who can access it, how it could realistically be exposed (a lost laptop, a phishing email, a misconfigured cloud storage bucket), and rating each identified risk by likelihood and impact. This should conclude with a documented, prioritised list of gaps and remediation steps, not just a generic pass/fail score.

Continuous Monitoring Versus Periodic Assessment

These serve different, complementary purposes: continuous monitoring (24/7 SOC, dark web monitoring, endpoint detection) catches active threats and compromise attempts in real time. Periodic formal assessment steps back to evaluate whether your overall security posture, policies, and controls are still appropriately matched to your current risk, a different, more strategic kind of review that daily monitoring alone doesn't provide.

What Documentation to Keep

Beyond the assessment itself, keep records of what was assessed, what was found, and what remediation was taken, this documentation is exactly what demonstrates "reasonable safeguards" under POPIA if you're ever investigated following an incident, and it's often specifically requested during public-sector tender processes or client security due diligence.

Our Approach

We build annual structured risk assessments into ongoing managed security relationships as standard, alongside continuous 24/7 monitoring for real-time threat detection between those formal reviews, and provide the documented reporting needed for both POPIA compliance evidence and client or tender due diligence requests.