Skip to main content

Protection & Compliance for SMBs

Enterprise-grade protection, at small-business economics

SMBsecure™ is a fully managed security and compliance service: endpoint protection, email security, dark web monitoring and the compliance evidence POPIA and the FSCA Joint Standard ask for — in one SKU, one price and one onboarding flow, on a single dashboard.

Already using SMBsecure? Sign in to your portal

Watch the demo

Cyber Security for Everyone

A walkthrough of SMBsecure — enterprise-grade protection packaged so a small business can actually buy, deploy, and live with it.

Watch on YouTube

What SMBsecure covers

Four areas, one service. Each is included in the base tier unless it says add-on.

Endpoint protection

Behavioural detection on every device, not signature-only antivirus — and the option of someone watching it at 3am.

  • EDR + Next-Gen Antivirus standard in the base tier — no extra SKU
  • MXDR SOC add-on: a managed 24/7 SOC whose analysts triage and contain, closing the after-hours gap
  • Managed encryption for PC, Mac and mobile, with remote lock, kill and locate
  • Unlimited Secure USB enforcement
  • RiskResponder® Computer Logon MFA for workstation and Windows Server sign-in
  • SASE add-on: identity-aware access and web filtering with no branch hardware

Email security

The channel most small-business breaches arrive through — covered without touching your mail flow.

  • Classic Outlook PDF email encryption with Check4Phish™ — a human-layer check catching what AI filters miss
  • SendGuard Lite recipient review before send, stopping misdirected email before it leaves
  • Managed DMARC and MTA-STS on one domain with unlimited sub-domains, with 1-year records retention
  • No MX record changes and no gateway migration — deployment takes minutes

Dark web monitoring

Credentials leak long before they are used. Knowing first is the whole advantage.

  • Dark-web and data-breach monitoring across company domains
  • Personal Digital Identity Monitoring for employees
  • Risk discovery and vulnerability assessment with PII scanning and CVE reporting
  • Unlimited external network scans

Regulatory compliance

POPIA and the FSCA Joint Standard ask for evidence, not intentions. This produces the evidence as a by-product.

  • ComplianceEZ® framework mapping: 9/10 FSCA Joint Standard domains, 10/10 ISO 27001 Annex A groups, 5/6 NIST CSF functions with MXDR SOC in place
  • Company Policy Training with a bespoke Training Evidence Report that keeps customers audit-ready
  • Everything in one centralised dashboard — you provide the onsite, SMBsecure provides the oversight

How it is sold

One SKU, one price, one onboarding flow — in two sizes. Pricing is quoted per business through a CRS partner.

ComplianceSuite

The full base tier for an established small business: all five pillars, one SKU, one onboarding flow.

ComplianceSuite MICRO

The same service sized for a smaller footprint, for teams that would otherwise run no managed security at all.

Cyber Warranty included

R1M data breach, R500K cyber extortion and R250K business email compromise cover, for South African customers. Cover amounts, not a price — what SMBsecure itself costs is quoted per business.

Who it is for

South African SMBs needing POPIA compliance with minimal IT overhead
FSPs subject to FSCA Joint Standard JS01 and JS02 requirements
SMBs with no internal security team and no 24/7 monitoring — the after-hours gap MXDR SOC closes
Hybrid and remote-workforce SMBs moving from perimeter security to identity-based access (SASE)
Legal and medical practices requiring sector-specific compliance documentation, including HPCSA
Organisations still running signature-only AV with no EDR, encryption or compliance evidence
MSSPs building a recurring managed security revenue stream for SMB clients on one SKU
Any South African business wanting cyber warranty coverage alongside compliance

Free External Assessment

Submit your organisation's details for a free external assessment and see where SMBsecure closes your POPIA and FSCA compliance gaps.

Frequently asked questions

Does SMBsecure require MX record changes or complex email infrastructure changes?

No. SMBsecure's PDF email encryption works via an Outlook plugin — no MX record changes, no email gateway migration, and no disruption to existing mail flow. Deployment is designed to take minutes, making it suitable for SMBs without dedicated IT staff or the ability to absorb infrastructure downtime.

What does the SMBsecure Cyber Warranty cover?

The Cyber Warranty provides R1,000,000 in data breach cover, R500,000 for cyber extortion events, and R250,000 for Business Email Compromise (BEC) — covering the most common threats facing South African SMBs. The warranty is included as part of the SMBsecure managed service, not sold separately, giving partners a compelling differentiator in every proposal.

Is SMBsecure suitable for organisations subject to the FSCA Joint Standard?

