Cybersecurity Incidents Do Not Begin Only with Advanced Hackers
A cybersecurity incident may begin with something simple:
- An employee opens a fraudulent email attachment
- A password is reused across several accounts
- An administrator account has excessive privileges
- A former employee still has access
- A laptop is lost without adequate protection
- An application is not updated
- A supplier account is compromised
- A confidential document is shared incorrectly
- A payment-change request is accepted without verification
- An incident occurs, but nobody knows who should respond
Technology is important, but it is only one part of cybersecurity.
An organisation also needs clear responsibilities, approved policies, employee awareness, secure configurations, monitoring, escalation procedures and a practical recovery plan.
NIST describes its Cybersecurity Framework 2.0 as guidance that organisations of any size, sector or level of maturity can use to understand, assess, prioritise and communicate cybersecurity risk.
Junubia Host helps organisations in Tanzania assess cybersecurity requirements, identify weaknesses, select appropriate technologies and develop a structured improvement plan. Cybersecurity forms part of Junubia Host’s wider ICT and digital-transformation portfolio for businesses, government institutions, financial organisations, NGOs and growing enterprises.
What Is a Cybersecurity Readiness Assessment?
A cybersecurity readiness assessment is a structured review of how well an organisation can prevent, detect, manage and recover from security incidents.
It examines more than the equipment installed in the server room.
The assessment may review:
- Cybersecurity governance
- Users and administrator accounts
- Devices and endpoints
- Email and collaboration systems
- Network-security controls
- Business applications
- Cloud environments
- Data access and sharing
- Software updates
- Employee awareness
- Security monitoring
- Incident-response procedures
- Recovery responsibilities
- Supplier and third-party access
The objective is to understand the organisation’s current security position, identify priority gaps and prepare a realistic improvement plan.
1. Govern: Define Responsibility and Direction
Cybersecurity should have clear organisational ownership.
Management should understand:
- Which information and systems are most important
- Who approves security policies
- Who manages user access
- Who reviews security alerts
- Who can make decisions during an incident
- Which risks the organisation can accept
- Which legal or contractual requirements apply
- How suppliers and technology partners are controlled
The Govern function was added as a central element of NIST CSF 2.0. It connects cybersecurity with enterprise risk management, leadership priorities, policies, roles and supply-chain responsibilities.
Without governance, security tools may be purchased but not configured, monitored or maintained consistently.
Questions to ask
- Is one person accountable for cybersecurity?
- Are administrator responsibilities documented?
- Does management receive security reports?
- Are technology suppliers reviewed?
- Are important policies approved and communicated?
- Are employees required to report suspicious activity?
2. Identify: Know What You Must Protect
An organisation cannot protect systems and information it does not know it has.
The identification process should review:
- Employees and contractors
- User accounts
- Administrator accounts
- Laptops and desktops
- Servers
- Mobile devices
- Network equipment
- Business applications
- Cloud subscriptions
- Email accounts
- Shared folders
- Sensitive information
- External suppliers with access
This stage should also identify the systems that would cause the greatest operational damage if they became unavailable.
Examples may include:
- Financial systems
- Customer databases
- Human-resources systems
- Procurement platforms
- Payment systems
- Government-service applications
- Operational databases
- Management reporting systems
The Identify function in NIST CSF supports understanding assets, business context, vulnerabilities and cybersecurity risks before controls are selected.
3. Protect: Reduce the Likelihood and Impact of an Incident
Protection involves technical controls, administrative rules and employee behaviour.
A security improvement programme may include:
Identity and access controls
- Individual user accounts
- Multifactor authentication
- Strong administrator protection
- Role-based access
- Regular access reviews
- Immediate removal of former employees
- Separation of administrator and daily-use accounts
Device protection
- Approved operating systems
- Endpoint-security software
- Device encryption
- Automatic security updates
- Restricted administrator rights
- Approved application installation
- Mobile-device controls where required
Email and collaboration security
- Phishing protection
- Malware filtering
- Safe document-sharing rules
- External-sender identification
- Verification of payment changes
- Controlled guest access
- Employee awareness
Network protection
- Secure firewalls
- Network segmentation
- Controlled wireless access
- Secure remote connectivity
- Updated routers and switches
- Monitoring of unusual activity
Protection must be based on the organisation’s real risks, users, devices and operational environment.
4. Detect: Recognise Suspicious Activity Early
Prevention is important, but no organisation should assume that every incident will be stopped.
The organisation must also be able to recognise:
- Repeated failed login attempts
- Unusual administrator activity
- Sign-ins from unexpected locations
- Malware detections
- Changes to critical files
- Suspicious email forwarding
- New unauthorised applications
- Unusual data transfers
- Security systems that stop reporting
- Unexpected network activity
TZ-CERT regularly publishes cybersecurity advisories and honeypot monitoring reports, reflecting an environment in which organisations need continuous awareness and detection rather than passive security controls.
Detection responsibilities should be clear. Alerts provide limited value when nobody reviews or escalates them.
Questions to ask
- Which security alerts are currently generated?
- Who receives them?
- How quickly are they reviewed?
- Which events require escalation?
- Are logs retained?
- Can the organisation reconstruct what happened after an incident?
