Security solutions with passion,
expertise & integrity

Simphiwe Mayisela, Managing
Director: SS-Consulting (Pty) Ltd.

Simphiwe Mayisela’s career as the Head of Information Security took an unexpected direction when he became a whistleblower after uncovering corruption at the Public Investment Corporation. This painful and difficult journey had a positive outcome, as it led to him becoming an entrepreneur, and founding SS-Consulting.

Honesty and integrity align strongly with our ethos in the security industry,” Mayisela says. “However, after reporting this corruption to the SAPS, I faced threats and criminal charges, and was dismissed, which is a common outcome for whistleblowers.

Despite my actions having good intent, I Because it was difficult for Mayisela to find alternative employment while this was playing out, he started his own business. SS-Consulting became fully operational in 2018.

Today, it is a 51% black, female-owned consultancy company that specialises in strategic and technical consultation in the field of cybersecurity, was slandered in sections of the press and on social media. My story was published in the Mail & Guardian and later in a book by Mandy Wiener called The Whistleblowers.

Thanks to my actions, the corrupt individuals at PIC were later dismissed and there is an ongoing investigation by the Hawks against them.”

Because it was difficult for Mayisela to find alternative employment while this was playing out, he started his own business. SS-Consulting became fully operational in 2018.

Today, it is a 51% black, female-owned consultancy company that specialises in strategic and technical consultation in the field of cybersecurity, governance, risk and compliance.
Mayisela emphasises that cybersecurity is his vocation. “I have worked in the field for the past 19 years. My career started in mainframe security, back in a time where we looked at blue screens. I transitioned myself to a distributed environment and then to cloud security. So much has happened during my tenure, and there is so much exciting change still to come.”

SS-Consulting offers infrastructure security consulting, application security consulting, business continuity management, identity management, and information security management services. “Our philosophy is to become strategic partners with our clients to address their security challenges,” Mayisela says. “We offer customised on-site consulting services and assistance in the assessment of business risks and requirements, and the development of security strategy, policies and processes.

Our services include security design and architecture, cybersecurity assessments, penetration testing, and managed security services, including firewall management,
SIEM-as-a-Service, identity and access management, among others.”

The weakest link

Penetration testing is their biggest area of specialisation. “All the team members at SS-Consulting are Offensive Security Certified Professionals (OSCP). We conduct IT security assessments for our clients, where we simulate the role of hackers in an effort to highlight security gaps. We are successful 8 out of 10 times. It’s very rare that defences are solid. But this exercise shows an organisation where its weaknesses are. Often the weakest link is the human element, so we put a lot of focus on making people aware of the risks caused by their own actions,” he says.

One of Mayisela’s biggest points of pride was when the Independent Electoral Commission (IEC) entrusted SS-Consulting to assess their entire ICT infrastructure and voter management devices in preparation for the provincial elections last year.

In another exciting step, Accenture has recently onboarded them into their Enterprise Supplier Development Programme.

 


Mayisela realised there is a huge gap in the market when it comes to cybersecurity, and a massive skills shortage.

Being able to provide these sought-after skills to clients is what gives SS-Consulting the edge.

“In the US alone, there are about 1 million cybersecurity workers, but there were around 715 000 jobs yet to be filled as of November 2021, according to a report by Emsi Burning Glass (now Lightcast),” he says.

“The SA government has also identified a big gap in cybersecurity skills and is currently working to develop a National Cybersecurity Skills Framework to guide the training of cybersecurity professionals in the country.

SS-Consulting has been appointed as a member of the Advisory Panel for the MICT SETA Cyber Security Qualification Working Group from August 2020 to develop a Cybersecurity Tertiary Qualification.

Key agenda item


All team members at SS Consulting have received the necessary training and, where appropriate, are certified in CISSP, CISA, OSCP, CEH, SABSA, and more. “

This means SS-Consulting is in a better position than many others to assist its clients by identifying the IT risks, and the determination of controls needed to mitigate those risks,” Mayisela says. “SS-Consulting has also created a pipeline of skills, where we bring on graduates as interns, empower them with skills, and then retain some of them as full time cybersecurity experts.

We look for a true passion for the industry and a fascination with security and technology, as well as a desire to keep learning.




“Quality is a cornerstone of our organisation,” he adds. “Part of our philosophy is the brainstorming of solutions to ensure that they are aligned with best practice, and add value to our clients.”

Cost is a key issue in today’s environment, and the cost structure SS-Consulting offers is fair. They ensure that clients receive value without compromising on the quality of the resources, skills and expertise that are needed to ensure an organisation is fully protected. “We are seeing cybersecurity being taken more seriously today, and at board level. It’s a key agenda item. There is increased demand across all sectors because the consequences of a breach are so serious.

Not only is there massive financial damage, but there is also reputational damage, and that is not easy to quantify in terms of costs,” Mayisela emphasises.

All companies are unique in their own right, as such, we strive to acquire an in-depth understanding of our clients’ business objectives, goals and vision in order to ensure that our solutions do not only support critical business initiatives, but are also an enabler to our clients’ business objectives.

Send us your details for us to keep in touch