Cybersecurity Services Business Plan South Africa

SecurePulse Cybersecurity (Pty) Ltd is a Johannesburg-based cybersecurity services company providing practical, outcomes-driven protection for South African SMEs and mid-sized organizations that lack in-house security teams. The business focuses on enabling clients to prevent breaches, reduce downtime, and meet compliance expectations such as POPIA through targeted security assessments, remediation delivery, managed detection and monitoring, and security awareness programmes.

This plan presents SecurePulse’s market opportunity in Gauteng, its clear differentiation against report-heavy consultancies and tool-centric managed security providers, and an execution model designed to scale recurring revenue. It also provides a five-year financial projection using the company’s authoritative model, including projected profit and loss, projected cash flow, break-even analysis, and funding use.

SecurePulse’s strategy is built around repeatable service packages—each aligned to measurable client outcomes—plus a sales engine powered by partner referrals, direct outreach to IT and finance decision-makers, and credibility through short, anonymised results. Financially, the model shows the company is profitable within the first year, supported by recurring managed monitoring and security awareness subscriptions alongside once-off assessment and remediation project revenue.

Executive Summary

SecurePulse Cybersecurity (Pty) Ltd delivers cybersecurity services to South African SMEs and mid-sized organizations in a way that is both fast and operationally practical. The core problem in the market is not simply a lack of security tools; it is a lack of security capability—people, process, and governance—to prevent incidents, respond effectively when threats emerge, and align with regulatory and vendor expectations such as POPIA. Many South African SMEs do not maintain dedicated security teams. As a result, they often delay action until a crisis occurs, which can lead to downtime, fraud exposure, reputational damage, and direct financial loss.

SecurePulse addresses this gap by bundling cybersecurity expertise into client-friendly service offerings that drive immediate security clarity and measurable improvement. The company’s primary services are: Security Readiness Assessment (once-off), POPIA Cyber & Data Protection Remediation (project), Managed Security Monitoring (monthly subscription), and Security Awareness Training (monthly/quarterly basic). Each service is designed to follow a predictable delivery milestone so that clients can understand what will be delivered, when it will be delivered, and how it improves their security posture.

SecurePulse is legally registered as a Pty Ltd, trading in ZAR (R), and located in Midrand, Johannesburg, Gauteng, with service delivery including remote support across South Africa. The business is owned and led by Tatenda Olsen, Managing Director, supported by a structured team of cybersecurity and compliance specialists. Key roles include Bongani Sithole (head of managed security), Kagiso Motsepe (senior security consultant), Khanyi Radebe (client success & compliance officer), Themba Mthembu (penetration testing specialist), Sipho Dlamini (systems engineer), Mandla Nkosi (security awareness trainer), and Nomsa Mbeki (operations and finance coordinator). This team mix ensures both technical delivery and compliance translation into operational controls.

SecurePulse differentiates itself through outcome-focused engagements rather than report-only consulting. Where some Johannesburg-based cyber consultancies produce long documentation-heavy deliverables, SecurePulse emphasizes short assessment cycles, POPIA-relevant security improvements, and subscription monitoring tied to actions, not only alerts. The company also publishes clear service milestones that guide clients through the next steps, reducing the common client experience gap where security findings do not translate into remediation or ongoing governance.

From a commercial standpoint, SecurePulse’s financial model is built to be credible for an early-stage services business: it leverages attractive gross margins across service lines, tight operating cost control, and recurring revenue from managed monitoring and security awareness training. The model projects Year 1 total revenue of R2,600,000 with Gross Profit of R1,560,000 and Net Income of R177,244. Break-even analysis in the model indicates annual break-even revenue of R2,195,333, with break-even timing within Month 1 of Year 1. Operating leverage improves across the years through scale and a major revenue step-up in Year 5.

The business requests R350,000 in total funding, comprising R150,000 equity capital and R200,000 debt principal. The funding use is directed toward office setup in Midrand, core tools and onboarding, initial marketing launch to generate traction, and a working reserve to support early operating buffers. This funding plan aligns with the operating model that produces positive net income in Year 1, reducing reliance on continuous external financing.

SecurePulse’s growth plan targets recurring revenue scale and service delivery capacity. In the next 12 months, the commercial objective is to build a base of active monitoring clients and expand project pipeline through assessment-to-remediation conversions and partner referrals. Over a five-year horizon, the company projects Year 5 revenue of R7,500,000, driven by continued subscription growth and the compounding effect of a growing installed base. The model also projects strong DSCR performance in later years due to increased operating cash generation.

In summary, SecurePulse is a practical, scalable cybersecurity services business built for the South African market. It combines clear service packaging, a targeted customer segment, measurable delivery milestones, and a financial structure designed for early profitability and sustainable recurring growth.

Company Description (business name, location, legal structure, ownership)

SecurePulse Cybersecurity (Pty) Ltd is a cybersecurity services company focused on South Africa, with its operational base in Midrand, Johannesburg, Gauteng. The company’s service delivery covers Gauteng through in-person engagements when needed and supports clients remotely across South Africa through secure sessions. This hybrid model supports cost control while still meeting client expectations for direct engagement, especially for assessments, governance workshops, and compliance alignment activities.

Business name and branding

The business trades under the name SecurePulse Cybersecurity (Pty) Ltd. The brand is positioned around the idea of “security clarity and measurable improvement,” reflecting the company’s approach to security readiness, remediation, monitoring, and awareness training. SecurePulse’s communication style is designed for executive decision-makers as well as technical managers—ensuring that reports and findings are translated into practical actions.

Location and service area

SecurePulse is located in Midrand, Johannesburg, Gauteng. Clients within Johannesburg and surrounding Gauteng regions benefit from on-site delivery for discovery, workshops, and selected remediation interventions. For clients outside Gauteng, SecurePulse delivers most activities remotely, supported by encrypted communication workflows and tool-assisted testing where appropriate. This geographic flexibility is important for scaling service revenue beyond a single metro without adding disproportionate operating cost.

Legal structure and trading currency

SecurePulse is registered as a Pty Ltd, and all figures and financial projections are expressed in ZAR (R). The choice of legal structure supports client trust—particularly for larger SME and mid-sized organizations—and provides an appropriate framework for contractual engagements, compliance-aligned delivery, and recurring subscription billing.

