Data protection alignment
Controls mapped to Botswana's Data Protection Act — consent, access control and audit trails on personal data flows.
Botswana's Data Protection Act 2024 puts real teeth behind personal data handling: controllers must notify the Information and Data Protection Commission within 72 hours of a breach, communicate to affected individuals without undue delay where there's high risk, and demonstrate appropriate technical and organisational measures were in place, backed by fines of up to BWP 50 million or 4% of global turnover, whichever is higher. That last clause is doing the real work; "appropriate measures" is a compliance test that technical controls either pass or fail on the day of an incident, not on the day of an audit.
The controls this covers aren't separate from the rest of the security work; they're the same identity, access and audit-trail capabilities configured with personal data flows specifically in mind. Consent tracking, role-based access control that limits who can see personal information, and audit logs that can reconstruct who accessed what and when, are what actually let you meet a 72-hour notification deadline with facts instead of guesswork, and what let you show the Commission the technical and organisational measures the Act requires, rather than assert them after the fact.
The more connected your operations become, the more there is to protect. We secure identities, devices, information and cloud environments — pragmatically, in the order that reduces the most risk first, with the Microsoft and Acronis tooling your licences likely already include.
Identity & access
Microsoft Entra ID configured properly — MFA everywhere, conditional access, least-privilege admin and joiner-mover-leaver hygiene.
Protect & recover
Acronis Cyber Protect across servers and endpoints — backup, anti-malware and recovery rehearsals, because the test of security is the restore.
Microsoft 365 hardening
Secure-score-driven hardening of email, sharing and device access — closing the doors most attacks actually walk through.
We're a small company — are we really a target?
Yes, precisely because attackers assume your defences are weaker — roughly half of small businesses report attacks. The good news: five essentials stop the large majority of real-world attacks — multi-factor authentication, modern endpoint protection, email security, tested backups and staff awareness. You need those five done properly, not twenty products.
Is multi-factor authentication really necessary?
It is the highest-impact control per pula you will ever spend: Microsoft's research puts MFA at blocking about 99.9% of automated credential attacks. It is already included in your Microsoft 365 licence — the work is enforcing it properly, with conditional access and no legacy-authentication loopholes. Cyber insurers now treat it as mandatory.
What do cyber insurers require before covering us?
Three controls have become effectively non-negotiable: MFA on email, admin and remote access; endpoint detection and response on every device; and tested, immutable backups. Just as important is documented evidence of all three — most declined applications fail on proof, not on tooling. We implement the controls and produce the evidence pack.
What does Botswana's Data Protection Act require of us?
The Data Protection Act, 2024 — in force since 14 January 2025 — applies to any processing of personal data in Botswana. It requires appropriate technical and organisational security measures, notification of breaches to the Commission within 72 hours, and a data protection officer for certain categories of processing. Penalties reach BWP 50 million or 4% of global turnover. The technical half of compliance is exactly the security baseline above.
Our staff are the weak link — what do we do about phishing?
Most incidents start with a phished credential, so treat people as a control, not a liability: awareness training with phishing simulations, email filtering in front of the inbox, and MFA behind it so a single click is never fatal. It is inexpensive, measurable, and insurers recognise it.
Platforms: Microsoft Entra ID · Microsoft 365 · Acronis Cyber Protect · Azure