CX Consulting

CX Consulting CX Consulting offers a variety of IT services ranging from security assessments, cyber security consulting, as well as IT Managed Services.

If your security team is like most, you may lack unified visibility across tools. This makes it harder to spot and stop ...
04/09/2026

If your security team is like most, you may lack unified visibility across tools. This makes it harder to spot and stop threats early. 🤖

When St. Luke's faced this problem, it turned to Microsoft Security Copilot to connect its security stack, cutting phishing triage time and saving nearly 200 hours each month -- watch the video to see how. 365

Security teams often struggle with a lack of unified visibility across their tools, which delays the detection and neutralization of threats. St. Luke's addressed this challenge by implementing Microsoft Security Copilot to integrate its security stack. This integration drastically reduced the time....

Facing growing pressure from alerts, threats, and AI-driven attacks? 🤖 You're not alone.We recommend checking out this d...
03/09/2026

Facing growing pressure from alerts, threats, and AI-driven attacks? 🤖 You're not alone.

We recommend checking out this demo video, which shows how Microsoft Security Copilot agents handle high-volume tasks, adapt to your workflows, and operate within a Zero Trust framework across your tools. Security

Security demands keep growing while time and resources stay limited. This demo video shows how Microsoft Security Copilot agents handle high-volume security tasks, adapt to your workflows, and operate within a Zero Trust framework. Watch how these AI-powered agents work across your existing tools to...

Are your defences keeping up with AI-powered threats?Cybercriminals are using automation and AI-assisted tactics to scal...
02/09/2026

Are your defences keeping up with AI-powered threats?

Cybercriminals are using automation and AI-assisted tactics to scale phishing, credential theft and ransomware. That means businesses need practical protection that evolves as risks change.

What to check:
* Are you detecting automated phishing at scale?
* Do you have controls to reduce credential theft?
* Can your ransomware response keep pace with fast-moving attacks?

Download our free guide to learn how CX Consulting (Pty) Ltd can help protect your organisation and close those gaps.

https://campaigns.channext.com/cx-consulting-pty-ltd/ransomware-en-gb?lang=en_US&utm_source=fb&utm_term=42402

Are your Microsoft 365 accounts over-permissioned or showing gaps in security posture?Overly broad access and inconsiste...
26/08/2026

Are your Microsoft 365 accounts over-permissioned or showing gaps in security posture?

Overly broad access and inconsistent controls increase breach risk — and the potential impact across your business.

What to check:
- Visibility: Can you see who has access and where?
- Access control: Are permissions limited to what's needed?
- Recovery: Do you have fast, proven steps to recover when incidents occur?

With support from CX Consulting (Pty) Ltd, you can reduce risk by improving visibility, limiting unnecessary access, and strengthening recovery capabilities for a more resilient Microsoft 365 environment.

Find out how we help strengthen Microsoft 365 protection:
https://campaigns.channext.com/cx-consulting-pty-ltd/microsoft-365-es-la?lang=en_US&utm_source=fb&utm_term=43272

A small discovery that South Africans should pay attention to.A researcher recently took apart how Microsoft Paint and P...
25/08/2026

A small discovery that South Africans should pay attention to.

A researcher recently took apart how Microsoft Paint and Photos generate AI images on Windows, and found something worth talking about. Every image created with these tools carries an invisible watermark tied to a unique ID issued by Microsoft's servers each time a prompt is submitted, and successive prompts can be linked to one another. Microsoft had disclosed that it filters and moderates prompts, and adds C2PA content credentials, but had not made clear, in plain terms, that this metadata ties an image back to the person who requested it.

Why should this matter to someone who has never opened Paint in their life?
Because this is exactly the kind of quiet, behind-the-scenes data collection POPIA was written to deal with. A user ID linked to a prompt, and by extension to a Microsoft account, is personal information. Under our Act, a lawful basis is required to process it, the purpose must be clear, and people should reasonably be able to understand what is being collected and why. A watermark buried in pixel data, explained only in documentation most people will never read, sits uncomfortably against that standard.