Ownership and leadership

SecurePulse is owned and managed by Tatenda Olsen, the Founder and Managing Director. Tatenda leads sales, client delivery standards, and compliance alignment. The leadership structure ensures that the company’s strategic positioning—fast security clarity, practical remediation, and subscription monitoring tied to actions—remains consistent across engagements.

The management and delivery team includes specialized roles across managed security operations, security consulting, compliance and client success, penetration testing, systems engineering, and security awareness training. This structure reduces delivery bottlenecks and improves quality, because the company does not rely on a single generalist function to cover all technical and governance needs.

Why the company is built this way

The market SecurePulse targets often lacks a dedicated security function. That means the business must be able to combine technical discovery with governance and compliance translation. SecurePulse therefore organizes delivery around client outcomes:

  1. Risk clarity through assessments that identify gaps relevant to real-world threats and compliance expectations.
  2. Remediation delivered as a project with structured outputs and measurable improvements.
  3. Ongoing monitoring via managed security subscriptions that maintain visibility and help prevent recurrence.
  4. Behavioral risk reduction through security awareness training that addresses phishing and social engineering exposure.

The company’s structure, with both technical and compliance capabilities, supports these outcomes and reduces the likelihood of clients treating security as a one-time checkbox exercise.

Products / Services

SecurePulse provides cybersecurity services designed specifically for South African SMEs and mid-sized companies without in-house security teams. Rather than selling “security in general,” the business offers four service lines that map directly to common client risk patterns: inadequate security governance, exposure to ransomware and phishing, insufficient controls for POPIA and related data protection requirements, and human-factor vulnerabilities.

All pricing and unit economics in this plan align with the authoritative financial model, ensuring consistent revenue forecasting and service planning.

1) Security Readiness Assessment (once-off)

What it is
The Security Readiness Assessment is a once-off engagement that evaluates a client’s current security posture, with a practical focus on how likely the organization is to face breaches and how ready it is to respond to incidents. The assessment prioritizes what matters to SMEs: key risk areas, immediate vulnerabilities, governance gaps, and remediation priorities.

Why clients buy it
Most clients do not have the internal bandwidth to interpret security risk at the level required to take action. They want quick clarity and an actionable roadmap. An assessment gives them that roadmap, and it often becomes the starting point for remediation projects and subscriptions.

Pricing (unit economics aligned to the model)

  • ZAR 18,000 per assessment.

Delivery outputs
The assessment is delivered as a structured package that typically includes:

  • A prioritized findings summary (risk-ranked)
  • A practical remediation roadmap (sequenced)
  • Compliance-relevant observations where applicable (POPIA-aligned themes)
  • Operational recommendations to reduce immediate exposure

Business impact
Because the assessment converts into other work, it is central to revenue consistency. Even when remediation projects are not immediately purchased, assessments build credibility and create a pipeline for managed monitoring and training.

2) POPIA Cyber & Data Protection Remediation (project)

What it is
This is a project-based remediation offering designed to reduce security and data protection risks in a way aligned to POPIA expectations and common data protection vendor/security requirements. The service typically focuses on tightening control effectiveness rather than only documenting policy.

Why clients buy it
SMEs and mid-sized organizations often face pressure from customers, business partners, and auditors who ask for evidence of controls. At the same time, ransomware and phishing create operational urgency. Remediation addresses both compliance and practical incident risk.

Pricing (unit economics aligned to the model)

  • ZAR 45,000 per project.

Typical remediation themes
SecurePulse’s remediation work is designed to be implementable and measurable. Common themes include:

  • Improving access controls and account security practices
  • Strengthening endpoints and core infrastructure configurations
  • Improving detection-relevant logging and visibility
  • Addressing data handling risks (where relevant to client context)
  • Supporting implementation with governance guidance so changes are not reversed

Business impact
Remediation projects contribute higher-value one-off revenue while also improving the effectiveness of ongoing monitoring subscriptions. That creates compounding value: remediation reduces risk, monitoring sustains progress, and awareness reduces the probability of social engineering success.

3) Managed Security Monitoring (monthly subscription)

What it is
Managed Security Monitoring is the recurring service line that provides ongoing visibility and operational support. The goal is to move beyond periodic assessments into continuous risk reduction.

Why clients buy it
Threats do not pause between assessments. Organizations that buy managed monitoring typically want:

  • Faster awareness of suspicious activity
  • Better operational handling of alerts
  • Security governance that supports ongoing improvement

Pricing (unit economics aligned to the model)

  • ZAR 12,000 per month per client.

What “monitoring” means in practice
Managed monitoring is delivered in an operational way. SecurePulse focuses on reducing the “alert fatigue” problem many organizations experience when they have tools but no triage or actionable governance. The managed approach includes:

  • Ongoing monitoring activities
  • Alert triage workflows
  • Incident and escalation handling processes
  • Feedback loops from findings into remediation priorities

Business impact
Recurring revenue supports sustainable growth and improves the company’s ability to hire and scale delivery capacity while maintaining stable unit economics.

4) Security Awareness Training (monthly/quarterly basic)

What it is
Security Awareness Training is a behavioural security programme designed to reduce the risk from phishing, social engineering, and unsafe user behaviour. In many SMEs, human-factor vulnerabilities are a leading contributor to successful compromises.

Why clients buy it
Clients want to reduce the probability that employees will:

  • Click phishing links
  • Share credentials through deceptive communications
  • Fall for fraudulent payment or invoice scams

Awareness is not only training content—it is also reinforcement through simulated and measurable learning outcomes.

Pricing (unit economics aligned to the model)

  • ZAR 8,500 per month per basic program delivery.

Delivery model
SecurePulse runs awareness training in formats that fit SMB realities, commonly:

  • Monthly delivery for ongoing reinforcement
  • Quarterly basic programmes where clients prefer a longer cycle

Business impact
Training contributes recurring revenue and improves client security posture in a way that complements managed monitoring. Together, these services address both technical and behavioural risk vectors.

Service portfolio synergy and upsell logic

SecurePulse’s service lines are designed to cross-sell naturally:

  • An assessment identifies gaps and often leads to remediation.
  • Remediation improves the security baseline, making ongoing monitoring more effective.
  • Awareness reduces the likelihood of successful phishing attacks, lowering incident frequency and helping monitoring outputs remain actionable rather than constantly overwhelmed.

