Cyber Security FAQ – Liyatech Solutions

Reference · Cybersecurity Resources

Cyber Security FAQ

Answers to the questions we're asked most in first consultations — on cost, risk, compliance and what actually happens if something goes wrong.


Every first consultation covers a lot of the same ground. We've collected the honest, plain-English answers here — if your question isn't covered, it's probably in our Knowledgebase, or just ask us directly.

Getting Started
We're a small business — are we really a target?
Yes, and often more so than larger companies. Attackers frequently prefer smaller businesses precisely because they tend to have fewer defences in place, while still holding valuable customer, financial or employee data. Size isn't a form of protection on its own.
We already have an IT person or internal team — can Liyatech still help?
Regularly. Most of our managed clients have some internal IT capability already. We typically take on the specialised, time-intensive pieces — 24/7 monitoring, security operations, and Microsoft 365 administration — so your internal team can focus on the projects only they have the context to run.
How much does managed IT or managed security cost?
It depends on your headcount, environment and the level of coverage you need, so we don't quote a single number publicly. What we can tell you upfront: it's typically priced per user or per device, and a free Cyber Readiness Assessment gives us enough information to put together an accurate quote quickly.
What's the difference between managed IT and managed security?
Managed IT keeps your systems running — devices, networks, helpdesk, Microsoft 365 administration. Managed security is specifically about detecting and stopping threats — monitoring, MDR, incident response. Many businesses need both, and they work best when they're coordinated rather than run by two disconnected providers.

Risk & Incidents
What happens if we get hit by ransomware — should we pay?
Paying is a last resort, not a first step. It doesn't guarantee you'll get a working decryption key, and it doesn't guarantee stolen data won't still be leaked or sold. Our first priority in an incident is containment and recovery from backups; if backups aren't viable, we talk through the options honestly, including the realistic odds of payment actually resolving things.
How quickly can you respond to an incident?
Our service desk and CSOC operate 24/7/365, so monitoring and initial response don't wait for business hours. Exact response times depend on your service tier and the severity of the incident, which we'll walk through as part of onboarding.
Is Microsoft 365 secure enough on its own, without extra tools?
Microsoft 365 includes a strong set of security capabilities, but most businesses are only using a fraction of what they're already paying for — multi-factor authentication, conditional access and mailbox protection are often left at default settings. Before recommending additional tools, we usually start by properly configuring what you already have.

Compliance
Do we need to comply with POPIA if we're not a tech company?
Yes. POPIA applies to any organisation that processes personal information — employee records, customer contact details, even a CV inbox counts. There's no exemption for small businesses or for companies outside the tech sector. See our POPIA Compliance Hub for the detail.
How long does a security assessment take?
Our free Cyber Readiness Assessment is a structured, roughly 30-minute review of your backups, access control, endpoint protection and detection coverage, followed by a written summary of findings. Deeper assessments and penetration testing take longer and are scoped individually.
Do you only work with businesses in Centurion or Gauteng?
No — while we're based in Centurion, our managed services and CSOC support businesses across South Africa. Most day-to-day support is delivered remotely, with on-site visits arranged where needed.

"The best question in a first consultation is usually the one people are hesitant to ask — 'are we already behind?' Ask it. We'd rather tell you honestly than have you find out during an incident." Liyatech Solutions

Didn't find your question here?

Check our Knowledgebase for more detailed, step-by-step answers, or send us your question directly.

Check our Knowledgebase

Ready to see where you stand?

Book a free, no-obligation Cyber Readiness Assessment with our team.

Book a free assessment