There is a history here worth remembering. Decades ago, laser printer manufacturers embedded near-invisible tracking dots into printed pages, a practice that only came to light through independent research. We may be watching a similar pattern with AI image generation, just at greater scale, given how much of ourselves goes into a simple prompt.

To be fair to Microsoft, the intention is largely legitimate. Watermarking AI content helps combat misinformation, protects artists, and supports standards such as the EU's Code of Practice on transparency. The concern is not that provenance tracking exists, but whether people know, in language they understand, that their activity is tied to an identifier and retained somewhere.

For businesses, this is a good moment to check your own house. If your organisation issues Windows devices or uses Copilot features, ask your IT or security partner two things: what data is actually generated and transmitted when these AI features are used, and whether that activity is reflected in your data protection impact assessments and your Information Officer's records of processing.

For everyone else, the lesson is simpler. Convenience often comes with a quiet trade-off, and it is worth asking, now and then, what a tool is doing in the background while it does the thing you asked it to do.

I would be glad to hear how others, in security, legal, compliance or simply as concerned users, are reading this.


Privacy? Not if you use hosted AI services

22/08/2026

South Africa has had a difficult few months on the cyber front. Four incidents alone: Rectron, Euphoria Telecom, Fidelity Services Group and Pick n Pay - are worth sitting with, not for the headlines, but for what they tell us about the state of our collective resilience.
Rectron, one of the country's largest ICT distributors, confirmed in July that its IT environment had been accessed unlawfully by an unauthorised third party, with personal information potentially exfiltrated.

The intrusion, suspected to be linked to the DragonForce collective, was severe enough that the distributor closed all its branches nationwide and halted operations for more than a week.

Euphoria Telecom, a respected local cloud PBX provider, detected unauthorised access to its cloud environment in mid-July. Commendably, its leadership moved fast: precautionary limits on international dialling were applied to protect customers from fraudulent charges after the intrusion was identified, and the company confirmed ransomware was not involved.

Fidelity Services Group, Southern Africa's largest private security provider, was listed by the extortion group RansomHouse. Its CEO stated plainly that no third-party or customer information was breached, a claim strengthened by the fact that systems were isolated the moment the incident was identified.

Pick n Pay rounded out the pattern with a breach traced not to current infrastructure, but to customer information from a retired, rebranded - a reminder that decommissioned systems remain a liability until they are properly retired, not merely switched off.

What connects these four? None involved a sophisticated zero-day. All were disclosed under POPIA's mandatory breach notification duty. All required external forensic specialists to be brought in after the fact, rather than having that relationship on retainer beforehand. And all sit within a country that, per Interpol's 2026 assessment, accounts for 92% of ransomware detections on the continent.

The uncomfortable truth is this: incident response plans are being tested for the first time during the incident itself. That is not resilience. That is improvisation under pressure.

We value the perspective of others in governance, risk and security roles here: are we, as South African business, genuinely investing in prevention and readiness, or are we simply becoming more practised at damage control?

Fragmented security operations can make it harder to detect and respond to threats efficiently. 📊This analyst report sho...
20/08/2026

Fragmented security operations can make it harder to detect and respond to threats efficiently. 📊

This analyst report shows how a unified, AI-driven SecOps platform improves visibility, reduces false positives, and streamlines workflows.

Download this complimentary report to see how Microsoft Defender and Sentinel drive 242% ROI and strengthen security outcomes. Security

Security complexity can slow response and increase costs. This analyst report on the 'Total Economic Impact™ of Microsoft Defender and Sentinel' shows how a unified, AI-driven SecOps platform like Microsoft Defender improves detection, reduces false positives, and streamlines operations. For insig...

Think your backups are enough? Think again.Backing up data is necessary, but recovery readiness is more than copies on a...
19/08/2026

Think your backups are enough? Think again.

