Skip to content

Digital technologies and solutions

IT security & risk.

The systems that carry your finance, your customers and your data deserve better than perimeter security. We set the strategy, measure real exposure, fix what matters and govern over time, right into the core of SAP and Salesforce, where access, authorisations and continuity are decided.

The problem

The core business system, blind spot of security.

Security teams watch the network and the workstations. The ERP and the CRM, meanwhile, live their own lives: authorisations accumulated over years, segregation of duties never checked, forgotten privileged accounts, uncontrolled exports of customer data, a recovery plan tested on paper. Yet that is where payments, personal data and accounting entries flow. On top of technical exposure comes the regulatory requirement: Law No. 2008-12 and oversight by the CDP (Senegal's data protection authority), the frameworks of your sector regulators, the expectations of your partners and your insurers. It is no longer satisfied with statements of intent.

Our approach

Measure, fix, prove.

01

Set the strategy

Security policy, risk analysis, priorities aligned with business stakes and the regulatory framework. ISO 27001 serves as the structuring reference, without turning certification into a goal if it is not yours.

02

Measure exposure

Penetration testing of your applications, infrastructure and exposed access points, configuration and authorisation audit of SAP and Salesforce. A factual assessment, ranked by risk.

03

Control access

Identity and access management (IAM), account lifecycle, authorisation review and segregation of duties (SoD) in SAP, profiles and permissions in Salesforce. Every access justified, every conflict detected and resolved.

04

Ensure continuity

Business continuity plan and IT disaster recovery plan: crisis scenarios, realistic recovery objectives, verified backups, full-scale exercises. Resilience is proven.

05

Govern over time

Automated controls, risk indicators, periodic reviews, team awareness. Security as a permanent state, not a sprint before the audit.

What we take on

From diagnosis to permanent control.

Security strategy & risk management

Security policy, risk mapping and analysis, prioritised treatment plan, dashboard for management. Structured on ISO 27001, sized to your organisation.

Penetration testing & audits

External and internal penetration tests, web and mobile applications, cloud configuration reviews, dedicated SAP and Salesforce audit (configuration, authorisations, interfaces, sensitive data). Remediation plan prioritised by risk.

SAP security

Segregation of duties matrix, detection of authorisation conflicts, compensating controls, role redesign, system hardening, security of interfaces and SAP BTP extensions.

Salesforce security

Profiles, permission sets and sharing rules, strong authentication, control of exports and integrations, logging of access to customer data, regular configuration review.

IAM & identity management

Identity and access lifecycle, privileged accounts, single sign-on and multi-factor authentication, on premises and in the cloud. The right access for the right person, and its revocation proven.

Law No. 2008-12 & CDP compliance

Mapping of processing activities, register, declarations and authorisation requests to the Commission de protection des données personnelles, technical and organisational measures, implemented in the IT system right into SAP and Salesforce. For subsidiaries of European groups, alignment with the GDPR.

Awareness

Team awareness programs, phishing exercises, training of administrators and privileged users. The first line of defence remains human.

Business continuity & recovery

Business impact analysis, continuity plan, IT disaster recovery plan, crisis exercises and regular failover tests, including for systems hosted in the cloud.

The context

Compliance, here, has a name: the CDP.

In Senegal, all processing of personal data falls under Law No. 2008-12 of 25 January 2008 and the oversight of the Commission de protection des données personnelles. A CRM, a payroll database, a customer portal or an AI project are all concerned. We prepare the declarations and authorisation requests, document purposes and security measures, and design systems so that compliance is verifiable, not merely declared. For a group present in several UEMOA countries, we take each national framework into account. Customer data protection in Salesforce

One authorisation too many is an open door in the middle of the house. Perimeter security cannot help. You have to audit where the money and the data flow.
AGILICIS convictionIT security & risk team

Flash audit

When were your access rights last audited?

A flash audit (authorisations, segregation of duties, external exposure) to measure your real risk and prioritise remediation.

Let's talk