Here's the scene that plays out in a South African firm most weeks: a director opens their laptop on a Monday and every file — drawings, contracts, financials, the client database — has been renamed and locked. A text file on the desktop explains that the data is encrypted, that a copy has already been stolen, and that unless a cryptocurrency payment is made within days, everything will be published on a leak site where competitors, clients and the Information Regulator can all see it.

This is double-extortion ransomware, and it has become the dominant model. It's not just "we locked your files" anymore — it's "we locked your files and we're holding your clients' data hostage in public." For a firm whose entire reputation rests on confidentiality and reliability, that second threat is often the more dangerous one.

72hPOPIA breach-notification window
R10mMaximum POPIA fine
Top 5SA among most-attacked nations

Why Engineering & Professional Firms Specifically

Ransomware crews are not throwing darts. They profile targets, and professional firms tick every box:

The "we use the cloud, we're fine" trap

Cloud storage that syncs automatically will happily sync the encrypted versions of your files over your good ones. Backups only protect you if they are versioned, isolated from your network, and — critically — actually tested by restoring them. Untested backups are a story you tell yourself, not a safety net.

What an Attack Actually Costs

The ransom demand is the number everyone fixates on, but it's rarely the biggest cost. Add these up honestly for your firm:

Against that, the cost of getting your defences and response plan in order is small — and it is the entire ROI argument for security. You are not buying software; you are buying the difference between a bad afternoon and a business-ending quarter.

See the Threat for Yourself — In Real Time

You don't have to take our word for any of this. These public, live sources let you watch the threat landscape and check your own exposure right now:

Local incidents are also increasingly reported by MyBroadband and ITWeb — and named South African engineering and consulting firms have appeared on ransomware groups' public leak sites. Follow those outlets and you'll see the pattern is not hypothetical; it's a weekly occurrence. (All of these live in our Trusted Sources directory.)

The Prevention That Pays for Itself

You cannot reduce ransomware risk to zero, but you can make your firm a hard, unrewarding target and ensure that if the worst happens, it's a recovery — not a catastrophe. The essentials:

  1. Tested, isolated backups. Versioned, off-network, and restored on a schedule so you know they work. This single control defeats most ransomware leverage.
  2. Multi-factor authentication everywhere. Email, remote access, admin accounts. It stops the overwhelming majority of credential-based break-ins.
  3. Patching & hardening. Close the known holes attackers scan for — mapped to frameworks like MITRE ATT&CK and the NIST Cybersecurity Framework.
  4. An incident-response plan written in advance. Who to call, how to isolate, how to notify — decided calmly now, not at 2am mid-attack. Our first-72-hours guide walks through it.
  5. Staff awareness. Human error opens most doors; a team that recognises phishing is your cheapest, strongest control.

This is exactly what our audits deliver. A cybersecurity assessment finds the gaps a ransomware crew would exploit; a POPIA compliance audit makes sure a breach doesn't also become a R10 million regulatory problem; and Data Breach Response gives you the plan — and the people — before you ever need them.

Would your firm survive Monday morning?

Find out before an attacker does. We'll assess your real exposure and hand you a prioritised, plain-language plan — no fear-selling.

Related Reading