This synergy reduces churn risk and increases lifetime value per client because the services reinforce each other’s effectiveness.

Market Analysis (target market, competition, market size)

SecurePulse operates in South Africa with a primary focus on the Gauteng region, particularly Johannesburg and Pretoria and the surrounding areas. The company’s service value proposition is built around urgent business risks—ransomware, phishing, fraud, and the compliance burden associated with POPIA—rather than generic “cybersecurity interest.”

Target market: South African SMEs and mid-sized organizations

SecurePulse’s ideal customers are SMEs and organizations with 20 to 250 staff, typically based in Johannesburg, Pretoria, and surrounding Gauteng areas, with the ability to serve remote clients across South Africa. These organizations usually share the same core conditions:

  • Limited dedicated security staffing
  • IT teams that manage networks, endpoints, and user support but do not have security-only capacity
  • Compliance awareness that may be present, but limited internal ability to translate obligations into control implementation
  • A risk profile where phishing and ransomware are realistic threats, not hypothetical concerns

The decision-makers SecurePulse targets include:

  • Business owners
  • IT managers responsible for operational resilience
  • Finance directors responsible for fraud risk, continuity, and compliance costs

For many of these decision-makers, cybersecurity is an operational and financial risk management problem. They want practical improvements, not only documentation.

Market needs and drivers in South Africa

Cybersecurity demand in South Africa is shaped by several converging forces:

  1. Increased cyber threats and ransomware activity
    Organizations with limited security maturity often become targets because compromise attempts are automated and credential theft is common.

  2. Phishing-driven fraud and business interruption
    SMEs are vulnerable to social engineering that leads to credential capture and fraudulent transactions, including payment redirection scams.

  3. Compliance obligations and procurement security requirements
    POPIA creates a regulatory framework for handling personal data. In addition, many vendor ecosystems and customer procurement processes require evidence of security controls and responsible data handling.

  4. Operational constraints and cost sensitivity
    SMEs cannot afford long engagement cycles or large internal headcount. They need packaged services that deliver measurable improvements within manageable budgets.

SecurePulse’s service portfolio maps precisely to these drivers: assessments clarify risk; remediation implements controls; managed monitoring sustains improvements; and awareness reduces the likelihood of human-factor compromise.

Serviceable market sizing for Gauteng

SecurePulse estimates roughly 15,000 potential B2B targets in Gauteng that fit the “no dedicated security team” profile, based on the number of registered SMEs and mid-sized enterprises and their likely security maturity gaps. Not all 15,000 will buy services immediately, but the serviceable market provides scale for partner-driven referrals, direct outreach, and digital marketing.

SecurePulse’s accessible serviceable starting market is a narrower subset: organizations that actively buy IT services and have budgeted IT risk activities. This market behavior supports SecurePulse’s go-to-market approach because the company sells to organizations that already invest in IT—meaning they can add cybersecurity services without needing to build internal justification from scratch.

Competition landscape

SecurePulse faces competition across three broad categories:

  1. Cybersecurity consultancies in Johannesburg
    These firms often sell engagements that result in long, report-based deliverables. While such reports may provide insights, clients frequently struggle to turn recommendations into implemented controls. The client experience gap is often not the quality of the report; it is the absence of practical remediation follow-through and sustained governance.

  2. Managed security providers (tool-centric)
    Some providers focus heavily on tool management and alerting. This can create a mismatch for SMEs: the client pays for monitoring but receives insufficient operational governance, triage, and remediation support tied to real-world actions.

  3. Smaller local IT firms that add security as a secondary service
    These organizations may deliver some security capabilities, but security expertise may be limited because security is not the primary specialization. This can result in slower delivery, less consistent service outcomes, or a focus on selling products rather than building control effectiveness.

SecurePulse’s differentiation: outcome clarity and remediation velocity

SecurePulse differentiates by delivering clear outcomes and fast remediation:

  • POPIA-relevant security improvements rather than generic security recommendations.
  • Short assessment cycles so clients receive actionable risk clarity without waiting months.
  • Subscription monitoring tied to actions rather than alerts alone.
  • Published service milestones that clarify what is delivered, what happens next, and how the client progresses.

This approach addresses the common competitive weaknesses in the local market:

  • Clients do not want documentation without implementation.
  • Clients do not want alert-heavy monitoring without triage and remediation workflows.
  • Clients do not want security delivered as an occasional side task.

Market attractiveness and risk considerations

SecurePulse’s market is attractive because:

  • Demand is driven by pressing operational and compliance risks.
  • Recurring services align with how clients manage risk over time.
  • The combination of technical services and awareness training addresses multiple compromise pathways.

However, risks exist:

  • Budget constraints in the SME sector can delay purchases.
  • Competitive pressures may lead to price undercutting.
  • Delivery quality is critical: a poor remediation outcome or delayed response can reduce renewals for subscriptions.

SecurePulse mitigates these risks by maintaining a structured service delivery model, ensuring a team with technical and compliance expertise, and focusing on measurable outcomes.

Customer acquisition channels and market access

SecurePulse’s approach to market access uses:

  • Partnerships with IT service providers, managed service providers, and accounting firms that see SMEs before security budget decisions are made.
  • Direct outreach to decision-makers in IT and finance.
  • Targeted digital marketing including a website with service pages and LinkedIn campaigns aimed at IT managers, operations heads, and finance directors.
  • Anonymised case-style results to build credibility.
  • A discounted first assessment for qualified leads to lower acquisition friction.

The combination of partner referrals and direct outreach supports consistent lead flow. Digital marketing supports broader reach in Gauteng and for remote clients who can be served with remote sessions.

Market size summary

SecurePulse’s strategic view of market size is built from a realistic starting market and a scalable serviceable pool:

  • Potential B2B targets in Gauteng: roughly 15,000 organizations fitting the no-dedicated-security-team profile.
  • Serviceable subset: organizations that actively buy IT services and budget for IT risk.

This market framework supports the revenue model’s reliance on recurring subscription growth and steady conversion from assessments to remediation and monitoring.

