Identity & access
Microsoft Entra ID configured properly — MFA everywhere, conditional access, least-privilege admin and joiner-mover-leaver hygiene.
Identity is where most real intrusions start, and it's also where they're cheapest to stop: Microsoft's own research puts multi-factor authentication at blocking over 99% of account-compromise attacks, because password spray and credential-stuffing bots have nothing to replay once a second factor is required. Configuring Entra ID properly means MFA is enforced everywhere it matters, not just on a handful of admin accounts, and conditional access policies add context, blocking or challenging sign-ins based on device compliance, location and risk signal rather than trusting a valid password alone.
The other half of identity hygiene is who holds standing access and for how long. Least-privilege admin roles, time-bound elevation instead of permanent Global Admin membership, and a disciplined joiner-mover-leaver process close the gap where most breaches actually widen: an account that kept access long after the role, or the person, moved on. None of this is exotic configuration; it's the baseline Entra ID already supports, applied consistently instead of partially.
How much of this you already own often comes down to licence tier. On the SMB side (up to 300 users), Microsoft 365 Business Premium already includes policy-based identity management and Conditional Access — Business Basic and Standard don't. On the enterprise side, E3 includes Conditional Access, MFA and data-loss prevention, while E5 adds Defender for Office 365's email threat protection, Defender for Identity's behavioural monitoring, and deeper threat analytics on top. A lot of Botswana organisations are sitting on capability their existing licence already includes but has never been switched on, which is why we start by checking what you actually own before recommending anything new.
Microsoft Entra ID
Core identity platform — single sign-on, conditional access, MFA and the joiner-mover-leaver lifecycle.
Conditional Access
Risk-based sign-in policies — block or challenge access by device compliance, location or risk signal, not just a valid password. Included from Business Premium up.
Defender for Identity (E5)
Behavioural monitoring of on-premise and hybrid identity infrastructure for compromised-account activity.
The more connected your operations become, the more there is to protect. We secure identities, devices, information and cloud environments — pragmatically, in the order that reduces the most risk first, with the Microsoft and Acronis tooling your licences likely already include.
Protect & recover
Acronis Cyber Protect across servers and endpoints — backup, anti-malware and recovery rehearsals, because the test of security is the restore.
Microsoft 365 hardening
Secure-score-driven hardening of email, sharing and device access — closing the doors most attacks actually walk through.
Data protection alignment
Controls mapped to Botswana's Data Protection Act — consent, access control and audit trails on personal data flows.
We're a small company — are we really a target?
Yes, precisely because attackers assume your defences are weaker — roughly half of small businesses report attacks. The good news: five essentials stop the large majority of real-world attacks — multi-factor authentication, modern endpoint protection, email security, tested backups and staff awareness. You need those five done properly, not twenty products.
Is multi-factor authentication really necessary?
It is the highest-impact control per pula you will ever spend: Microsoft's research puts MFA at blocking about 99.9% of automated credential attacks. It is already included in your Microsoft 365 licence — the work is enforcing it properly, with conditional access and no legacy-authentication loopholes. Cyber insurers now treat it as mandatory.
What do cyber insurers require before covering us?
Three controls have become effectively non-negotiable: MFA on email, admin and remote access; endpoint detection and response on every device; and tested, immutable backups. Just as important is documented evidence of all three — most declined applications fail on proof, not on tooling. We implement the controls and produce the evidence pack.
What does Botswana's Data Protection Act require of us?
The Data Protection Act, 2024 — in force since 14 January 2025 — applies to any processing of personal data in Botswana. It requires appropriate technical and organisational security measures, notification of breaches to the Commission within 72 hours, and a data protection officer for certain categories of processing. Penalties reach BWP 50 million or 4% of global turnover. The technical half of compliance is exactly the security baseline above.
Our staff are the weak link — what do we do about phishing?
Most incidents start with a phished credential, so treat people as a control, not a liability: awareness training with phishing simulations, email filtering in front of the inbox, and MFA behind it so a single click is never fatal. It is inexpensive, measurable, and insurers recognise it.
Platforms: Microsoft Entra ID · Microsoft 365 · Acronis Cyber Protect · Azure