Cybersecurity
Security built around the people who use it.
A suspicious email. A reused password. A rushed decision at the end of a long day. We work on the ground between an ordinary moment and a serious problem.
- Your people are part of your security.
- Security starts before the click.
- One small mistake can expose important information.
- Build safer digital habits.
What we cover
Six ways we shrink the gap between you and a bad day.
Start with one, or lean on all six. Every engagement begins with a conversation about what you actually stand to lose.
- Teach
Awareness training
Your team learns what a scam actually looks like.
A practical workshop run at your offices for up to ten people, plus the slides, trainer notes and drill scripts, so whoever runs onboarding next year can teach it again without calling us.
- Assess
Security assessments
A clear picture of where the real risk sits.
We test your systems the way someone with bad intentions would, then hand you a plain-language report ranked by what actually puts you at risk, not by what sounds most alarming.
- Govern
Policies and compliance
Paperwork that would survive an audit.
Gap assessments against the Malawi Data Protection Act and relevant sector rules, policy drafting and audit-ready documentation your board or funders can actually read.
- Harden
Network and device protection
The basics set up properly, once.
Firewalls, updates, device policy and access control configured correctly and then kept that way as the organisation grows.
- Watch
Monitoring and response
A plan for the day something does go wrong.
Someone watching the signals, and a clear set of steps to follow in the first hour of an incident, so a bad morning does not turn into a bad month.
- Control
Access control and surveillance
The physical and digital sides finally agree.
CCTV and biometric access built into the same security thinking as your network, so who can walk in and who can log in are answered together.
Awareness training
A training toolkit your team keeps after we leave.
Most awareness training is a slideshow nobody remembers. Ours is a toolkit: a workshop at your offices for up to ten people, plus the deck, the trainer notes and the drill scripts, so the learning does not leave when we do.
- Phishing and social engineering: what a real scam looks like on WhatsApp, email and phone
- Passwords and accounts, including a painless path to a password manager
- Handling devices and information on laptops, phones and shared office computers
- Reporting drills: what to do in the first ten minutes after something feels wrong
Try it yourself
The same tools we hand your team.
A taste of what is inside the toolkit. Everything below runs in your browser only. Nothing you type is stored or sent anywhere.
This runs entirely in your browser. Nothing you type here is stored or sent anywhere.
Policies and compliance
Paperwork that would actually survive an audit.
Compliance is not a binder nobody opens. We work through what the Malawi Data Protection Act and your sector genuinely require, then write policy in language your team can follow on a normal Tuesday.
- Gap assessment against the Malawi Data Protection Act and relevant sector rules
- Policy drafting: acceptable use, information handling, incident response, retention
- Audit-ready documentation your board or funders can actually read
- An ongoing retainer, so policy keeps up with how the organisation changes
Common questions
What organisations ask us about security.
If you are weighing up whether this is worth doing, start here.
What is cybersecurity awareness training and who is it for?
It is a practical workshop for the people in your organisation who handle information every day, not just the IT team. It covers what a real scam looks like on WhatsApp, email and phone, passwords and accounts, handling devices and information, and what to do in the first ten minutes after something feels wrong.
How long does a cybersecurity training session take, and how many people can attend?
A session runs for an afternoon at your own offices, for up to ten people at a time. Larger organisations usually run several sessions so every team is covered.
Do we keep the training materials afterwards?
Yes. You keep the full toolkit: the slide deck, the trainer notes and the drill scripts. Whoever runs onboarding next year can teach the same material again without calling us back.
Can Octet help with Malawi Data Protection Act compliance?
Yes. We run a gap assessment against the Malawi Data Protection Act and the rules for your sector, draft the policies that come out of it, including acceptable use, information handling, incident response and retention, and produce audit-ready documentation your board or funders can actually read.
What does a security assessment involve?
We test your systems the way someone with bad intentions would, then give you a plain-language report ranked by what genuinely puts you at risk rather than by what sounds most alarming. You get a clear picture of where to spend first.
How do we start if we are not sure what we need?
Start with a free security review. It takes thirty minutes, carries no obligation, and we tell you honestly where the real risk sits before you spend a kwacha fixing the wrong thing.
Not sure where to start
Start with a free security review.
Thirty minutes, no obligation. We look at what you have and tell you honestly where the real risk sits, before you spend a kwacha fixing the wrong thing.
Contact
Have a problem worth solving?
Tell us what you are working on. Let us figure out the technology together.
Office
Area 48, Bingu National Stadium, Corporate Box E14, Lilongwe, Malawi
- Monday to Friday
- 08:00 – 17:00
- Saturday
- By appointment
- First consultation
- Free