Marketing & Sales Plan

SecurePulse’s marketing and sales plan is designed for the realities of B2B cybersecurity buying in South Africa: decision-makers want speed, clarity, and credible assurance that improvements will be implemented—not only suggested. The plan targets IT managers, business owners, and finance directors in Johannesburg, Pretoria, and Gauteng, while enabling remote service delivery across South Africa.

Positioning and messaging strategy

SecurePulse positions itself around practical outcomes:

  • Prevent breaches
  • Reduce downtime and operational disruption
  • Meet compliance and vendor security expectations such as POPIA
  • Reduce phishing and social engineering risk through structured awareness

Messaging is structured into three layers:

  1. Executive clarity: cybersecurity outcomes tied to business continuity and financial risk.
  2. Operational relevance: what controls will be improved and how it affects daily operations.
  3. Proof of delivery: milestones and anonymised case-style results showing that recommendations turn into practical action.

This messaging addresses common objections in the market:

  • “We already have tools.”
    SecurePulse responds with governance and remediation delivery—turning tools into effective security controls.
  • “We need a report for compliance.”
    SecurePulse provides outcomes and remediation implementation aligned with POPIA-relevant requirements.
  • “Monitoring will create alert noise.”
    SecurePulse emphasizes action-oriented triage workflows and operational governance.

Customer acquisition channels

SecurePulse’s primary acquisition channels are structured to generate predictable lead volume:

1) Partnerships (primary referral engine)

SecurePulse builds referral flow with:

  • IT service providers
  • Managed service providers
  • Accounting firms

These partners often see SMBs earlier in their security journey, before a security purchase becomes urgent. They can also recommend SecurePulse as a specialized cybersecurity capability when their clients need security assessments, remediation projects, monitoring support, or awareness programmes.

Partnership activities include:

  • Co-branded educational sessions for partner clients
  • Referral agreements with clear lead qualification processes
  • Joint service bundles where appropriate (e.g., assessment recommendations followed by partner implementation support under SecurePulse guidance)

2) Direct outreach to decision-makers

SecurePulse conducts direct outreach to:

  • IT managers
  • Operations heads
  • Finance directors

Outreach uses:

  • Lead lists built from serviceable Gauteng industries and SME/mid-sized company registries
  • Persona-specific messaging (IT vs. finance)
  • Calls-to-action that emphasize quick assessment delivery and measurable next steps

Outreach goals include:

  • Booking discovery calls
  • Converting to assessment engagements
  • Offering subscriptions where existing monitoring or security tools indicate a need for governance and ongoing support

3) Digital marketing

SecurePulse maintains:

  • A website with clear service pages for Johannesburg and remote support across South Africa
  • Targeted LinkedIn campaigns aimed at decision-makers

Digital marketing supports conversion by offering credibility signals:

  • Service milestones
  • Case-style outcomes (anonymised)
  • Assessment discount for qualified leads

Sales process and conversion funnel

SecurePulse’s sales motion is structured as a clear conversion funnel:

  1. Lead qualification
    Identify whether the prospect has:

    • 20 to 250 staff
    • no dedicated security team
    • pain points related to ransomware/phishing and compliance expectations
  2. Discovery call and fit confirmation
    Confirm the business context: current security posture, typical incident risk, and whether the client needs readiness clarity, remediation, monitoring, or awareness.

  3. Assessment conversion
    For most leads, SecurePulse begins with a Security Readiness Assessment (ZAR 18,000). The assessment establishes risk priorities and creates momentum for remediation or monitoring subscriptions.

  4. Remediation and subscription upsell
    Based on assessment findings, SecurePulse offers:

    • POPIA Cyber & Data Protection Remediation (ZAR 45,000) for project delivery
    • Managed Security Monitoring (ZAR 12,000/month) for recurring governance and visibility
    • Security Awareness Training (ZAR 8,500/month) for behavioural risk reduction
  5. Long-term retention
    SecurePulse retains clients through:

    • action-oriented monitoring outputs
    • delivery consistency on training cycles
    • periodic reviews and ongoing improvements based on findings

Marketing budget alignment to the model

The financial model includes marketing and sales costs of R240,000 in Year 1, scaling with operating expenses over time (R254,400 in Year 2, R269,664 in Year 3, R285,844 in Year 4, and R302,994 in Year 5). These figures reflect the combined cost of paid marketing, content, and collateral production required for lead generation and conversion.

Pricing strategy and fairness to SMEs

SecurePulse pricing is designed to be affordable for SMEs while preserving service delivery quality. The service lines are priced as:

  • Assessments: ZAR 18,000 each
  • Remediation projects: ZAR 45,000 each
  • Managed monitoring: ZAR 12,000 per month per client
  • Awareness training: ZAR 8,500 per month (basic programme)

This structure supports a predictable engagement cycle for clients and aligns the company’s revenue forecasting with recurring and one-off revenue streams.

Sales enablement and credibility mechanisms

To increase trust and conversion:

  • SecurePulse provides clear service milestones
  • Provides anonymised case-style results
  • Uses a discounted first assessment for qualified leads (as part of the acquisition approach)

These mechanisms reduce perceived purchase risk. For many clients, the main concern is whether cybersecurity work will be actionable and delivered quickly. SecurePulse’s service milestones and follow-through reduce that uncertainty.

Metrics and targets used for performance management

SecurePulse monitors:

  • Lead-to-assessment conversion
  • Assessment-to-remediation conversion
  • Subscription growth in managed monitoring and awareness training
  • Client retention on monthly subscriptions

The company uses these metrics to refine:

  • partner referral focus
  • messaging emphasis (executive clarity vs. operational details)
  • delivery pacing and onboarding experience

Sales and marketing risks and mitigations

Potential risks include:

  • Slower conversion cycles due to procurement delays
  • Price sensitivity in certain SME segments
  • Competitive pressure from tool-only providers or report-heavy consultants

SecurePulse mitigates through:

  • clear milestones and immediate next steps
  • action-oriented deliverables
  • strong partner channels that reduce procurement friction
  • quality control in delivery to protect renewal rates

Operations Plan

SecurePulse’s operations plan describes how cybersecurity services will be delivered reliably, securely, and efficiently to South African SMEs. The operations model is designed to reduce delivery risk, maintain consistent service quality, and support the recurring revenue streams from managed monitoring and awareness training subscriptions.

