Serros

National · Provincial · Municipal · SOEs

Protect citizen data and keep public services online.

Public institutions are among the most targeted organisations in South Africa. Serros helps departments, municipalities and state-owned entities defend critical systems and meet their regulatory obligations.

Regulation

Aligned with the frameworks you answer to.

Our controls, reporting and evidence map directly to the legislation and standards public bodies are audited against.

POPIA

Security safeguards for personal information, breach notification readiness and Information Regulator reporting.

Cybercrimes Act

Incident handling and reporting processes that support your obligations under the Act.

MISS & ISO 27001

Information security controls aligned with the Minimum Information Security Standards and ISO 27001.

AGSA audit findings

Remediation plans that address IT general control findings from the Auditor-General.

A modern government building with tall columns

Solutions for the public sector

Security that keeps essential services running.

  • 24/7 monitoring of critical systems, email and user accounts
  • Ransomware readiness, tested backups and recovery plans
  • Penetration testing of public portals and networks
  • Security awareness training for officials and staff
  • Incident response with clear reporting for accounting officers
  • Policy, risk register and audit evidence preparation
See all solutions

Working with us

Protection that fits your procurement process.

We understand public procurement timelines and provide the documentation your supply chain team needs at each stage.

  1. Briefing session

    A confidential call to understand your environment and mandate.

  2. Needs assessment

    A written assessment that can inform your specification or terms of reference.

  3. Proposal & compliance pack

    Pricing, methodology and supplier documentation for RFQs and tenders.

  4. Deployment

    Phased rollout with minimal disruption to public services.

  5. Report & review

    Monthly reporting and quarterly reviews for accounting officers and audit committees.

FAQ

Questions from public sector teams.

Can you respond to RFQs and tenders?

Yes. We provide pricing, methodology, CVs of key personnel and supplier documentation in the format your procurement process requires.

Where is our data stored?

Monitoring data can be kept in South African cloud regions to support data residency requirements. We confirm this in writing during scoping.

Do your staff have security clearance?

Key personnel can undergo vetting where your environment requires it. Let us know your requirements during the briefing session.

Can you help with Auditor-General IT findings?

Yes. We review your findings, build a prioritised remediation plan and collect the evidence your auditors will ask for.

Book a call

Need to strengthen your institution's cyber security?

Book a confidential briefing with a senior consultant. We'll discuss your environment, your audit findings and a realistic path forward.

30 minutes, no sales deck, NDA on request.