Small businesses get targeted precisely because they are small. Attackers know that a company of fifteen people rarely has an IT department, that the owner approves payments from a phone, and that the same password often opens the email, the accounting system and the bank profile. The attack that hurts a South African SME is almost never sophisticated. It is a convincing email asking accounts to update a supplier’s banking details.
On top of the fraud risk sits a legal one. The Protection of Personal Information Act applies to businesses of every size, so the customer list on your laptop and the ID copies sitting in your email carry obligations. This session covers both sides in practical terms, without the jargon.
What actually goes wrong in South African small businesses
Three patterns come up repeatedly. The first is business email compromise, where an attacker quietly watches a mailbox and then sends a payment instruction with changed banking details at exactly the right moment. The second is a password reused across systems, so one leak opens several doors. The third is ransomware arriving through an attachment, which locks the files the business runs on and leaves the owner with no clean backup.
The South African Banking Risk Information Centre publishes regular guidance on payment and card fraud patterns, and it is worth reading with your finance person rather than alone.
POPIA in plain language
If you hold information that identifies a person, you are processing personal information and POPIA applies. That includes customer names and numbers, employee records, ID copies, and the marketing list you have been building for years. The Act asks you to collect only what you need, tell people what you will use it for, keep it secure, and delete it when the purpose ends.
You are also expected to appoint an Information Officer, which for most small businesses is the owner, and to register that person with the Information Regulator. Many owners have simply never been told this step exists.
What this session covers
- Stopping payment fraud. The verification rule that prevents almost all changed banking detail scams, built into your process so it does not depend on somebody remembering.
- Passwords and access. Why a password manager and two factor authentication on email and banking give the biggest security return for the least money.
- Backups that work. The difference between a copy and a backup, and how to test a restore before you need it.
- Staff as the first line. What to teach a team of five, and how to make it safe for them to question the owner.
- POPIA basics. Information Officer registration, a privacy notice, consent for marketing, and record retention.
- If it happens to you. The first hour matters. Who to call, what to preserve, and when you must notify people.
Who should watch this session
- Owners who approve payments, especially where somebody else prepares them.
- Businesses holding customer databases, employee files or ID copies.
- Anyone marketing by email or WhatsApp who is unsure whether they have valid consent.
- Service businesses holding client data under contract, where a breach becomes a client problem as well as yours.
What to do after the session
Turn on two factor authentication for your email and banking today, because it is free and it blocks the most common route in. Then write down one verification rule for banking detail changes and tell your team it applies to instructions from you as well. Finally, check whether your Information Officer registration has been done.
Our free templates and guides include policy documents you can adapt rather than draft from scratch. If an incident has already cost you money and cash flow is tight, look at what is available on our business funding pages.
Frequently asked questions
Does POPIA really apply to a business with five employees?
Yes. The Act does not exempt businesses by size. What changes with size is how much process you need, not whether the obligations exist.
Do I need expensive software to be reasonably secure?
No. Two factor authentication, a password manager, current updates and a tested backup cover most of the realistic risk for a small business. Those are cheap or free.
Can I still send marketing emails to my existing list?
It depends how the addresses were collected and whether the person is an existing customer. The safe position is a clear opt out on every message, and stopping mail to addresses that never engage. That protects your compliance position and your sender reputation at the same time.
Someone changed a supplier’s banking details and we paid. What now?
Contact your bank immediately, because speed decides whether funds can be recalled. Report it, preserve the emails rather than deleting them, then fix the verification process before the next payment run.
Watch the session and pick the two actions that apply to your business. Security for a small business is mostly a handful of habits done consistently, not a large budget. Join the community to compare notes with other owners, or see the rest of the sessions.