Package 01 · Agent Security · most requested · for South African FSPs

Protect your client data from AI misuse, inside and out.

We find every AI tool touching client data, attack it the way an adversary would, put the controls in, train your people, and leave an evidence pack mapped to POPIA, Joint Standard 2 of 2024 (cybersecurity and cyber resilience) and Joint Standard 1 of 2023 (IT governance).

Start with 10 free hours
  • From R265,000, fixed
  • Controls in place by the end of Phase 2
  • Last 30% only when your test passes
  • Everything in your name

What you get, phase by phase

For financial-services firms whose staff, vendors or attackers already use AI near client data.

What it feels like now

Staff use AI tools nobody approved, agents get more access than they need, suppliers holding your client files get breached, and attackers use AI for better phishing, fake client voices and prompt injection. The regulators hold you responsible, not the supplier.

Where others stop

AI-security platforms are priced for enterprises and sold without implementation; local cyber firms sell generic tests; and the Joint Standards set the controls without saying how they apply to AI agents.

Sources: Webber Wentzel on Joint Standard 2 of 2024

What we do

We find every AI tool touching client data, attack it the way an adversary would, put the controls in, train your people, and leave an evidence pack mapped to POPIA, Joint Standard 2 of 2024 (cybersecurity and cyber resilience) and Joint Standard 1 of 2023 (IT governance).

The Joint Standards apply to many regulated institutions, including discretionary and administrative FSPs, insurers and retirement-fund administrators. For advice-only firms they are a sound benchmark rather than a legal requirement.

  • Inventory of approved and shadow AI, agents and connectors, including what ChatGPT and Microsoft 365 Copilot can see
  • Supplier review: which vendors and AI tools hold your client data, and your plan if one is breached
  • Red-team tests run against the OWASP Top 10 for LLM applications and MITRE ATLAS: prompt injection, data exfiltration, voice fraud, phishing
  • Controls implemented, not just recommended
  • Evidence pack mapped clause by clause to POPIA s19 to s22 and the Joint Standards, with an incident log that fills the regulators' notification template

Where it fits

Advice practices and family offices
Staff pasting client files into ChatGPT, and payment or bank-detail changes that need a call-back rule.
Discretionary and administrative FSPs, insurers and fund administrators
Joint Standard evidence your board, principal officer or regulator can read.
Firms on Microsoft 365 or Google Workspace
A ChatGPT and Copilot exposure review: which files AI can reach that it shouldn't.
Fintechs running their own agents
An independent red-team of your production agents, run with your engineers.
Brokers and insurers
Voice-clone and fake-instruction fraud on claims payouts and bank-detail changes.

What every Agent Security engagement leaves in place

How we keep your agents safe

By the end of Phase 3 every line below is in place, tested and written up in your evidence pack, mapped to the rule it answers.

Controls at handover7 of 7 in place
  • Least-privilege access

    Each agent and connector reaches only the mailboxes, folders and systems its job needs.

    Maps to: POPIA s19Joint Standard 2 of 2024
  • ID numbers and bank details masked before any model

    Identity numbers, account numbers and similar fields are replaced before text reaches an AI model.

    Maps to: POPIA s19
  • Every agent action logged

    Who or what did it, when, on which record, kept where your compliance officer can read it.

    Maps to: POPIA s19Joint Standard 2 of 2024
  • Kill switch tested

    One step stops every agent, and the team has practised it.

    Maps to: Joint Standard 2 of 2024
  • Human approval on payments and bank-detail changes

    No agent can pay, or change where money goes, without a named person approving and a call-back.

    Maps to: POPIA s19Joint Standard 2 of 2024
  • Quarterly red-team retest

    The test set and schedule are handed over: your team runs it, or we do on the optional monthly plan.

    Maps to: Joint Standard 2 of 2024
  • Incident playbook with the POPIA s22 decision

    Who decides whether a breach must be reported to the Information Regulator and to clients, and how fast.

