- Home
- Our services
- IT security & risk
Digital technologies and solutions
IT security & risk.
The systems that carry your finance, your customers and your data deserve better than perimeter security. We set the strategy, measure real exposure, fix what matters and govern over time, right into the core of SAP and Salesforce, where access, authorisations and continuity are decided.
The problem
The core business system, blind spot of security.
Security teams watch the network and the workstations. The ERP and the CRM, meanwhile, live their own lives: authorisations accumulated over years, segregation of duties never checked, forgotten privileged accounts, uncontrolled exports of customer data, a recovery plan tested on paper. Yet that is where payments, personal data and accounting entries flow. On top of technical exposure comes the regulatory requirement: Law No. 2008-12 and oversight by the CDP (Senegal's data protection authority), the frameworks of your sector regulators, the expectations of your partners and your insurers. It is no longer satisfied with statements of intent.
Our approach
Measure, fix, prove.
Set the strategy
Security policy, risk analysis, priorities aligned with business stakes and the regulatory framework. ISO 27001 serves as the structuring reference, without turning certification into a goal if it is not yours.
Measure exposure
Penetration testing of your applications, infrastructure and exposed access points, configuration and authorisation audit of SAP and Salesforce. A factual assessment, ranked by risk.
Control access
Identity and access management (IAM), account lifecycle, authorisation review and segregation of duties (SoD) in SAP, profiles and permissions in Salesforce. Every access justified, every conflict detected and resolved.
Ensure continuity
Business continuity plan and IT disaster recovery plan: crisis scenarios, realistic recovery objectives, verified backups, full-scale exercises. Resilience is proven.
Govern over time
Automated controls, risk indicators, periodic reviews, team awareness. Security as a permanent state, not a sprint before the audit.
What we take on
From diagnosis to permanent control.
- Security strategy & risk management
Security policy, risk mapping and analysis, prioritised treatment plan, dashboard for management. Structured on ISO 27001, sized to your organisation.
- Penetration testing & audits
External and internal penetration tests, web and mobile applications, cloud configuration reviews, dedicated SAP and Salesforce audit (configuration, authorisations, interfaces, sensitive data). Remediation plan prioritised by risk.
- SAP security
Segregation of duties matrix, detection of authorisation conflicts, compensating controls, role redesign, system hardening, security of interfaces and SAP BTP extensions.
- Salesforce security
Profiles, permission sets and sharing rules, strong authentication, control of exports and integrations, logging of access to customer data, regular configuration review.
- IAM & identity management
Identity and access lifecycle, privileged accounts, single sign-on and multi-factor authentication, on premises and in the cloud. The right access for the right person, and its revocation proven.
- Law No. 2008-12 & CDP compliance
Mapping of processing activities, register, declarations and authorisation requests to the Commission de protection des données personnelles, technical and organisational measures, implemented in the IT system right into SAP and Salesforce. For subsidiaries of European groups, alignment with the GDPR.
- Awareness
Team awareness programs, phishing exercises, training of administrators and privileged users. The first line of defence remains human.
- Business continuity & recovery
Business impact analysis, continuity plan, IT disaster recovery plan, crisis exercises and regular failover tests, including for systems hosted in the cloud.
The context
Compliance, here, has a name: the CDP.
In Senegal, all processing of personal data falls under Law No. 2008-12 of 25 January 2008 and the oversight of the Commission de protection des données personnelles. A CRM, a payroll database, a customer portal or an AI project are all concerned. We prepare the declarations and authorisation requests, document purposes and security measures, and design systems so that compliance is verifiable, not merely declared. For a group present in several UEMOA countries, we take each national framework into account. Customer data protection in Salesforce →
One authorisation too many is an open door in the middle of the house. Perimeter security cannot help. You have to audit where the money and the data flow.
Flash audit
When were your access rights last audited?
A flash audit (authorisations, segregation of duties, external exposure) to measure your real risk and prioritise remediation.
Let's talk →