Cybersecurity services
Practical cybersecurity: assessments, endpoint protection, email security, training, incident readiness and 24/7 monitoring for managed-service clients.
You cannot fix everything at once, and you should not have to guess what matters most. A Promatics security assessment reviews how your organisation is actually set up, ranks the risks by likelihood and impact, and gives you a remediation plan you can act on.
A security assessment is a structured review of how well your organisation is protected against the attacks that most often cause harm: stolen passwords, phishing, ransomware, unpatched systems and misconfigured cloud services. It ends with a ranked list of risks and a practical plan, not a pile of scanner output.
We measure what we find against recognised baselines, such as the CIS Critical Security Controls and the NIST Cybersecurity Framework, and take account of current advisories from ngCERT. Where you have a specific requirement, such as the Central Bank of Nigeria's cybersecurity framework for banks and payment service providers, the security duties in the Nigeria Data Protection Act 2023 or a client's security questionnaire, we map the findings to it.
Three rows from an invented risk register, showing the format we use:
| Finding | Likelihood | Impact | Recommended fix | Effort |
|---|---|---|---|---|
| Two administrator accounts have no MFA | High | High | Enforce MFA and move admins to separate accounts | Low |
| Backups stored on a share reachable by all staff | Medium | High | Isolate backups and test a restore | Medium |
| No DMARC record on the main email domain | High | Medium | Publish DMARC in monitoring mode, then enforce | Low |
Reviewing security means handling sensitive information. We use read-only access wherever possible, through named accounts that are removed at the end. Scans run only within written authorisation and agreed time windows. Findings are shared only with the people you name, and assessment data is deleted at the end of the engagement as agreed.
You can fix the findings with your own team, with another provider, or with us. Promatics can deliver the remediation as a project, or fold it into managed IT services with ongoing security. Common next steps include EDR deployment, email security and awareness training.
The exact list is agreed in writing for each project. These are the usual deliverables and the usual boundaries.
Most delays in this kind of work come from access and decisions, not from the technical build. Knowing these early keeps the project predictable.
Each stage ends with something you can review before the next one starts.
Agree the systems, sites and questions in scope, and the rules and time windows for any scanning.
Output: Signed scope and scanning authorisation.
Review configurations, run approved scans, and hold short interviews with the people who run your systems.
Output: Evidence and raw findings.
Compare what we found with a recognised baseline and rank each finding by likelihood and impact on your organisation.
Output: Risk register.
Walk leadership and IT through the findings, the quick wins and the longer-term roadmap.
Output: Executive summary, technical report and roadmap.
After an agreed period, check the fixes that were made and update the register.
Output: Retest note and updated risk register.
We do not publish package prices. Each estimate is based on an agreed scope, in naira, with taxes shown separately. These are the things that move the number most:
A scan finds known technical weaknesses on the systems it can reach. An assessment also looks at how accounts, email, backups and processes are set up, and explains which risks matter for your organisation. Scanning is one input, not the whole picture.
Very little. Most of the work is configuration review and short interviews. Any scanning is authorised in writing and scheduled in agreed windows.
Yes. You receive an executive summary suitable for sharing and a detailed technical report for your IT team. You decide who sees what.
No. The assessment shows how well your controls reduce risk and where the gaps are. Whether you comply with the Nigeria Data Protection Act or sector rules from regulators such as the CBN is a legal question for your counsel, and certification comes from an independent body. See privacy and compliance readiness.
Typically once a year, and after major changes such as a merger, a move to the cloud or a significant incident. Managed-service clients receive ongoing reviews under their agreement.
Practical cybersecurity: assessments, endpoint protection, email security, training, incident readiness and 24/7 monitoring for managed-service clients.
Get your privacy and security practices ready for regulators, clients, auditors and insurers, with gaps found and fixed before someone asks.
Four practical lessons from large data breaches, what they mean for your organisation, and a checklist based on NDPC guidance and international good practice.
Tell us about your organisation and what prompted the question. We will reply to arrange a scoping conversation.