Resilience Framework
Cyber resilience in South Africa starts with a framework
A practical five-pillar model that helps MSPs build, prove and scale cyber resilience — connecting prevention, detection, recovery, operational stability and accountability into a single, measurable approach.
The framework helps organisations reduce exposure, improve visibility, respond effectively and strengthen recovery readiness. It is designed to help MSPs connect prevention, detection and response, recoverability and operational stability — with ownership holding the whole model together.
Ownership connects and surrounds every pillar
OwnershipText alternative: Prevention, Detection and Response, Recoverability and Operational Stability are the four operating pillars. Ownership surrounds and connects all four, defining responsibility, evidence, escalation, governance and accountability across the model.
Prevention
Reducing the likelihood and impact of disruption through layered protection, hardening and good operational hygiene.
- Why it matters
- Most incidents are avoidable or containable when exposure is reduced before an attacker or failure can exploit it.
- MSP responsibility
- Configure and maintain protective controls, patching and policy standards across the customers you manage.
- Soteria enablement role
- Provides the platform capabilities, onboarding and standards that help partners apply prevention consistently.
- Example evidence
- Configuration baselines, patch status reports and policy standards recorded per customer.
Question to ask: Which exposures have we reduced for this customer, and how do we know?
Detection and Response
Identifying, investigating, containing and responding to abnormal activity before it becomes a material incident.
- Why it matters
- Not everything can be prevented. Fast, informed response limits the impact of what gets through.
- MSP responsibility
- Monitor alerts, triage events and act on escalations within the agreed service model.
- Soteria enablement role
- Enables EDR, XDR and MDR capabilities with investigation and escalation pathways for partners.
- Example evidence
- Alert-handling records, investigation notes and escalation timelines within the agreed service model.
Question to ask: How quickly can we detect, investigate and contain abnormal activity?
Recoverability
Protecting critical workloads and restoring them against defined recovery objectives (RTO and RPO).
- Why it matters
- Resilience is demonstrated at recovery. Tested restores against defined objectives are what keep businesses running.
- MSP responsibility
- Define recovery objectives with customers, protect the right workloads and test restores.
- Soteria enablement role
- Provides backup, disaster-recovery and restore-testing capabilities supported by local infrastructure.
- Example evidence
- Restore-test results validated against the documented recovery objective and date.
Question to ask: Have we tested restores against defined recovery objectives, and when?
Operational Stability
Maintaining reliable infrastructure, monitoring, support and repeatable service delivery day to day.
- Why it matters
- Stable operations are the foundation that prevention, detection and recovery all depend on.
- MSP responsibility
- Run consistent monitoring, management and service processes across your customer base.
- Soteria enablement role
- Provides multi-tenant management, reporting and local support that keep delivery predictable.
- Example evidence
- Monitoring dashboards, service reports and change records across the customer base.
Question to ask: Is service delivery consistent, monitored and repeatable day to day?
Ownership
Defining responsibility, evidence, escalation, governance and accountability across the whole model.
- Why it matters
- Resilience fails at the seams. Clear ownership makes responsibilities visible and followed through.
- MSP responsibility
- Own the customer relationship, set expectations and coordinate escalation and governance.
- Soteria enablement role
- Provides responsibility mapping, escalation pathways and service reviews that make accountability explicit.
- Example evidence
- Responsibility matrices, escalation pathways and completed service reviews.
Question to ask: Is it clear who is responsible for each part of the model, with evidence to show it?
From framework to action
Solutions that deliver on each pillar
The framework defines what matters. These solutions provide the technology to deliver on it.
Cloud Backup
Server, workstation and SaaS backup stored locally in South Africa.
Learn more RecoverabilityMicrosoft 365 Backup
Dedicated cloud-to-cloud backup for Exchange, OneDrive, SharePoint and Teams.
Learn more RecoverabilityDisaster Recovery
Rapid failover with defined RTO and RPO targets.
Learn more All pillarsPlatform
The unified platform that connects prevention, detection, recovery and operations.
Learn moreQuarterly MSP Resilience Review
A structured review aligned to the five pillars. Speak to us to access it and discuss how it applies to the customers you manage.