Cyber Security Act 2021 Compliance

Cyber Governance & Policy Framework

Barakat helps leadership and operational teams define who owns cybersecurity, who approves access, who handles incidents, how vendors are controlled, how backups and records are governed, and how exceptions are approved in a way that supports Section 56 of Sierra Leone's Cyber Security and Crime Act, 2021 and the National Cybersecurity Policy 2021 organisational measures pillar.

Governance before technology sprawl

For many organisations, the real cyber weakness is not a missing tool. It is the absence of clear ownership, approval paths, and operating rules. This engagement creates the governance structure that tells people who decides, who is accountable, and what the organisation expects before technical controls are rolled out or expanded.

Legal anchor

Section 56 of Sierra Leone's Cyber Security and Crime Act, 2021 creates exposure where a person exercising management or supervisory authority fails to exercise reasonable and proper control, and it also extends liability to the legal person where an offence occurs due to lack of supervision or control. That makes cybersecurity governance a management issue, not just an IT preference.

The National Cybersecurity Policy 2021 organisational measures pillar calls for institutional frameworks, accountability among stakeholders, coordinating governance and oversight bodies, regulatory mechanisms, legal authority, and guidelines to make cybersecurity effective and efficient. This engagement turns those governance expectations into practical internal policies, decision rights, and operating standards for the organisation.

Best for

Ministries NGOs Banks Hospitals Schools Medium & Large Corporates

Best suited to organisations that need a clear entry point into cybersecurity compliance before moving into technical packs, especially where leadership wants stronger accountability across operations, IT, HR, finance, and third-party access.

Deliverables

  • Cybersecurity policy
  • Access-control policy
  • Backup policy
  • Incident response policy
  • Vendor-access policy
  • Acceptable-use policy
  • Records handling policy
  • Branch office IT standards
  • Admin privilege standards

Governance scope

  • Decision rights for ownership, access approval, incident handling, and exception approval
  • Vendor, backup, logging, records, and offboarding governance defined in plain operating terms
  • Policy and standards pack that can guide technical implementation afterwards
  • Leadership alignment across operational and technical teams, not just the IT department
Ownership & Accountability

Define who owns cybersecurity before responsibility disappears in meetings

Cybersecurity weakens quickly when everyone assumes someone else is responsible. We work with leadership and operational teams to define who owns the overall program, who takes key decisions, and how accountability moves across management, IT, operations, HR, and finance.

Define who owns cybersecurity at executive and operational level and how responsibility is distributed across teams that influence risk in practice
Clarify who approves access, who accepts exceptions, and who signs off on risk-sensitive decisions instead of leaving them to informal habits
Translate management accountability into practical governance rules so leaders can show reasonable and proper control rather than relying on undocumented assumptions
Placeholder illustration for cybersecurity ownership, decision rights, and accountability design
Access & Vendor Control

Set the approval rules for staff, admins, branches, and third parties

Access decisions and vendor access are often where governance breaks down first. We define the rules for who gets access, how it is approved, how administrators are controlled, and how suppliers, consultants, and support vendors are allowed into the environment without bypassing discipline.

Define access-approval workflows, privilege standards, and rules for administrative accounts so high-risk access is governed consistently
Create vendor-access rules covering onboarding, remote support, approval, supervision, and removal of third-party access when work ends
Align offboarding, contractor expiry, and branch-office standards so access governance stays consistent across offices and service providers
Placeholder illustration for access approvals, admin standards, and vendor access governance
Operational Governance

Put incident, backup, logging, and records decisions into working policy

Good governance becomes real when it shapes daily operations. We help teams define how incidents are escalated, how backups are checked, what gets logged, how records are classified, and how exceptions are approved so control does not depend on memory or personality.

Define who handles incidents, who is called when something goes wrong, and what escalation path management expects to be followed
Set rules for backup checks, logging expectations, records classification, and evidence of control so operational teams know what good discipline looks like
Build exception-approval paths so departures from policy are visible, justified, and owned instead of quietly becoming the new normal
Placeholder illustration for incident, backup, logging, and records governance workflows
Policy & Standards Pack

Leave the organisation with rules that can guide technical implementation

A governance project should produce more than workshop notes. We leave clients with a practical policy and standards pack that leadership can approve, teams can operate against, and future technical work can be measured against. This is why it often becomes the starting point before deeper implementation packs.

Prepare the cybersecurity policy, access-control policy, backup policy, incident response policy, vendor-access policy, acceptable-use policy, and records-handling policy
Define branch office IT standards and admin privilege standards so different sites and administrators work to a clearer baseline
Give the organisation a governance baseline that future firewall, endpoint, incident response, document control, and identity projects can build on cleanly

Deliverables: Cybersecurity policy, access-control policy, backup policy, incident response policy, vendor-access policy, acceptable-use policy, records handling policy, branch office IT standards, and admin privilege standards.

Urgency: If the organisation still cannot say who owns cyber decisions, who approves risky access, or which standards teams are expected to follow, the governance gap should be closed before the next incident or audit exposes it.

Book Governance Review
Placeholder illustration for cybersecurity policy pack and operational standards framework

If no one clearly owns cyber decisions, control is already weaker than it looks

We can define the ownership model, approval paths, operational rules, and policy pack your organisation needs before technical projects multiply without a clear governance base.

Request a Compliance Review