Barakat helps leadership and operational teams define who owns cybersecurity, who approves access, who handles incidents, how vendors are controlled, how backups and records are governed, and how exceptions are approved in a way that supports Section 56 of Sierra Leone's Cyber Security and Crime Act, 2021 and the National Cybersecurity Policy 2021 organisational measures pillar.
For many organisations, the real cyber weakness is not a missing tool. It is the absence of clear ownership, approval paths, and operating rules. This engagement creates the governance structure that tells people who decides, who is accountable, and what the organisation expects before technical controls are rolled out or expanded.
Section 56 of Sierra Leone's Cyber Security and Crime Act, 2021 creates exposure where a person exercising management or supervisory authority fails to exercise reasonable and proper control, and it also extends liability to the legal person where an offence occurs due to lack of supervision or control. That makes cybersecurity governance a management issue, not just an IT preference.
The National Cybersecurity Policy 2021 organisational measures pillar calls for institutional frameworks, accountability among stakeholders, coordinating governance and oversight bodies, regulatory mechanisms, legal authority, and guidelines to make cybersecurity effective and efficient. This engagement turns those governance expectations into practical internal policies, decision rights, and operating standards for the organisation.
Best suited to organisations that need a clear entry point into cybersecurity compliance before moving into technical packs, especially where leadership wants stronger accountability across operations, IT, HR, finance, and third-party access.
Cybersecurity weakens quickly when everyone assumes someone else is responsible. We work with leadership and operational teams to define who owns the overall program, who takes key decisions, and how accountability moves across management, IT, operations, HR, and finance.
Access decisions and vendor access are often where governance breaks down first. We define the rules for who gets access, how it is approved, how administrators are controlled, and how suppliers, consultants, and support vendors are allowed into the environment without bypassing discipline.
Good governance becomes real when it shapes daily operations. We help teams define how incidents are escalated, how backups are checked, what gets logged, how records are classified, and how exceptions are approved so control does not depend on memory or personality.
A governance project should produce more than workshop notes. We leave clients with a practical policy and standards pack that leadership can approve, teams can operate against, and future technical work can be measured against. This is why it often becomes the starting point before deeper implementation packs.
Deliverables: Cybersecurity policy, access-control policy, backup policy, incident response policy, vendor-access policy, acceptable-use policy, records handling policy, branch office IT standards, and admin privilege standards.
Urgency: If the organisation still cannot say who owns cyber decisions, who approves risky access, or which standards teams are expected to follow, the governance gap should be closed before the next incident or audit exposes it.
Book Governance Review