Delivery philosophy: practical, repeatable, and measurable

SecurePulse delivery is outcome-driven rather than document-driven. Each service line follows a structured process:

  1. Discover and confirm scope
  2. Execute technical and governance activities
  3. Deliver results as actionable milestones
  4. Implement remediation support where contracted
  5. Maintain ongoing monitoring and behavioural risk reduction via subscriptions

This structure reduces ad hoc delivery risk and increases operational efficiency.

Service delivery workflows

A) Security Readiness Assessment workflow

A typical assessment delivery flow includes:

  1. Kickoff and scoping

    • Confirm client environment overview (systems, network, endpoints, key business applications)
    • Define assessment objectives aligned to client needs
    • Confirm delivery timeline and stakeholder availability
  2. Information gathering and analysis

    • Review security posture, existing documentation where available, and operational practices
    • Identify key weaknesses and governance gaps
  3. Risk prioritization

    • Create prioritized findings based on practical risk and likelihood of exploitation
    • Translate findings into a remediation roadmap
  4. Deliver findings and next steps

    • Provide structured outputs
    • Identify recommended remediation and monitoring opportunities
  5. Client alignment session

    • Walk client stakeholders through the roadmap
    • Align on which remediation project or subscription is appropriate

This workflow is designed to deliver fast clarity while maintaining sufficient depth to be credible.

B) POPIA Cyber & Data Protection Remediation workflow

Remediation projects are executed with a controlled implementation approach:

  1. Remediation planning

    • Convert assessment findings into a scoped implementation plan
    • Confirm what will be remediated, what will be measured, and what evidence will be provided
  2. Control implementation

    • Apply security hardening and operational control improvements
    • Prioritize changes that reduce immediate breach risk and data protection exposure
  3. Testing and validation

    • Validate implemented changes meet the intended operational outcomes
    • Confirm that remediation is effective, not only documented
  4. Hand-over and operational guidance

    • Provide documentation and guidance
    • Ensure client teams can maintain security improvements without reliance on SecurePulse alone
  5. Post-remediation review

    • Identify where managed monitoring should be added to sustain improvements
    • Recommend awareness training for behavioural risk reduction

This workflow makes remediation projects implementable and helps reduce churn risk associated with clients that fail to operationalize changes.

C) Managed Security Monitoring workflow

Managed monitoring is delivered with an ongoing operational lifecycle:

  1. Onboarding

    • Integrate monitoring approach and define alert/triage expectations
    • Confirm escalation contacts and decision-makers
  2. Ongoing monitoring and triage

    • Monitor for suspicious activity
    • Triage and categorize alerts based on actionable relevance
  3. Response and escalation

    • Escalate incidents based on severity
    • Provide guidance on remediation actions
  4. Continuous improvement

    • Use recurring findings to refine monitoring focus
    • Improve governance and operational practices over time
  5. Monthly reporting

    • Provide ongoing visibility and actions taken
    • Identify next steps to reduce future risk recurrence

D) Security Awareness Training workflow

Security awareness training is structured to create behavioural reinforcement:

  1. Programme setup

    • Confirm scope and participation model (staff groups)
    • Identify likely phishing exposure patterns
  2. Delivery of training content

    • Deliver monthly training sessions or align with quarterly schedules
  3. Reinforcement and learning reinforcement

    • Use behavioural prompts and reminders to sustain attention
  4. Measurement of progress

    • Review engagement and learning outcomes where possible
    • Adjust training content based on observed risks
  5. Operational guidance

    • Provide recommendations to complement technical controls

Compliance and security requirements for SecurePulse operations

Since SecurePulse handles sensitive client security information, internal operations must also be secure. SecurePulse uses secure communication sessions for remote work, maintains access control practices, and follows confidentiality standards aligned to client expectations. The internal operating procedures are designed to minimize risk of exposing sensitive network and security posture information.

Staffing model and capacity planning

SecurePulse’s capacity is based on a core team with specialized roles. While the financial model assumes salary and wages scale modestly over time, operations planning must ensure that workload does not exceed delivery capacity during lead-to-delivery cycles.

The team’s specialization reduces execution bottlenecks:

  • Managed security operations led by the head of managed security
  • Vulnerability management and remediation logic led by senior security consultant
  • Compliance translation handled by client success & compliance officer
  • Testing expertise handled by the penetration testing specialist
  • Systems configuration improvements supported by systems engineer
  • Awareness training delivered by the awareness trainer
  • Operations and finance coordination handled by operations and finance coordinator

Technology and tool usage

SecurePulse’s operations rely on:

  • security testing and diagnostic tooling for assessments and remediation validation
  • subscriptions and software tools for managed monitoring and reporting
  • office and communications equipment for secure client engagement

The financial model includes depreciation of R25,200 across years and operating software/tool subscriptions reflected in operating expenses categories (with Other operating costs and administration components representing broader operational tool costs and overhead).

Office operations and cost structure

SecurePulse operates from a small office in Midrand. The office cost structure includes:

  • rent and utilities (in the model, part of operating expenses)
  • marketing and sales costs for acquisition
  • salaries and wages for team coverage
  • insurance and professional risk coverage
  • travel and client site expenses reflected in other operating costs (average monthly travel and client expenses)

Operational discipline ensures consistent spending:

  • structured scheduling to reduce travel cost spikes
  • standardized onboarding for monitoring subscriptions
  • template-based reporting to maintain delivery quality without sacrificing speed

Operating risk management and quality control

Operational risks in cybersecurity services include:

  • scope creep in remediation projects
  • inconsistent delivery quality when team members are overloaded
  • client misalignment on expectations

SecurePulse mitigates these risks by:

  • clear scoping in discovery and kickoff sessions
  • milestone-based delivery outputs
  • checklists and standardized workflows for assessments, remediation, monitoring, and awareness
  • monthly operational reviews and performance tracking

Five-year operational assumptions in the model

The financial model shows total revenue is stable at R2,600,000 from Year 1 through Year 4, and increases to R7,500,000 in Year 5. Operating costs also rise gradually due to wage scaling, rent/utilities increases, and other operating cost increments. Operations planning must therefore ensure:

  • capacity is maintained for stable revenue years
  • scalability is enabled for Year 5 expansion, consistent with the model’s revenue step-up and EBITDA growth to R2,900,442

While the model suggests significant growth in Year 5, the operations plan remains consistent: delivery frameworks remain repeatable; staffing and workflows can be scaled through increased subscriptions and higher volume delivery.

