SOC status: Operational/Continuous monitoring active

Acronis MDR / XDR available +230 5254 7558

Home/Compliance

Regulatory alignment

Compliance & regulatory readiness

Security controls that exist but cannot be evidenced fail audits just as thoroughly as controls that do not exist. We design the evidence trail into the deployment.

Mauritius

The local obligations

Mauritius

Data Protection Act 2017

Obligations on controllers and processors covering lawful basis, security of processing, breach notification and cross-border transfer.

  • Records of processing and lawful basis mapping
  • Technical and organisational measures evidenced, not asserted
  • 72-hour breach notification workflow with a named owner
  • Consent capture stored with text and timestamp
  • Processor agreements with your own suppliers

Mauritius

Cybersecurity & Cybercrime Act 2021

Offences, investigatory powers and expectations on organisations to handle incidents and preserve evidence properly.

  • Incident handling procedure with defined escalation
  • Evidence preservation to an admissible standard
  • Log retention sufficient to reconstruct an incident
  • Reporting lines agreed before an incident, not during

Regulated financial institutions

Bank of Mauritius guideline on cyber risk

Board-level accountability, risk assessment cadence, third-party risk and tested recovery capability.

  • Board-reportable risk register with cyber entries
  • Independent assessment on a defined cycle
  • Third-party and outsourcing risk assessment
  • Tested business continuity and recovery, with results

Global business and financial services licensees

FSC Mauritius expectations

Client data segregation, operational resilience and demonstrable oversight of outsourced technology.

  • Per-client data segregation and access control
  • Outsourcing oversight with defined KPIs
  • Resilience testing evidence
  • Retention aligned to licence conditions

International

Frameworks that follow your clients

Framework Applies when What we contribute
EU GDPR Where you process EU resident data or serve EU clients Article 32 security of processing, breach notification, transfer mechanisms
PCI DSS Any cardholder data environment Segmentation, logging, patching cadence, quarterly scanning
HIPAA Health data, or serving US healthcare counterparties Administrative, physical and technical safeguards; audit controls
ISO/IEC 27001 Where clients or tenders require a recognised framework Annex A control mapping; we align, we do not certify
NIST CSF As a common language for board reporting Identify, Protect, Detect, Respond, Recover scoring

Our approach

Evidence as a by-product, not a project

Compliance work fails when it is a separate annual exercise run by people who did not build the controls. We generate the artefacts as part of normal operation, so an audit request is a retrieval task rather than a fire drill.

  • Control-to-obligation mapping produced during onboarding and maintained after
  • Automated patch, backup verification and coverage reports retained on a schedule
  • Incident records written to a standard that satisfies both regulator and insurer
  • Annual review against changes in local law and guideline
  • Support during audits, inspections and client due diligence exercises

A necessary caveat. This page is a general orientation to obligations we commonly encounter, not legal advice. Applicability, thresholds and timelines depend on your specific circumstances, and the law changes. Take advice from a qualified legal practitioner on what applies to you — we work alongside your counsel rather than in place of them.

Where we stop

We are Solutions Specialists and analysts. We implement and evidence technical and organisational controls, and we support you through audits. We do not issue certifications, act as your external auditor, or provide legal opinions on regulatory interpretation.

Get in touch

Have a deadline?

Client mandate, regulator inspection or insurance renewal — tell us the date and we will work back from it.