    Maps to: POPIA s22Joint Standard 2 of 2024

POPIA s19 sets the security safeguards; s22 sets breach notification. Joint Standard 2 of 2024 (cyber resilience) and Joint Standard 1 of 2023 (IT governance) apply to many regulated institutions, including discretionary and administrative FSPs, insurers and retirement-fund administrators. For advice-only firms they are a benchmark.

How it works

Phase 0: information gathering. Here is what happens.

The first 10 hours are on us: no invoice and no obligation. At the end you keep the written findings whether or not you go ahead.

  1. Step 1

    First call

    Thirty minutes online. You tell us what isn't working; we ask how the work gets done today.

  2. Step 2

    We read your log

    You note what isn't working on our private form. An automatic email with your next steps arrives within a minute; the people assigned to your firm read the log itself within one working day.

  3. Step 3

    An engineer at your office

    Your engineer sits with the people doing the work and logs every problem as it really happens.

  4. Step 4

    Assessment

    What each problem costs you, what has to be in place first, and which package fits.

  5. Step 5

    Findings and a fixed price

    Written findings you keep either way, and one package at one fixed price if it is worth building.

Your log stays private

You write down what isn’t working on our confidential form. It is encrypted, read only by the people assigned to your firm, and never sent to an AI model or anyone else.

Next steps in a minute

As soon as you send the log, you get an email that says what we heard, which package fits, what we need from you, and how the three phases would run.

One engineer, on site

If you go ahead, a forward-deployed engineer works inside your firm two days a week through all three phases: one person who knows your files, your people and your systems.

Why fixed packages

We cost more than an hourly project. Here’s what that buys.

Most AI work billed by the hour never leaves the pilot. We price the outcome instead, and we carry the risk of getting there.

Typical hourly projectA MAKGLOBAL package
PriceAn estimate, then change requestsFixed before we start
Who builds itWhoever is free that weekOne named engineer, on your site
When you pay the last partOn delivery, whether it works or notWhen the acceptance test agreed before Phase 1 passes
Who owns itOften the vendor’s accounts and licencesYour company, from the start of Phase 1
After handoverA support contract you needYour team runs it; ongoing care is optional
RulesGenericBuilt around FAIS, POPIA and the cyber resilience Joint Standard

Talk to a person

Want to know more before you start?

Ask us anything about a package, the price or how the three phases would run in your firm. You will speak to a person.

Leave your number on the free hours form and choose “call me back”. A person phones you within one working day.

Or email hello@makglobal.africa.

Claim your 10 free hours

Questions

Questions people ask

How long does a package take?

Every package runs in three phases: develop, implement and hand over. We agree the dates for each phase with you in the first week, put them in the scope sheet you sign, and hold ourselves to them.

Why are you more expensive than other providers?

Because you are buying a working result with a test attached, not hours. The price includes redesigning the work with your people, building it on your accounts, an engineer on site through all three phases, training, documentation and handover. If it does not pass the acceptance test, you do not pay the last 30%.

What if it doesn’t pass the acceptance test?

We keep working on it at our own cost until it does. If it still doesn’t, the final 30% is never invoiced. The test is written with you before Phase 1 starts, so we both know what “working” means before any build starts.

Can we take two packages at once?

We run one at a time. The first is handed over and working before the second begins, and the second goes faster because we already know your firm. It keeps the price fixed and the focus on one result.

Is the confidential log really confidential?

Yes. It is encrypted before it is stored, only the people assigned to your firm can read it, it is never pasted into an AI tool, and the internal notice we send says only that a log arrived, not what is in it. We sign a mutual NDA before your visit.

Do you work outside financial services?

Not at the moment. Our references, templates and test sets are built for advice practices, wealth and asset managers, insurers, lenders and fiduciary firms, and the 10 free hours are for firms of five or more people.

What does the optional monthly fee cover?

Monitoring, model and API changes, fixes when a system you use changes, and a monthly review. It is month to month and cancellable on 30 days’ notice (Investment Models: 12-month minimum). Handover is designed so you can run everything without it.

· AI-generated presenter, script by MAKGLOBAL

Claim your 10 free hours