A systematic approach delivers results. Here is ours.
Four steps, the same every time, so you always know where you are, what is coming, and what it costs. No stage begins before you have approved what came out of the one before it.
Assessment and discovery.
We start with where you are. What systems run your business today? Where are the gaps? Which regulations apply to you in each market you operate in? We look at your infrastructure, your controls, and your obligations together, because a finding only matters once you know what it puts at risk.
A documented picture of your current posture, your compliance exposure, and a prioritised list of what needs attention first.
Strategy and roadmap.
We design a plan that balances security, usability, and cost against what we found. You get clear milestones, realistic timelines, and transparent pricing, whether you need immediate remediation or a two-year transformation programme. Where we think you should spend less than you expected, we will say so — a roadmap that recommends everything is a sales document, not a plan.
An approved roadmap with costs, sequencing, and named owners on both sides.
Implementation and protection.
This is where the roadmap becomes working controls. We deploy in agreed waves, lowest risk first, each with a defined change window, a tested rollback, and an acceptance test you sign off before we move on. Nothing reaches production without a way back.
- 01Controls deployed and configured against the design agreed in step 2, tuned to your environment rather than left on defaults.
- 02Integration with what you already own. If a tool you have licensed does the job, we configure it properly instead of selling you another one.
- 03Documentation produced as we go: configuration baselines, run books, and evidence mapped to the frameworks you are certifying against. Compliance evidence is a by-product of the work, not a project afterwards.
- 04Knowledge transfer to your team at each wave, so operating the control does not depend on us being available.
- 05Validation. We test that each control does what it was deployed to do, and report the result, including where it did not.
Controls live and validated, documentation in your hands, and your team trained to operate them.
Monitoring and support.
Threats change and so does your business, so the work does not stop at go-live. You get 24/7 monitoring, regular vulnerability assessment, and continuous tuning as your environment evolves. Your support team works in your time zone and answers in English, French, or Arabic.
Monthly reporting, a quarterly review, and a security posture that is measured rather than assumed.
Straight answers, before you ask.
How quickly can you respond to a security incident?
Our security operations centre monitors 24/7. Clients on a managed agreement get contractual response times, stated in the agreement and reported against every month. If you are not a client, we offer incident response retainers with guaranteed response, and we will still take your call during an active incident. Every minute counts, so we would rather help first and arrange the paperwork second.
How is nexaya different from international cybersecurity firms?
Two things. First, we know the rules where you operate — Loi 09-08 and the CNDP, Loi 05-20 and the DGSSI, the Nigeria Data Protection Act, Egypt's Law 151, and Ivory Coast's Loi 2013-450, run alongside ISO 27001 and GDPR from a single control set. Second, we are here. Same time zone, same languages, on site when remote is not enough.
We already have an IT team. Can you work with them?
Yes, and most of our clients are in exactly that position. Teams bring us in for the specialisms they cannot justify hiring full time: penetration testers, SOC analysts, cloud architects, and compliance specialists. Your team keeps ownership. We add depth where it is needed and hand the knowledge over as we go.
Is our business too small for this?
Our Core package exists for organisations taking security seriously for the first time. Start there and move up as you grow. If a smaller scope would serve you better, we will tell you at the scoping call rather than after you have signed.
Do you support businesses across all African countries?
We have people in Morocco, Nigeria, Ivory Coast, and Egypt, plus Frankfurt, and we work with partners in 15+ further African markets. Where we have no local presence, we support you remotely and coordinate local requirements through those partners. We will tell you plainly which of the two applies to your market.
Can you help us meet both African and international requirements?
That is most of what our compliance practice does. Clients operating across several African markets and serving international customers need local regulations and international certifications satisfied at once. We map both onto one control set so you build the evidence once.
How do you charge?
Three ways, depending on the work. Fixed price for defined engagements such as a penetration test or a gap assessment, so you know the cost before you start. Monthly retainer for managed services and virtual CISO. Time and materials only where scope genuinely cannot be fixed in advance, and we will say so up front rather than discover it later.
What happens to our data during an engagement?
It is covered by a mutual non-disclosure agreement signed before work begins. Test data and findings are held under our own ISO 27001 controls, kept in the jurisdiction we agree with you, and destroyed on the schedule set out in the agreement. You get a certificate of destruction.
See how step 1 works on your environment.
Book the free assessment — the same team you'd be working with either way.
100+ businesses protected across the continent · reply within one business day