Security Practices

Governed security, documented and continuously improved.

The people, processes and controls that underpin Numata's information security programme, aligned to the CIS Controls, NIS2, POPIA and GDPR and independently validated through Cyber Essentials Plus.

Monitoring
Continuous
Incident response
CISO led
Service desk
24 / 7
Access control
MFA and SSO

At Numata, we are committed to building a culture of cybersecurity excellence that aligns seamlessly with the goals of our clients and organisation. By placing the right individuals in the right roles, fostering effective collaboration, and concentrating on the most critical priorities, we aim to proactively protect our systems and data.

Jason Scanlon, Chief Information Security Officer
Governance, Risk and Compliance

Who owns security, and how it is run.

  • Certified Chief Information Security Officer

    Numata employs a Chief Information Security Officer (Jason Scanlon) who reports to the Chief Operating Officer, a direct report of Numata's CEO. The CISO leads risk management and cybersecurity strategy, incident response, crisis management and the security-first culture across the organisation.

  • Risk Management Committee

    A Risk Management Committee, made up of senior management, IT leaders, compliance officers and department heads, oversees the implementation and effectiveness of Numata's Risk Management Framework, reviews assessments, monitors emerging risks and regulatory change, and aligns risk practice with business objectives.

  • Internal IT Governance, Risk and Compliance

    A staffed GRC function conducts multiple internal audits annually to assure that internal controls continue to operate effectively and to maintain continuous external audit readiness. The team supports legal and privacy compliance and prepares Numata for additional security standards as needed.

  • Third-Party Risk Management

    A Third-Party Risk Management programme evaluates vendor and supplier risk through questionnaires, interviews, onsite visits and continuous security posture monitoring. Vendors are assessed for compliance with standards such as ISO 27001, GDPR and POPIA, and monitored on an ongoing basis.

  • Cyber and Professional Indemnity Insurance

    Numata maintains cybersecurity and professional indemnity insurance through specialist providers, protecting against financial losses from cyber incidents such as data breaches, ransomware and business interruption, and against claims related to service delivery.

  • Employee Security and Training

    Staff receive security education on hire, monthly and as needed, covering safe computing, acceptable use, ransomware, endpoint security, credential security, social engineering and phishing. Regular phishing simulations reinforce awareness, with additional training where a staff member engages with a simulated message.

Cyber Hygiene and Defence

The controls that protect our estate every day.

  • Intrusion Monitoring and External SOC

    Numata operates threat management, intrusion monitoring and an external Security Operations Centre (SOC) partnership that provides continuous coverage. Alerts are triaged, investigated and escalated in line with Numata's Incident Management and Response policy.

  • Endpoint Protection

    Endpoint protection is deployed across managed devices with malware protection, secure configuration and centralised policy enforcement, aligned with the Cyber Essentials control set.

  • Incident Management and Response

    Numata follows an Incident Management and Response policy aligned with best practices, led by the CISO's Incident Response Team. The plan covers detection, containment, eradication, recovery and post-incident review.

  • Vulnerability Management and Penetration Testing

    Vulnerability and patch management processes cover endpoints, servers and network infrastructure. Penetration testing is integrated into the security strategy to continuously improve defensive capabilities.

  • Identity, Access and Network Security

    Each user receives unique credentials, strong passwords and mandatory Multi-Factor Authentication (MFA). Centrally managed Single Sign-On (SSO) enforces secure access and regular access audits confirm compliance with security policies. Network operating systems are monitored and updated to address vulnerabilities.

  • Business Continuity and Disaster Recovery

    Business Continuity and Disaster Recovery plans are maintained alongside the Incident Response plan, supported by the GRC function to keep response and recovery plans current and actionable.