Skip to main content

Insights

Web security, compliance, and POPIA — in plain English.

What the law actually requires of a South African business, and how confirmed scanning gives you evidence you can hand to a bank, insurer, or client — and re-run later.

Indigo topographic contour lines rising from a dark grid toward a lit horizon.

Featured · Foundations · 9 min read

Website security for South African businesses: the 2026 guide

The comprehensive hub: what website security actually means, what POPIA §19 requires, the threat reality in rand terms, and where to go deeper on scanning, cost, compliance, and sector-specific risk.

Read the guide →
An indigo wireframe network on a dark field, a few nodes lit brighter than the rest.

Comparison · 6 min read

Vulnerability scan or penetration test: which does your business actually need?

A scan is cheaper — and for POPIA §19 it's usually the right-sized evidence. Here's when you genuinely need a manual pen test, and when a confirmed scan is the honest answer.

A dark indigo grid of connected nodes, several glowing points scattered across the field.

Pricing · 5 min read

What does a web-application security test cost in South Africa?

The direct answer, plus the full cost spectrum from free DIY tools to six-figure pen tests — and what actually drives the price. Most competitors won't show a number; here's ours.

Fine indigo network lines over a dark ground, with lit nodes marking points across the grid.

Compliance · 6 min read

Financial data protection in South Africa: what the law actually requires

There's no “Financial Data Protection Act” in South Africa — financial and payment data is personal information under POPIA §19. Where PCI DSS fits, and the evidence a bank asks for.

Abstract indigo wireframe blueprint on a dark field, one node lit.

Compliance · 5 min read

Which compliance standards actually matter for web application security in South Africa?

POPIA §19 is the standard with legal teeth. Here's what “reasonable technical measures” means for a web app — and where PCI DSS and ISO 27001 stop.

Indigo topographic contour lines rising from a dark grid toward a lit horizon.

Foundations · 5 min read

What is cybersecurity compliance, and why does it matter for your business?

Compliance isn't the PDF you file — it's the evidence you can re-run when a bank, insurer, or client asks you to prove it. POPIA §19 in plain English.

Interlocking indigo modules connecting into a larger grid on a dark field.

How-to · 6 min read

How do you fit web application security scanning into an existing compliance programme?

Give scanning a trigger, an owner, and a record. Where it belongs — at release, after change, and on a schedule — and how findings slot into your POPIA §19 register.

Fine indigo data-flow lines streaming through a wireframe gateway on a dark field.

E-commerce · 6 min read

What are the best practices for data security in e-commerce?

Lock down input, sessions and access, patch what you run, and know where POPIA §19 ends and PCI DSS begins. Practical guidance for a South African online store.