5. Respond: Know What to Do During an Incident
During a security incident, confusion can increase damage.
Employees and management should know:
- Who must be contacted
- Who has authority to isolate a device or account
- How affected users will be informed
- How evidence will be preserved
- When management must be notified
- When external specialists are required
- Whether regulators, customers or partners must be informed
- How business operations will continue
A basic incident-response process may include:
- Receive and confirm the report
- Determine affected users and systems
- Contain the immediate threat
- Preserve logs and evidence
- Remove malicious access
- Restore services safely
- Communicate with authorised stakeholders
- Document lessons and corrective actions
NIST CSF 2.0 connects the Respond function with incident management, communication, analysis, mitigation and improvement.
6. Recover: Restore Operations and Improve
Recovery is not limited to restoring data.
The organisation must also consider:
- Which service must return first
- Who approves restoration
- Whether restored systems are safe
- How employees will work during disruption
- How customers and partners will be updated
- What caused the incident
- Which controls must change
- How management will review the event
A recovery plan should define priorities for critical systems and business services.
The Recover function in the NIST framework focuses on restoring capabilities, communicating recovery activities and improving resilience following an incident.
Common Security Gaps Found in Organisations
A readiness review may identify issues such as:
- No complete device or account inventory
- Employees sharing passwords
- Multifactor authentication not enforced
- Too many administrators
- Former employees retaining access
- Outdated software
- Uncontrolled personal devices
- Weak email-security practices
- Sensitive files shared publicly
- No regular access review
- Security alerts not monitored
- No written incident-response procedure
- No employee-awareness programme
- Suppliers retaining unnecessary access
- Management receiving no cybersecurity reporting
Not every gap requires an expensive solution.
Some risks can be reduced through improved configuration, clearer responsibility, stronger processes and employee guidance.
Employee Awareness Is a Security Control
Employees should be able to recognise and report:
- Suspicious login pages
- Unexpected attachments
- Fake payment instructions
- Requests to reveal passwords or verification codes
- Unusual messages from executives
- Fraudulent supplier-bank changes
- Unexpected software-installation requests
- Suspicious links
- Lost devices
- Accidental information sharing
TZ-CERT advises users to apply stronger password practices, including suitable length, mixed character types and avoiding password reuse for sensitive services.
Awareness training should be practical and connected to the employee’s daily responsibilities.
A finance employee may need additional guidance on payment-change fraud, while an administrator may need training on privileged-account protection.
Cybersecurity for Microsoft 365 Environments
Organisations using Microsoft 365 should review areas including:
- Administrator accounts
- Multifactor authentication
- User and licence management
- Email-security policies
- External sharing
- Guest accounts
- Mailbox forwarding
- Employee onboarding and offboarding
- Device access
- Suspicious sign-in alerts
- Teams and SharePoint permissions
Junubia Host has previously published a practical Microsoft 365 security checklist for SMEs covering measures such as multifactor authentication, administrator governance, employee awareness and safer collaboration.
The exact controls available depend on the organisation’s Microsoft 365 licences and configuration.
Cybersecurity for Networks and Infrastructure
Business networks should be reviewed for:
- Firewall configuration
- Internet-facing services
- Router and switch updates
- Wireless security
- Remote access
- Branch connectivity
- Network segmentation
- Administrator access
- Monitoring
- Unsupported equipment
Junubia Host’s Cisco portfolio includes enterprise networking and security technologies for secure, scalable organisational infrastructure.
A security assessment should identify the technology already installed before recommending replacements or additional products.
Junubia Host Cybersecurity Readiness Process
Step 1: Initial consultation
We discuss the organisation’s operations, users, systems, concerns and security priorities.
Step 2: Current-environment review
We review agreed areas such as accounts, devices, email, applications, networks, cloud environments and administrative processes.
Step 3: Gap identification
We identify weaknesses, unclear responsibilities and security controls that require attention.
Step 4: Risk prioritisation
Findings are organised according to business importance, likelihood, potential impact and urgency.
Step 5: Improvement roadmap
We prepare recommended actions covering immediate fixes, short-term improvements and longer-term requirements.
Step 6: Implementation support
Junubia Host can support agreed configuration, product sourcing, deployment, security-awareness activities and technical coordination.
Step 7: Review
Cybersecurity should be reviewed periodically as users, systems, threats and organisational responsibilities change.
Organisations That Can Benefit
A cybersecurity readiness assessment can support:
- Banks and financial institutions
- Government institutions
- NGOs
- Schools and universities
- Healthcare providers
- Telecom companies
- Law firms
- Hotels
- Construction companies
- Engineering organisations
- Energy companies
- Media organisations
- SMEs
- Professional-service firms
- Growing digital businesses
The scope should be adapted to each organisation’s size, systems, information, risk level and regulatory responsibilities.
Conclusion
Cybersecurity readiness cannot be measured only by asking whether the organisation has antivirus software or a firewall.
A prepared organisation understands its risks, protects important systems, monitors suspicious activity, responds through a defined process and restores operations safely.
Junubia Host helps Tanzanian organisations examine cybersecurity across governance, users, devices, applications, information, networks and incident-response processes.


