FREQUENTLY ASKED QUESTIONS +
QUESTIONS ARE A GOOD PLACE TO START
Cybersecurity can get complicated quickly. It doesn’t have to stay that way. Here are some of the things people ask us most often, explained without the jargon.
1. GETTING STARTED
1. I'M NOT SURE WHAT CYBERSECURITY SERVICE I ACTUALLY NEED. WHERE DO I START?
That’s completely fine. You shouldn’t need to diagnose your own cybersecurity problem before speaking to a cybersecurity company.
Start with what you’re worried about, what you’re trying to understand, or what has changed in your business.
We’ll help you work out what makes sense, and just as importantly, what doesn’t.
2. DO SMALL BUSINESSES REALLY NEED CYBERSECURITY HELP?
Small businesses don’t necessarily need complicated security. They do need the right protections in the right places.
That might mean improving account security, understanding what is exposed to the internet, checking for vulnerabilities, improving backups, or helping staff recognise suspicious activity. The goal isn’t to turn a small business into a security operations centre. It’s to protect what matters without making business harder.
3. WILL YOU TRY AND SELL ME A BUNCH OF CYBERSECURITY TOOLS?
No.
Sometimes the right answer is a new tool. Sometimes it’s changing a setting, improving a process, training your team, or simply understanding what you already have. We’d rather recommend the right next step than the most expensive one.
2. ASSESSMENTS & TESTING
1. WHAT’S THE DIFFERENCE BETWEEN A VULNERABILITY ASSESSMENT AND A PENETRATION TEST?
A Vulnerability Assessment looks for weaknesses across your systems and helps you understand what needs attention.
A Penetration Test goes further. With your permission, we actively test whether weaknesses can actually be exploited and what an attacker could potentially reach.
A simple way to think about it:
Vulnerability Assessment:
Where are the weaknesses?
Penetration Test:
What could someone actually do with them?
If you’re unsure which one you need, we’ll help you figure it out.
2. WILL A PENETRATION TEST DAMAGE OUR SYSTEMS?
The objective is exactly the opposite.
Testing is planned, scoped and controlled before anything begins. We agree on what can be tested, what should be avoided, and how the work will be conducted. The aim is to learn how your security behaves under pressure without creating unnecessary disruption.
3. WHAT IS A DIGITAL FOOTPRINT HUNT?
It looks at what someone could discover about your business using legitimate, publicly available sources.
That can include things such as:
+ domains and internet-facing infrastructure
+ staff and organisational information
+ exposed documents
+ technology in use
+ social media
+ publicly accessible information that may help someone build a picture of the business.
The individual pieces may seem harmless. The interesting part is what they reveal when connected.
4. DO YOU NEED ACCESS TO OUR SYSTEMS FOR EVERY ASSESSMENT?
No.
It depends on the service.
A Digital Footprint Hunt, for example, focuses primarily on what can be discovered externally. A Vulnerability Assessment or Penetration Test may require specific access depending on the agreed scope. We’ll explain exactly what is required before anything begins.
3. PEOPLE AND AWARENESS
1. IS SECURITY AWARENESS TRAINING BASICALLY JUST TELLING STAFF NOT TO CLICK LINKS?
It shouldn’t be.
Good awareness training helps people understand how attacks actually show up in everyday work and what to do when something feels wrong.
That includes things like phishing, social engineering, suspicious requests, passwords, MFA, data handling and reporting concerns.
The goal isn’t paranoia.
It’s confidence.
2. ARE PHISHING SIMULATIONS DESIGNED TO CATCH PEOPLE OUT?
No.
A phishing simulation should be a learning tool, not an office humiliation machine.
We use simulations to understand how people respond to realistic situations and where additional support may help.
A click is information.
It isn’t a character assessment.
4. MANAGED SECURITY
1. WE DON'T HAVE A DEDICATED SECURITY TEAM. IS THAT A PROBLEM?
Not necessarily.
A lot of smaller organisations have someone responsible for IT, security or both without having a dedicated cybersecurity department.
The important thing is knowing what needs attention, who is responsible for it, and where you need outside help.
That’s exactly where practical managed security or cybersecurity consulting can help.
2. DOES MANAGED SECURITY MEAN TANOSEC TAKES OVER OUR IT?
No.
Cybersecurity and general IT support overlap, but they’re not the same thing.
Managed Security is about helping you improve and maintain security visibility and controls.
Your existing IT provider can continue doing what they do.
We’re quite happy working alongside them.
5. REPORTS AND RESULTS
1. WILL WE GET A REPORT FULL OF TECHNICAL JARGON?
Hopefully not.
There will always be technical detail where it matters, especially for the people fixing the problem.
But you should also be able to understand:
+ what we found
+ why it matters
+ what needs attention first
+ what can wait
+ what you can do about it
A report shouldn’t leave you with more questions than you started with.
2. WHAT HAPPENS IF YOU FIND SOMETHING SERIOUS?
We’ll explain what we found, why it matters and what we recommend doing next.
We don’t manufacture panic. If something deserves urgent attention, we’ll say so. If something is low risk, we’ll say that too.
3. DO YOU FIX THE PROBLEMS YOU FIND?
Sometimes we can help directly. Sometimes your internal IT team or IT provider is better placed to make the change. And sometimes a particular issue needs a specialist.
We’ll tell you which is which.
Finding the problem is only useful if you know what to do next.
WORKING WITH TANOSEC
1. DO YOU ONLY WORK WITH BUSINESSES IN BLOEMFONTEIN?
No.
We’re based in Bloemfontein, many cybersecurity services can be delivered remotely.
Where on-site work is required, we’ll discuss the practicalities with you.
2. DO I NEED TO UNDERSTAND CYBERSECURITY BEFORE SPEAKING TO YOU?
Absolutely not.
That would rather defeat the point.
Ask questions. Ask basic questions. Ask technical questions. Tell us you have no idea where to start.
There are no stupid questions here.
3. WHAT IF TANOSEC ISN'T THE RIGHT COMPANY FOR WHAT WE NEED?
We’ll tell you.
Cybersecurity is a huge field and no company is genuinely the best fit for everything.
If something needs expertise outside the areas where we can properly help, we’d rather point you in the right direction than pretend otherwise.
Not sure where to start? +
STILL NOT SURE?
That’s what conversations are for.
Tell us what you’re trying to understand and we’ll help you figure out the next step.