Wired Audit: IT Security Audit for South African Businesses
An IT security audit is a structured review of your IT environment, policies, and controls against a defined framework — typically POPIA, ISO 27001, NIST CSF, or a sector-specific standard. The output is a documented assessment of where you actually are versus where the framework expects you to be, with a prioritised remediation plan.
For South African businesses, IT security audits have become a practical necessity rather than a compliance nice-to-have. POPIA Section 19 requires "appropriate, reasonable technical and organisational measures to safeguard personal information" — and the Information Regulator has been issuing enforcement notices since 2024. Cyber insurers now require a documented security posture for cover. And boards, under King IV, are personally accountable for IT governance and information security oversight. An IT security audit produces the evidence each of those audiences needs.
Wired Audit is a packaged compliance and risk assessment service — clear visibility on your IT security posture, gaps, and priorities.
What's Included in Wired Audit
1. Security Posture Assessment
A documented review of your current security controls against the most relevant frameworks for South African businesses.
- POPIA Section 19 alignment review
- ISO 27001:2022 Annex A controls assessment
- NIST CSF maturity scoring
- King IV Principle 12 governance review
- Sector-specific overlays where relevant (PCI DSS, FAIS, FSCA cybersecurity directive)
2. Identity, Access, and Endpoint Review
The technical layers most commonly exploited in SA SME compromises. We review the configuration and produce specific findings.
- Microsoft 365 / Google Workspace security hardening review
- MFA enforcement and conditional access policy review
- Active Directory / Entra ID audit (privileged accounts, dormant users, password policy)
- Endpoint protection coverage and configuration
- Patch management hygiene
3. Network and Perimeter Security Review
- Firewall configuration and rule-base review
- Network segmentation review (VLANs, guest networks, IoT isolation)
- Remote access architecture (VPN, ZTNA)
- Wireless network security
- Public-facing services exposure analysis
4. Data Protection and Backup Review
- Backup coverage, encryption, and immutability review
- Data retention policy review
- Encryption at rest and in transit
- Mobile device and removable media controls
5. Interactive Compliance Dashboard
Findings don't live in a 60-page PDF that nobody opens. Wired Audit delivers an interactive dashboard you can refer back to, share with leadership, and use to track remediation progress over time.
- Tracked findings with severity, owner, target date
- POPIA and ISO 27001 alignment scoring
- Remediation progress charts
- Auditor-ready export when requested
6. Prioritised Remediation Plan
Every finding ships with a recommended remediation — what to do, in what order, with what effort estimate. You can action it internally, use Wired IT's other services, or use a third party.
- Per-finding remediation recommendation
- Quick-win identification (changes with the biggest impact for the least effort)
- Resource and effort estimate per remediation
- Sequencing recommendation
Frameworks Wired Audit Aligns To
Audit findings are mapped to the frameworks South African businesses are most often measured against:
- POPIA (Protection of Personal Information Act, Act 4 of 2013) — particularly Section 19 security safeguards
- Cybercrimes Act 19 of 2020 — incident logging and reporting readiness
- ISO 27001:2022 — full Annex A controls coverage
- NIST Cybersecurity Framework (CSF) 2.0 — identify, protect, detect, respond, recover, govern
- King IV — Principle 12 (Governance of Technology and Information)
- PCI DSS v4.0 — for clients processing card data
- FSCA Joint Standard 1 of 2023 — for FSP-regulated entities
- SARB cybersecurity directives — for banking-adjacent entities
We don't certify your business against any of these — that's an external auditor's role. We give you the gap analysis, the evidence, and the remediation plan that make the certification audit short.
Wired Audit vs Full IT Strategy and Consultancy
| Capability | Wired Audit (productised) |
IT Strategy and Consultancy (full) |
|---|---|---|
| Security posture assessment | ✓ Included | ✓ Included |
| Compliance gap analysis | ✓ POPIA, ISO 27001, NIST | ✓ + sector frameworks |
| Interactive compliance dashboard | ✓ Included | ✓ Included |
| Prioritised remediation plan | ✓ Included | ✓ Included |
| Forward-looking IT strategy | X | ✓ forward roadmap |
| BIA and full BCP | ✗ | ✓ Included |
| Policy and SOP drafting | ✗ | ✓ Included |
| Vendor and supplier strategy | ✗ | ✓ Included |
| Engagement length | Productised, shorter | Custom, longer |
| Fit for | Compliance baseline + audit prep | Full IT governance overhaul |
How a Wired Audit Engagement Runs
Every engagement follows the same six phases — the timeline scales with the size of your environment and the depth of regulatory exposure. We agree realistic dates with you during scoping.
- Scoping session Understand your environment, sector, regulatory exposure.
- Document collection. Existing policies, network diagrams, asset inventory, recent test reports.
- Technical review. Configuration review, identity and access audit, network and endpoint review.
- Findings analysis. Map findings to frameworks, score severity, draft remediation plan.
- Dashboard build and handover. Interactive dashboard configured, leadership presentation, formal findings report.
- Ongoing check-ins Track remediation progress on the live dashboard.
Measurable Outcomes
- A documented security posture baseline mapped to POPIA, ISO 27001, and your sector frameworks
- An interactive compliance dashboard tracking findings, severity, and remediation progress
- Prioritised remediation plan with effort estimates and sequencing
- Evidence for cyber insurance renewal — most SA insurers now require a documented audit at renewal
- Board-ready summary for King IV Principle 12 reporting
- Reduced "audit panic" through ongoing posture tracking, not once-off certification fire-drills
Frequently Asked Questions
What is an IT security audit?
An IT security audit is a structured assessment of your IT environment, policies, and controls against a defined framework — typically POPIA, ISO 27001, or NIST CSF for South African businesses.
It documents where you actually are versus where the framework expects you to be, with a prioritised remediation plan. It's different from a penetration test (which simulates active attack) and a vulnerability scan (which finds known weaknesses) — an audit assesses your overall security programme.
How long does Wired Audit take?
Wired Audit moves through scoping, document collection, technical review, findings analysis, and leadership handover. Total length depends on the size of your environment and the depth of regulatory exposure — we'll quote a realistic timeline during scoping.
What's the difference between Wired Audit and a full IT Strategy engagement?
Wired Audit is a focused, productised audit — what's your current security and compliance posture, what are the gaps, what should you fix first. Our broader IT Strategy, Audit and Consultancy service includes the audit but also the forward-looking strategy: where IT should go next, how budget should be allocated, which capabilities to build.
Most clients start with Wired Audit; some upgrade to full IT Strategy when scope justifies it.
Are you a registered auditor or assessor?
Wired Audit produces an internal audit / gap assessment, not a certification. Certification under ISO 27001 requires an accredited external auditor — we prepare you for that audit but we don't issue the certification.
For POPIA, there's no certification regime — your obligation is to take appropriate measures and document them, which Wired Audit produces.
Do you require us to act on the findings?
No — the findings are yours to action however you see fit. We provide the remediation plan; you can implement it internally, use Wired IT's managed IT or cybersecurity services, or engage a different provider.
Wired Audit's value is independent assessment, not lock-in.
How often should an IT security audit be repeated?
Audit cadence depends on your sector, regulatory exposure, and risk tolerance. Most SMEs run a full audit on a documented schedule, with lighter check-ins on remediation progress between full audits.
Higher-risk environments (financial services, healthcare) typically need audits more often. The interactive compliance dashboard makes the recurring audit lighter-touch than the first one — much of the framework alignment carries forward.