Yes. SMBsecure includes dedicated compliance suites for FSPs, with POPIA compliance documentation and FSCA Joint Standard JS01 and JS02 readiness evidence built into the service. It is designed specifically to help South African financial advice firms and FSPs meet their regulatory obligations with minimal IT infrastructure overhead.

What phishing protection and email security does SMBsecure include?

SMBsecure includes managed DMARC and MTA-STS email domain protection (preventing spoofing and impersonation of your domain), misdirected email protection (recipient and attachment confirmation before send), monthly phishing simulation exercises, and self-paced cyber awareness training modules. Together these address both inbound phishing threats and outbound data leak risk.

Can SMBsecure be resold by an MSP on behalf of multiple clients?

Yes. SMBsecure includes a 90-day ASP (Authorized Service Provider) success plan with sales playbooks and prospecting templates designed specifically for MSP and MSSP partners. CRS provides the onboarding, enablement materials, and ongoing support to help partners bring SMBsecure to market efficiently and begin generating recurring revenue quickly. New partners typically start with the Internal ASP StarterPack, deploying SMBsecure on their own business first — it proves they practise what they recommend, and it satisfies supply-chain security mandates their customers are increasingly asked about.

Does SMBsecure include EDR and antivirus?

Yes. Following the NEXT LAYER release, behavioural EDR with Next-Gen Antivirus ships standard in the SMBsecure base tier — no upgrade and no separate SKU. Behavioural EDR catches the attacks signature-only antivirus misses, while NGAV runs alongside it for baseline malware coverage on every endpoint. This also makes SMBsecure a replacement for a traditional AV product rather than a layer bought on top of one.

What is MXDR SOC Services, and how is it different from EDR?

EDR is the detection layer and is now standard in the base tier. MXDR SOC Services is the optional managed layer on top of it: a 24/7 security operations centre whose analysts triage the alerts that EDR generates and take containment action on the customer's behalf. The distinction matters because detection alone does not stop a breach — most SMBs have no one watching overnight, so an alert raised at 2am goes unread until morning. MXDR closes that gap, and is sold and supported through CRS as a single line item.

What is the SASE add-on and does it need another agent?

SASE provides secure access that follows the user rather than the network they happen to be on — cloud-delivered secure connectivity and firewalling with no branch hardware, identity-aware access decisions based on the user and device, and web filtering that blocks malicious destinations before a connection is made. It is an add-on to the same Todyl foundation that already powers EDR, so there is no new agent to deploy and no additional vendor relationship for the partner to manage.

Which compliance frameworks does SMBsecure map to, and how completely?

Per ComplianceEZ®'s published control mapping: 9 of 10 FSCA Cyber Joint Standard JS1 and JS2 domains are fully covered with MXDR SOC in place (8 of 10 on the base bundle alone), with formal penetration testing the remaining gap as a separate engagement; 10 of 10 ISO/IEC 27001 Annex A requirement groups with MXDR SOC in place (7 of 10 base alone); and 5 of 6 NIST CSF functions — Govern, Identify, Protect, Detect and Respond. Overall, ComplianceEZ® maps 50+ security controls to more than 800 software control requirements across NIST, CIS and ISO 27001. These are approved regulatory claims sourced from the published coverage sheets, with full detail available on request.

Does SMBsecure include backup or disaster recovery?

No, and we are deliberately upfront about it. Backup and restore are not part of the bundle, which is why the NIST CSF Recover function is the one function that stays partial in our published coverage mapping rather than being claimed as complete. SMBsecure prevents and contains incidents — encryption, MFA, EDR, awareness training and DMARC — and for South African customers the Cyber Warranty responds financially. Customers who need recoverability should treat that as a separate product conversation.

What protection does SMBsecure provide for the human layer?

Most breaches still start with a person rather than a firewall, so end-user protection has been significantly expanded. Alongside managed awareness training and phishing simulations, SMBsecure now includes Company Policy Training so employees are trained directly on their own organisation's policy, Personal Digital Identity Monitoring because a breach of an employee's personal data can be used to scam the business, its clients or its suppliers, and a bespoke Training Evidence Report designed to satisfy auditors. Mobile and BYOD devices are covered under the same protection and policy set.

Already using SMBsecure?

Sign in to the SMBsecure Portal for your devices, encryption, risk reports and compliance posture. No password — we email you a secure link.

Sign in to SMBsecure

Request a Demo of SMBsecure

Tell us what you need and when works for you — a member of the CRS team will confirm your session directly.

What are you looking for?

Your details

Which solution(s)?

SMBsecure

When works for you?