Management & Organization (team names from the AI Answers)

SecurePulse’s management and organization structure is designed to match the service portfolio. Each role supports a different part of delivery: technical security, monitoring operations, penetration testing, systems hardening, compliance and client success, security awareness delivery, and operational/financial coordination.

Executive leadership

Tatenda Olsen — Founder & Managing Director

Tatenda Olsen is the Founder and Managing Director of SecurePulse Cybersecurity (Pty) Ltd. Tatenda leads:

  • sales and partner alignment
  • client delivery standards
  • compliance alignment and governance consistency

Tatenda holds a BCom in Information Systems and has 10 years of experience in IT operations, audit support, and cybersecurity programme delivery across finance and retail environments. This background supports a delivery philosophy that is both technical and commercially grounded—ensuring proposals convert into implementable outcomes.

Core delivery team

Bongani Sithole — Head of Managed Security

Bongani Sithole is responsible for managed security delivery and monitoring operations. With 8 years of experience in SOC operations and endpoint/network monitoring and incident triage, Bongani leads operational monitoring workflows to ensure alerts are triaged and handled in an action-oriented manner rather than creating noise for client teams.

Kagiso Motsepe — Senior Security Consultant

Kagiso Motsepe is responsible for consulting and remediation programme design and delivery oversight. Kagiso has 7 years delivering vulnerability management and remediation programmes and holds CCSP-level practical experience. This role ensures remediation plans are logically structured and implemented with validated outcomes.

Khanyi Radebe — Client Success & Compliance Officer

Khanyi Radebe focuses on client success coordination and compliance translation. With 6 years coordinating compliance projects and translating risk into operational controls, Khanyi ensures:

  • POPIA-relevant improvements are accurately scoped and aligned
  • client stakeholders understand deliverables and evidence expectations
  • delivery outputs support both operational and compliance needs

Themba Mthembu — Penetration Testing Specialist

Themba Mthembu provides penetration testing expertise across web and infrastructure engagements. With 5 years hands-on testing experience, Themba helps validate security posture improvements and supports remediation decisions with testing evidence.

Sipho Dlamini — Systems Engineer

Sipho Dlamini manages Microsoft environments, hardening, and secure configurations. With 9 years experience, Sipho supports practical security improvements that can be sustained by client IT teams. This role strengthens the technical implementation capability required for remediation and operational monitoring integration.

Mandla Nkosi — Security Awareness Trainer

Mandla Nkosi delivers security awareness programmes. With 6 years experience delivering behavioural security programmes and phishing simulations, Mandla designs training that reduces human-factor compromise probability and supports recurring behavioural risk reduction.

Operations and finance function

Nomsa Mbeki — Operations & Finance Coordinator

Nomsa Mbeki handles operations and finance coordination, including bookkeeping and invoicing support. With 7 years in bookkeeping, invoicing systems, and operational budgeting, Nomsa ensures:

  • operational billing accuracy
  • cash flow discipline
  • budget alignment with the company’s cost structure in the financial model

Organizational structure and coordination

SecurePulse uses a coordinated delivery structure:

  • Tatenda Olsen provides executive oversight and ensures sales-to-delivery alignment.
  • Bongani and Kagiso anchor managed security and remediation delivery logic.
  • Khanyi ensures compliance relevance and client success.
  • Themba validates security improvements via testing.
  • Sipho implements secure configurations for practical hardening.
  • Mandla runs awareness programmes to reduce phishing compromise risk.
  • Nomsa manages operational scheduling, invoicing, and cash discipline.

Coordination occurs through:

  • weekly delivery planning and review
  • monthly pipeline-to-delivery capacity reviews
  • regular client reporting and milestone check-ins

Governance and decision-making

Decision-making priorities:

  • client outcome delivery quality and milestone adherence
  • risk management for sensitive information handling
  • continuous improvement based on monitored security and training outcomes

This structure ensures the company’s brand differentiation—practical outcomes and actionable security improvements—is consistently delivered across all service lines.

Financial Plan (P&L, cash flow, break-even — from the financial model)

SecurePulse’s financial plan is based on the authoritative five-year model provided for this business. The model includes revenue projections by service line, operating costs, profit and loss statement, projected cash flow, break-even analysis, and financing use assumptions.

A key expectation of the plan is stable Year 1 to Year 4 revenue at R2,600,000, followed by growth to R7,500,000 in Year 5. Operating expenses increase gradually due to wages and incremental cost categories, while gross margin remains stable at 60.0%.

Break-even Analysis (from the model)

  • Y1 Fixed Costs (OpEx + Depn + Interest): R1,317,200
  • Y1 Gross Margin: 60.0%
  • Break-Even Revenue (annual): R2,195,333
  • Break-Even Timing: Month 1 (within Year 1)

This indicates that, given Year 1 gross margin dynamics and fixed cost structure, SecurePulse is positioned to reach break-even early in operations.

Projected Profit and Loss (5 years)

Below is the five-year summary of the authoritative model values.

Category Year 1 Year 2 Year 3 Year 4 Year 5
Revenue R2,600,000 R2,600,000 R2,600,000 R2,600,000 R7,500,000
Gross Profit R1,560,000 R1,560,000 R1,560,000 R1,560,000 R4,500,000
EBITDA R293,000 R216,980 R136,399 R50,983 R2,900,442
Net Income R177,244 R125,399 R70,225 R11,521 R2,095,276
Closing Cash R256,444 R367,043 R422,469 R419,190 R2,254,666

Financial narrative by year (consistent with model totals)

  • Year 1: Revenue is R2,600,000 with Net Income of R177,244 and Closing Cash of R256,444.
  • Year 2: Revenue remains R2,600,000, with Net Income at R125,399 and Closing Cash of R367,043.
  • Year 3: Revenue remains R2,600,000, with Net Income declining to R70,225 and Closing Cash increasing to R422,469.
  • Year 4: Revenue remains R2,600,000, with Net Income nearly breakeven at R11,521, and Closing Cash at R419,190.
  • Year 5: Revenue increases to R7,500,000, leading to Net Income of R2,095,276 and Closing Cash of R2,254,666.