Backing up data is necessary, but recovery readiness is more than copies on a shelf. You need secure backups, regularly tested recovery procedures, and protections for the systems that handle recovery — because those are targets too.

A simple checklist for stronger resilience:
- Ensure backups are encrypted and access-controlled
- Test recovery processes on a schedule, not just once
- Protect recovery systems from threats that aim to disable restoration

Want to see how this works in practice? Book a consultation with CX Consulting (Pty) Ltd.

https://campaigns.channext.com/cx-consulting-pty-ltd/ransomware-en-gb?lang=en_US&utm_source=fb&utm_term=41734

17/08/2026

This week's South African Cyber Threat Intelligence Report (Week 33, 2–8 August 2026) shows the country's threat level has sat at HIGH for thirteen consecutive weeks, and the sectors under pressure are shifting in ways every risk committee should note.

Two South African organisations confirmed breaches inside a single week. DC Partner, one of only four NCR-accredited payment distribution agencies in the country, confirmed a ransomware attack and is issuing section 22 notifications under POPIA. Its estate holds identity numbers, bank details, debit order mandates and creditor schedules for consumers already under debt review. Fidelity Services Group, Southern Africa's largest integrated security provider, also confirmed a cyber incident, with the threat actor subsequently publishing exfiltrated data.

The sector heatmap tells its own story. Four sectors entered the critical or high-risk bands this week: MSP and IT distribution, professional and business services, manufacturing and wholesale, and property and hospitality. The MSP entry is driven by a vulnerability pair in N-able's N-central platform, under confirmed active exploitation, where one compromised provider reached nine downstream clients. Any business outsourcing IT management should ask its provider, in writing, which platform it runs and whether it is patched.

INTERPOL's African Cyberthreat Assessment, released this same week, puts the picture in context: South Africa accounts for 92 percent of Africa's ransomware detections, 70 percent of business e-mail compromise detections, and close to 40 percent of phishing detections. SABRIC's 2025 statistics recorded digital banking crime losses of R2.4 billion, up from roughly R1.9 billion the year before.

What this means for South African businesses over the next six to twelve months:

Regulatory exposure is real and enforceable. POPIA provides for fines of up to R10 million and possible imprisonment for responsible parties, and two confirmed breaches this week alone triggered section 22 notification duties.

Cyber insurance is hardening. Underwriters are demanding demonstrable controls before offering cover. Roughly one in three South African SMEs has already experienced a cyberattack, yet only about a quarter carry cyber insurance. Businesses unable to evidence basic controls risk becoming uninsurable.

Supply chain risk needs board-level attention. One compromised managed service provider can become the access point into many client organisations at once. Vendor assurance must move beyond certificates and ask what data a supplier holds and how they would notify you.

If your organisation has not reviewed its incident response plan, provider security posture, or cyber insurance position in the last six months, now is a sensible time to do so.



Source: SA Cyber Threat Intelligence Report, Week 33, TLP:WHITE, SA-CTI-2026-W33 (Steynberg/Sekate).

Attacks can escalate quickly when your visibility and response are disconnected. ⚠️This video shows how Microsoft Defend...
17/08/2026

Attacks can escalate quickly when your visibility and response are disconnected. ⚠️

This video shows how Microsoft Defender disrupts those attacks while enabling customizable telemetry and secure deployment across diverse estates.

Watch to see how stronger, faster protection helps reduce risk and improve response. Security

Get your security to act before damage spreads. This video highlights Microsoft Defender's attack disruption capabilities, showing how it helps stop attacks in progress while protecting critical assets. Watch the video to understand how stronger visibility and faster response can improve security ou...

Address

Cape Town

Opening Hours

Monday 08:00 - 17:00
Tuesday 08:00 - 17:00
Wednesday 08:00 - 17:00
Thursday 08:00 - 17:00
Friday 08:00 - 17:00

Telephone

+27212011247

Alerts

Be the first to know and let us send you an email when CX Consulting posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to CX Consulting:

Shortcuts

Featured

Share