Package 01 · Agent Security · most requested · for South African FSPs
Protect your client data from AI misuse, inside and out.
We find every AI tool touching client data, attack it the way an adversary would, put the controls in, train your people, and leave an evidence pack mapped to POPIA, Joint Standard 2 of 2024 (cybersecurity and cyber resilience) and Joint Standard 1 of 2023 (IT governance).
- From R265,000, fixed
- Controls in place by the end of Phase 2
- Last 30% only when your test passes
- Everything in your name
What you get, phase by phase
For financial-services firms whose staff, vendors or attackers already use AI near client data.
What it feels like now
Staff use AI tools nobody approved, agents get more access than they need, suppliers holding your client files get breached, and attackers use AI for better phishing, fake client voices and prompt injection. The regulators hold you responsible, not the supplier.
Where others stop
AI-security platforms are priced for enterprises and sold without implementation; local cyber firms sell generic tests; and the Joint Standards set the controls without saying how they apply to AI agents.
What we do
We find every AI tool touching client data, attack it the way an adversary would, put the controls in, train your people, and leave an evidence pack mapped to POPIA, Joint Standard 2 of 2024 (cybersecurity and cyber resilience) and Joint Standard 1 of 2023 (IT governance).
The Joint Standards apply to many regulated institutions, including discretionary and administrative FSPs, insurers and retirement-fund administrators. For advice-only firms they are a sound benchmark rather than a legal requirement.
- Inventory of approved and shadow AI, agents and connectors, including what ChatGPT and Microsoft 365 Copilot can see
- Supplier review: which vendors and AI tools hold your client data, and your plan if one is breached
- Red-team tests run against the OWASP Top 10 for LLM applications and MITRE ATLAS: prompt injection, data exfiltration, voice fraud, phishing
- Controls implemented, not just recommended
- Evidence pack mapped clause by clause to POPIA s19 to s22 and the Joint Standards, with an incident log that fills the regulators' notification template
Where it fits
- Advice practices and family offices
- Staff pasting client files into ChatGPT, and payment or bank-detail changes that need a call-back rule.
- Discretionary and administrative FSPs, insurers and fund administrators
- Joint Standard evidence your board, principal officer or regulator can read.
- Firms on Microsoft 365 or Google Workspace
- A ChatGPT and Copilot exposure review: which files AI can reach that it shouldn't.
- Fintechs running their own agents
- An independent red-team of your production agents, run with your engineers.
- Brokers and insurers
- Voice-clone and fake-instruction fraud on claims payouts and bank-detail changes.
What every Agent Security engagement leaves in place
How we keep your agents safe
By the end of Phase 3 every line below is in place, tested and written up in your evidence pack, mapped to the rule it answers.
-
Least-privilege access
Each agent and connector reaches only the mailboxes, folders and systems its job needs.
Maps to: POPIA s19Joint Standard 2 of 2024 -
ID numbers and bank details masked before any model
Identity numbers, account numbers and similar fields are replaced before text reaches an AI model.
Maps to: POPIA s19 -
Every agent action logged
Who or what did it, when, on which record, kept where your compliance officer can read it.
Maps to: POPIA s19Joint Standard 2 of 2024 -
Kill switch tested
One step stops every agent, and the team has practised it.
Maps to: Joint Standard 2 of 2024 -
Human approval on payments and bank-detail changes
No agent can pay, or change where money goes, without a named person approving and a call-back.
Maps to: POPIA s19Joint Standard 2 of 2024 -
Quarterly red-team retest
The test set and schedule are handed over: your team runs it, or we do on the optional monthly plan.
Maps to: Joint Standard 2 of 2024 -
Incident playbook with the POPIA s22 decision
Who decides whether a breach must be reported to the Information Regulator and to clients, and how fast.
Maps to: POPIA s22Joint Standard 2 of 2024
POPIA s19 sets the security safeguards; s22 sets breach notification. Joint Standard 2 of 2024 (cyber resilience) and Joint Standard 1 of 2023 (IT governance) apply to many regulated institutions, including discretionary and administrative FSPs, insurers and retirement-fund administrators. For advice-only firms they are a benchmark.