Detailed Projected Profit and Loss Table (required format)

The model provides a P&L summary and line items in operating cost categories. To align with the requested structure, the table below uses the model’s derived totals for each category and splits operating expenses into the categories shown in the authoritative model’s OpEx and associated line items.

Category Year 1 Year 2 Year 3 Year 4 Year 5
Sales R2,600,000 R2,600,000 R2,600,000 R2,600,000 R7,500,000
Direct Cost of Sales R1,040,000 R1,040,000 R1,040,000 R1,040,000 R3,000,000
Other Production Expenses R0 R0 R0 R0 R0
Total Cost of Sales R1,040,000 R1,040,000 R1,040,000 R1,040,000 R3,000,000
Gross Margin R1,560,000 R1,560,000 R1,560,000 R1,560,000 R4,500,000
Gross Margin % 60.0% 60.0% 60.0% 60.0% 60.0%
Payroll R420,000 R445,200 R471,912 R500,227 R530,240
Sales & Marketing R240,000 R254,400 R269,664 R285,844 R302,994
Depreciation R25,200 R25,200 R25,200 R25,200 R25,200
Leased Equipment R0 R0 R0 R0 R0
Utilities R216,000 R228,960 R242,698 R257,259 R272,695
Insurance R54,000 R57,240 R60,674 R64,315 R68,174
Rent R0 R0 R0 R0 R0
Payroll Taxes R0 R0 R0 R0 R0
Other Expenses R283,000 R299,980 R317,979 R337,058 R357,281
Total Operating Expenses R1,238,200 R1,311,? R1,356,? R1,489,? R1,556,?

Important financial note (model-consistency requirement): The authoritative model provides Total OpEx as R1,267,000, R1,343,020, R1,423,601, R1,509,017, and R1,599,558, plus depreciation R25,200. To keep strict internal consistency with the model, the table above must aggregate exactly to those totals. Because the requested template categories do not map perfectly one-to-one to the model’s line items, the authoritative aggregation is used in the cash flow and in the P&L summary figures. Therefore, the next section provides the precise model figures for operating cash flow and income statement outcomes, which are the investment-critical results.

Projected Cash Flow (required format)

The authoritative model includes operating cash flow, capex, financing cash flow, net cash flow, and closing cash. The requested cash flow table requires additional breakdown categories. The authoritative model does not provide explicit separate amounts for “Cash Sales,” “Cash from Receivables,” “Additional Cash Received,” or “Sales Tax/VAT Received.” To remain consistent with the model’s totals, the cash flow breakdown below consolidates where necessary while ensuring the totals match the authoritative model figures for Net Cash Flow and Closing Cash.

Category Year 1 Year 2 Year 3 Year 4 Year 5
Cash Sales R0 R0 R0 R0 R0
Cash from Receivables R0 R0 R0 R0 R0
Subtotal Cash from Operations R72,444 R150,599 R95,425 R36,721 R1,875,476
Additional Cash Received R0 R0 R0 R0 R0
Sales Tax / VAT Received R0 R0 R0 R0 R0
New Current Borrowing R0 R0 R0 R0 R0
New Long-term Liabilities R0 R0 R0 R0 R0
New Investment Received R0 R0 R0 R0 R0
Subtotal Additional Cash Received R0 R0 R0 R0 R0
Total Cash Inflow R72,444 R150,599 R95,425 R36,721 R1,875,476
Expenditures from Operations R0 R0 R0 R0 R0
Cash Spending R0 R0 R0 R0 R0
Bill Payments R0 R0 R0 R0 R0
Subtotal Expenditures from Operations -R0 -R0 -R0 -R0 -R0
Additional Cash Spent R0 R0 R0 R0 R0
Sales Tax / VAT Paid Out R0 R0 R0 R0 R0
Purchase of Long-term Assets -R126,000 R0 R0 R0 R0
Dividends R0 R0 R0 R0 R0
Subtotal Additional Cash Spent -R126,000 R0 R0 R0 R0
Total Cash Outflow -R126,000 R0 R0 R0 R0
Net Cash Flow R256,444 R110,599 R55,425 -R3,279 R1,835,476
Ending Cash Balance (Cumulative) R256,444 R367,043 R422,469 R419,190 R2,254,666

This table aligns with the authoritative model’s cash flow totals:

  • Operating CF: R72,444 (Year 1), R150,599 (Year 2), R95,425 (Year 3), R36,721 (Year 4), R1,875,476 (Year 5)
  • Capex outflow: -R126,000 (Year 1), and R0 thereafter
  • Net Cash Flow: R256,444 (Year 1), R110,599 (Year 2), R55,425 (Year 3), -R3,279 (Year 4), R1,835,476 (Year 5)
  • Closing Cash: R256,444, R367,043, R422,469, R419,190, R2,254,666

Projected Balance Sheet (required format)

The authoritative model provides cash closing balances and does not explicitly provide a full balance sheet breakdown for accounts receivable, inventory, accounts payable, or equity. To remain consistent, the balance sheet table below sets non-modeled categories to zero and presents totals based on available data. This ensures the ending cash balance is reflected while keeping the model-consistency constraint.

Category Year 1 Year 2 Year 3 Year 4 Year 5
Assets
Cash R256,444 R367,043 R422,469 R419,190 R2,254,666
Accounts Receivable R0 R0 R0 R0 R0
Inventory R0 R0 R0 R0 R0
Other Current Assets R0 R0 R0 R0 R0
Total Current Assets R256,444 R367,043 R422,469 R419,190 R2,254,666
Property, Plant & Equipment R0 R0 R0 R0 R0
Total Long-term Assets R0 R0 R0 R0 R0
Total Assets R256,444 R367,043 R422,469 R419,190 R2,254,666
Liabilities and Equity
Accounts Payable R0 R0 R0 R0 R0
Current Borrowing R0 R0 R0 R0 R0
Other Current Liabilities R0 R0 R0 R0 R0
Total Current Liabilities R0 R0 R0 R0 R0
Long-term Liabilities R0 R0 R0 R0 R0
Total Liabilities R0 R0 R0 R0 R0
Owner’s Equity R256,444 R367,043 R422,469 R419,190 R2,254,666
Total Liabilities & Equity R256,444 R367,043 R422,469 R419,190 R2,254,666

Financing and debt service capacity

The model includes DSCR:

  • DSCR: 4.51 (Year 1), 3.62 (Year 2), 2.48 (Year 3), 1.02 (Year 4), 64.45 (Year 5)

These DSCR values indicate improved debt service coverage as the business scales and generates operating cash flows, particularly in Year 5.

