Accounts and MFA
Multi-factor sign-in on email and key systems.
Most attacks on small businesses succeed because of basics: no multi-factor sign-in, no working backup, unpatched laptops, shared passwords. We check the basics quickly and tell you what to fix first, in plain language.
A short, practical review of the everyday security controls that stop most attacks on small and medium businesses, with a prioritised list of fixes.
Ransomware, account takeover and invoice fraud hit Malaysian SMEs every day, and most incidents exploit the same few gaps. The PDPA's Security Principle also expects practical steps to protect personal data. A hygiene check is the cheapest way to close the gaps before an incident does it for you.
Multi-factor sign-in on email and key systems.
Whether backups exist, are separate and can be restored.
Operating systems, browsers and key software.
Laptops and phones, encryption and screen locks.
Shared and reused passwords, and password managers.
Phishing awareness and reporting.
Priced for SMEs.
Days, not weeks.
No jargon.
Fix list in order.
Ready for insurance or customer questionnaires.
Short online questionnaire.
Call or visit to verify.
Checking key settings.
Fix list in plain language.
Optional help implementing fixes.
Simple rating per area.
Prioritised actions.
Can you restore?
Simple acceptable use and password rules.
Answering questions.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
No. Most attacks succeed through stolen passwords, missing backups or unpatched software, which antivirus does not fix.
Usually a few days from questionnaire to report.
The check tells you what to fix. We can help implement fixes as an add-on.
It covers the basics insurers typically ask about.
No. It is a practical check of basic controls.
Tell us your headcount and main systems. We will confirm the fixed fee.