Why Clients Choose Us
WHY CLIENTS CHOOSE US
Clients consistently choose Cyber Governance Solutions to solve their most pressing IT and cyber challenges.
“They are highly credible, experienced and always professional.”
Business partner
“They look at things holistically, before rushing in with a solution and suggest fit for purpose solutions. They go the extra mile.”
CIO of an industrial group
We mostly work behind the scenes at our clients, helping them prepare for and manage potentially disruptive and costly cyber risks.
Due to the sensitive nature of our work, we cannot always share the names of our clients. We can describe some of the most significant challenges our clients have faced and how we supported our clients.
Modal Box
modal-
Click here to edit the “modal-box” settings. This text is only for editing and will not appear after you publish the changes. Preview modal-Case Study 1
Strengthening IT risk management and controls in a public listed company
Our client is a JSE public listed company in South Africa and is required to comply with several financial reporting controls compliance standards.
The business consists of multiple independent operations with limited IT resources. The level of IT governance and risk management maturity was very low, with mostly informal processes. For JSE reporting compliance, this was inadequate. The client asked Cyber Governance Solutions to assist in several areas to enable sustainable compliance and an acceptable level of governance.
Our solutionWe helped our client to determine the current state of IT governance and controls of all its business operations, as well as the group overall. This was followed by a detailed gap assessment against JSE reporting requirements. We also agreed the proposed controls with the client’s external auditors.
Our next steps involved remediating the design adequacy of the client’s IT processes before rolling out the necessary controls. We implemented CSA testing, and the client’s IT department began testing the effectiveness of the controls.
We recognised that the IT governance and risk management structures and processes had to be strengthened – both at the business unit and group level – to ensure that control remediation is sustainable in the long term. We redesigned the IT governance forum and oversight process. The enhanced structures and processes were deployed. This has been operational for two years.
Business impact and benefits
Our client has seen the following measurable improvements since the completion of the project:
- Enhanced IT governance and control
- Clear visibility of IT risks and mitigation for the Risk Committee
- Reduction of IT external audit findings from 110 in 2020 to 22 in 2023
- CSA compliance of 94%
- Disaster Recovery Plan for all business units
Number of IT External Audit Findings 2020-2023
Strengthening IT risk management and controls in a public listed company
Vew Case StudyCase Study 1
Modal Box
modal-
Click here to edit the “modal-box” settings. This text is only for editing and will not appear after you publish the changes. Preview modal-Case Study 2
Elevating cyber security resistance in a multi-industry listed company
Our client is a listed entity with complex business operations and subsidiary entities that span several industries. Each of these businesses had very specific IT reliance requirements. Overall, the cyber security maturity within the group was not at a desired level. Our client realised that their IT dependence and risk profile had increased, and they initiated a three-year improvement programme to address the risk.
Our solutionOur client requested assistance from Cyber Governance Solutions to provide input at different stages and levels of the improvement programme. This ranged from strategic input in the structure, policies, and standards, as well as information security processes. Due to the nature of the client’s organisation, it also required us to design a solution that is fit-for-purpose based on each business operation’s risk profile.
Business impact and benefits
Since the inception of the programme, our client has reported a vast improvement in the following areas:
- User awareness
- Vulnerability management
- Incident response
- Network security
- Penetration testing results
- Insurance compliance
- End point protection
Number of Critical and High Risk Vulnerabilities for the External and Internal Environment
Elevating cyber security resistance in a multi-industry listed company
Vew Case Study