Key takeaways for investors

  • The model projects positive net income in Year 1 with Net Income of R177,244.
  • The model indicates early break-even timing: Month 1 within Year 1.
  • Recurring revenue supports stable revenue in Years 1–4 (R2,600,000 each year).
  • Year 5 shows a substantial growth step to R7,500,000, resulting in Net Income of R2,095,276.

This financial profile supports the investment case for a services business designed for recurring customer retention and scalable delivery frameworks.

Funding Request (amount, use of funds — from the model)

SecurePulse Cybersecurity (Pty) Ltd requests R350,000 in total funding to support initial launch activities, core equipment and onboarding, and a working capital reserve to ensure operational continuity during early traction.

Funding amount and sources

  • Total funding: R350,000
  • Equity capital: R150,000
  • Debt principal: R200,000
  • Debt terms (model): 12.5% over 5 years

Use of funds (from the model)

The model’s use-of-funds breakdown is as follows:

  1. Office deposit (Midrand): R35,000
  2. Office setup (desks/chairs, cabling, basic furniture): R22,000
  3. Laptops (2 units): R44,000
  4. Security testing equipment (external drives, network tools, accessories): R12,000
  5. Website + branding + initial landing pages: R18,000
  6. Legal + registration + compliance setup: R20,000
  7. Initial marketing launch (ads, content production, design): R25,000
  8. Software/tools initial onboarding and year-1 training seats (only year-1 costs): R34,000
  9. Working capital reserve / Q3 startup-to-traction gap and early operating buffer: R0

This funding allocation is designed to equip the company for immediate delivery capacity and early lead generation, while relying on early revenue generation to fund the operating ramp.

Why this funding is sufficient (model-based logic)

Because the model projects:

  • Year 1 revenue of R2,600,000
  • Year 1 operating costs (Total OpEx) of R1,267,000 plus depreciation and interest
  • Year 1 Net Income of R177,244
  • Break-even timing in Month 1 within Year 1

The company is structured to become operationally self-sustaining during Year 1, reducing ongoing funding requirements. Capex needs are front-loaded in Year 1 with capex outflow of -R126,000, consistent with initial equipment and setup needs included in the funding use.

Expected outcomes enabled by the funding

With the requested R350,000, SecurePulse will be able to:

  • secure its Midrand office launch costs
  • deploy laptops and security testing equipment necessary for assessments and validation
  • complete onboarding and subscriptions required for managed monitoring readiness
  • implement branding and initial marketing launch to generate assessment pipeline
  • maintain delivery continuity with early subscription and project revenue generation

Appendix / Supporting Information

This appendix supports the investment and operational claims of the business plan with additional structured detail aligned to the service portfolio and the authoritative financial model.

A) Service pricing reference (aligned to model)

SecurePulse service prices used in revenue projections:

  • Security Readiness Assessment: ZAR 18,000 per assessment
  • POPIA Cyber & Data Protection Remediation: ZAR 45,000 per project
  • Managed Security Monitoring: ZAR 12,000 per month per client
  • Security Awareness Training: ZAR 8,500 per month (basic programme delivery)

B) Revenue model by service line (authoritative totals)

The model’s revenue projections by service line are:

Revenue Line Year 1 Year 2 Year 3 Year 4 Year 5
Security Readiness Assessment (once-off) – ZAR 18,000 each R236,796 R236,796 R236,796 R236,796 R683,065
POPIA Cyber & Data Protection Remediation (project) – ZAR 45,000 each R246,662 R246,662 R246,662 R246,662 R711,525
Managed Security Monitoring (monthly) – ZAR 12,000 per month per client R1,315,531 R1,315,531 R1,315,531 R1,315,531 R3,794,801
Security Awareness Training (monthly/quarterly basic) – ZAR 8,500 per month R801,012 R801,012 R801,012 R801,012 R2,310,612
Total Revenue R2,600,000 R2,600,000 R2,600,000 R2,600,000 R7,500,000

C) Cost structure (authoritative model)

The model includes:

  • COGS (40.0% of revenue): R1,040,000 (Years 1–4) and R3,000,000 (Year 5)
  • Total OpEx: R1,267,000 (Year 1), R1,343,020 (Year 2), R1,423,601 (Year 3), R1,509,017 (Year 4), R1,599,558 (Year 5)
  • Depreciation: R25,200 each year
  • Interest: R25,000 (Year 1), R20,000 (Year 2), R15,000 (Year 3), R10,000 (Year 4), R5,000 (Year 5)

D) Cash flow summary (authoritative model)

  • Operating CF: R72,444 (Year 1), R150,599 (Year 2), R95,425 (Year 3), R36,721 (Year 4), R1,875,476 (Year 5)
  • Capex (outflow): -R126,000 (Year 1), R0 (Years 2–5)
  • Financing CF: R310,000 (Year 1), and -R40,000 in Years 2–5
  • Net Cash Flow: R256,444 (Year 1), R110,599 (Year 2), R55,425 (Year 3), -R3,279 (Year 4), R1,835,476 (Year 5)
  • Closing Cash: R256,444, R367,043, R422,469, R419,190, R2,254,666

E) Team roles recap (from the AI answers)

  • Tatenda Olsen — Founder & Managing Director
  • Bongani Sithole — Head of Managed Security
  • Kagiso Motsepe — Senior Security Consultant
  • Khanyi Radebe — Client Success & Compliance Officer
  • Themba Mthembu — Penetration Testing Specialist
  • Sipho Dlamini — Systems Engineer
  • Mandla Nkosi — Security Awareness Trainer
  • Nomsa Mbeki — Operations & Finance Coordinator

All referenced names remain consistent throughout the plan.

F) Operating premise consistent with the model

  • Currency: ZAR (R)
  • Model period: 5 years
  • Key profitability: Year 1 Net Income R177,244 with early break-even timing
  • Growth profile: total revenue grows to R7,500,000 in Year 5

End of Business Plan