The other four packages
We run one package at a time, so the first is handed over and working before the next begins.
- 02 Process Automation One internal process, redesigned and automated end to end. R195,000
- 03 FSP Back Office The admin behind every client file, done by agents your team supervises. From R285,000
- 04 Client Work Agents One agent that does one piece of client work properly. R295,000
- 05 Investment Models A model built on your investment philosophy, that you can explain one trade at a time. From R1,250,000
How it works
Phase 0: information gathering. Here is what happens.
The first 10 hours are on us: no invoice and no obligation. At the end you keep the written findings whether or not you go ahead.
- Step 1
First call
Thirty minutes online. You tell us what isn't working; we ask how the work gets done today.
- Step 2
We read your log
You note what isn't working on our private form. An automatic email with your next steps arrives within a minute; the people assigned to your firm read the log itself within one working day.
- Step 3
An engineer at your office
Your engineer sits with the people doing the work and logs every problem as it really happens.
- Step 4
Assessment
What each problem costs you, what has to be in place first, and which package fits.
- Step 5
Findings and a fixed price
Written findings you keep either way, and one package at one fixed price if it is worth building.
Your log stays private
You write down what isn’t working on our confidential form. It is encrypted, read only by the people assigned to your firm, and never sent to an AI model or anyone else.
Next steps in a minute
As soon as you send the log, you get an email that says what we heard, which package fits, what we need from you, and how the three phases would run.
One engineer, on site
If you go ahead, a forward-deployed engineer works inside your firm two days a week through all three phases: one person who knows your files, your people and your systems.
Why fixed packages
We cost more than an hourly project. Here’s what that buys.
Most AI work billed by the hour never leaves the pilot. We price the outcome instead, and we carry the risk of getting there.
| Typical hourly project | A MAKGLOBAL package | |
|---|---|---|
| Price | An estimate, then change requests | Fixed before we start |
| Who builds it | Whoever is free that week | One named engineer, on your site |
| When you pay the last part | On delivery, whether it works or not | When the acceptance test agreed before Phase 1 passes |
| Who owns it | Often the vendor’s accounts and licences | Your company, from the start of Phase 1 |
| After handover | A support contract you need | Your team runs it; ongoing care is optional |
| Rules | Generic | Built around FAIS, POPIA and the cyber resilience Joint Standard |
Talk to a person
Want to know more before you start?
Ask us anything about a package, the price or how the three phases would run in your firm. You will speak to a person.
Leave your number on the free hours form and choose “call me back”. A person phones you within one working day.
Or email hello@makglobal.africa.
Claim your 10 free hoursQuestions
Questions people ask
How long does a package take?
Every package runs in three phases: develop, implement and hand over. We agree the dates for each phase with you in the first week, put them in the scope sheet you sign, and hold ourselves to them.
Why are you more expensive than other providers?
Because you are buying a working result with a test attached, not hours. The price includes redesigning the work with your people, building it on your accounts, an engineer on site through all three phases, training, documentation and handover. If it does not pass the acceptance test, you do not pay the last 30%.
What if it doesn’t pass the acceptance test?
We keep working on it at our own cost until it does. If it still doesn’t, the final 30% is never invoiced. The test is written with you before Phase 1 starts, so we both know what “working” means before any build starts.
Can we take two packages at once?
We run one at a time. The first is handed over and working before the second begins, and the second goes faster because we already know your firm. It keeps the price fixed and the focus on one result.
Is the confidential log really confidential?
Yes. It is encrypted before it is stored, only the people assigned to your firm can read it, it is never pasted into an AI tool, and the internal notice we send says only that a log arrived, not what is in it. We sign a mutual NDA before your visit.
Do you work outside financial services?
Not at the moment. Our references, templates and test sets are built for advice practices, wealth and asset managers, insurers, lenders and fiduciary firms, and the 10 free hours are for firms of five or more people.
What does the optional monthly fee cover?
Monitoring, model and API changes, fixes when a system you use changes, and a monthly review. It is month to month and cancellable on 30 days’ notice (Investment Models: 12-month minimum). Handover is designed so you can run everything without it.