Cyber Security Act 2021 Compliance

Secure Hosting, Email & Domain Protection

Barakat helps public-facing organisations harden servers and hosted workloads, secure business and executive email, lock down registrar and domain control, and reduce impersonation exposure in a way that supports the control expectations reflected across Sections 35, 40, 42, 43, 45, and 54 of Sierra Leone's Cyber Security and Crime Act, 2021.

Digital estate control, brought together

For organisations relying on websites, domains, mailboxes, hosted applications, SSL certificates, and vendor-managed infrastructure, risk often builds in the gaps between those systems. This engagement brings the critical controls together so public identity, hosted services, backups, and admin ownership stop depending on scattered accounts and undocumented habits.

Legal anchor

Section 35 of Sierra Leone's Cyber Security and Crime Act, 2021 addresses unauthorised interception of non-public data transmissions, which makes remote administration discipline, TLS, secure email transport, and tighter hosting controls commercially important. Section 54 also matters where service providers or vendors misuse privileged access or consumer security codes, which is why ownership, provider access, and admin control need to be documented and constrained.

Section 45 addresses unauthorised use of names, trademarks, and domain names in ways that interfere with the rightful owner, while Section 42 addresses fraudulent use of another person's electronic signature, password, or other unique identifier and also covers impersonation for gain or disadvantage. Section 40 addresses computer-related forgery, and Section 43 addresses electronic signature or company-mandate forgery. In practice, strong domain control, mail authentication, executive mailbox protection, hosting hardening, and public-exposure review reduce the opportunity for those risks to succeed.

Best for

Banks NGOs Ministries Law Firms Hospitals Schools SMEs SaaS Operators Public-Facing Organisations

Best suited to organisations that run public websites, business email, hosted applications, donor or payment communications, or other trusted online services and cannot afford weak domain ownership, mailbox abuse, spoofing, or hosting outages.

Deliverables

  • Domain security audit
  • Hardened VPS or server
  • Secure business email setup
  • DNS mail-authentication deployment
  • Public-domain inventory
  • Backup and restore plan
  • Admin access register
  • Anti-impersonation recommendations
  • Monthly managed hosting and security plan

Control focus

  • Registrar and DNS ownership clarity with reduced admin exposure
  • Hardened hosting, remote administration, SSL, and patch discipline
  • SPF, DKIM, DMARC, MFA, and stronger executive mailbox protection
  • Backups, public-domain review, lookalike monitoring, and documented ownership of critical access
Domain Control

Secure the registrar, DNS, and public identity before someone else abuses them

A strong hosting environment can still be undermined if registrar access is weak, domain ownership is unclear, or public records have been left to drift across old vendors and personal inboxes. We start by locking down the organisation's public identity and reducing the openings that make spoofing and lookalike abuse easier.

Review domain ownership records, registrar access, recovery contacts, and DNS administration rights so the organisation knows exactly who controls its public identity
Audit public-facing subdomains, DNS records, certificates, and SSL configuration so exposed services and trust signals can be cleaned up before they are abused
Review lookalike and typo-squatted domain exposure and help define how suspicious new registrations should be noticed, escalated, and handled
Placeholder illustration for domain ownership, DNS governance, and public identity control
Hosting Hardening

Harden servers and hosted services before weak administration becomes the entry point

Whether the organisation runs a VPS, dedicated server, or hosted application stack, exposed administration paths and weak patching routines create unnecessary risk. We harden the environment so remote access, public services, and underlying workloads sit on a cleaner and more defensible baseline.

Provision or review the VPS or dedicated server and harden SSH and RDP access so administrative exposure is reduced from the start
Disable password-only login where appropriate, configure firewalls, enable SSL or TLS, and set practical patching routines that do not depend on memory
Separate web, application, and database workloads where needed and document provider and admin responsibilities so hosting control survives staff or vendor changes
Placeholder illustration for VPS, server, and hosting hardening
Email Protection

Make business email harder to spoof, misuse, or turn into false instructions

Email still carries approvals, donor requests, contracts, payment instructions, and other messages that can be abused when identity controls are weak. We protect the domain and the mailboxes that matter most so legitimate communication is more trustworthy and impersonation has fewer easy openings.

Set up or review mailboxes on the business domain with strong passwords, MFA, and cleaner mailbox ownership so critical email does not depend on weak or shared access
Deploy SPF, DKIM, and DMARC and tighten aliases, shared inboxes, and executive accounts so the domain is harder to impersonate and easier to govern
Review spoofing opportunities around display names, reply paths, delegated access, and high-trust accounts that could be abused for false approvals or fraudulent instructions
Placeholder illustration for secure business email, mail authentication, and executive account protection
Continuity & Oversight

Back up the environment properly and document who still controls what

Hosting and domain problems become full crises when backups have never been restored, SSL renewal is tied to a forgotten mailbox, or no one can say who still holds admin access. We close those operational gaps so the organisation can recover faster and retain control of its own digital estate.

Verify that backups exist for websites, email, servers, and supporting systems and confirm restore capability so resilience is tested rather than assumed
Document domain control, SSL renewal ownership, hosting access, and administrative rights in an access register that management can actually review
Leave the organisation with a public-domain inventory, backup and restore plan, anti-impersonation recommendations, and a managed review path so controls do not drift after the first hardening pass

Deliverables: Domain security audit, hardened VPS or server, secure business email setup, DNS mail-authentication deployment, public-domain inventory, backup and restore plan, admin access register, anti-impersonation recommendations, and a monthly managed hosting and security plan.

Urgency: If domain ownership, business email, hosted services, or SSL renewal are still weakly controlled, the organisation is carrying an avoidable exposure that can quickly turn into downtime, impersonation, or loss of operational control.

Book Hosting, Email & Domain Review
Placeholder illustration for backup planning, admin ownership, and managed hosting oversight

If domains, hosting, and email are not controlled together, trust is easier to break than it should be

We can lock down the registrar, harden the servers, secure the email domain, verify recovery, and document ownership before impersonation or downtime turns weak control into a public problem.

Request a Compliance Review