Independent investigation, assurance & risk consultancy · Africa

Find the facts.Secure what follows.

Investigations, digital forensics, cybersecurity, ICT audit, data analytics, risk advisory and monitoring solutions that help organisations act on clear evidence.

Since 2019Independent professional services
Southern AfricaResponsive regional presence
Cross-disciplinaryForensics, cyber, audit, data, risk & training
ReliableClear work that can be traced and checked

Evidence in motion

From uncertainty to a clear decision.

Investigation, technology and oversight work together as one connected service.

A fingerprint interface illustrating the preservation of digital evidence01

Establish the evidence

Protect the evidence, rebuild the sequence of events and separate facts from noise.

Cybersecurity practitioners monitoring organisational exposure02

See the exposure

Make technical risk clear before it harms daily operations.

Risk advisers translating evidence into a confident decision03

Act with confidence

Turn complex warning signs into clear priorities for leaders.

Connected response model

Each stage strengthens the next.

01

Signal

A report, unusual event, incident or control concern.

02

Evidence

Protected information that has been checked and confirmed.

03

Decision

A clear conclusion, supported by evidence, with named owners.

04

Resilience

Fixes, monitoring and stronger skills.

Our expertise

One partner from first concern to final action.

From the first sign of misconduct to stronger systems and better-prepared teams, SIFTCON brings evidence, security and oversight together.

01Forensic investigationsCommercial forensics · Litigation support · Court-ready reportingIndependent investigations into fraud, corruption, misconduct, financial abuse and whistle-blower reports.
What you gain

Find out what happened, how it happened, who was involved and what harm was caused. We follow the evidence and avoid guesswork.

Core capabilities
  • Fraud, corruption and financial misconduct investigations
  • Whistle-blower and protected disclosure matters
  • Payroll, claims, vendor and conflict-of-interest reviews
  • Disciplinary, civil, criminal and litigation support
02Digital forensics & responseEvidence preservation · Timeline reconstruction · Root cause analysisFast support for cyber incidents. We examine devices, systems, email, logs and other digital records.
What you gain

Build a verified timeline, understand the impact and plan a safe recovery based on evidence.

Core capabilities
  • Computer, laptop and mobile-device forensics
  • Email, communication, log and user-activity analysis
  • Data recovery and examination of deleted files
  • Insider-threat, data-leakage and breach investigations
03Cybersecurity assurancePenetration testing · Vulnerability assessments · Security reviewsPractical security checks that find weaknesses early and turn technical findings into clear actions.
What you gain

See where your organisation is at risk, which weaknesses matter most and what to fix first.

Core capabilities
  • Vulnerability assessments and penetration testing
  • Application, infrastructure and configuration reviews
  • Attack-surface and control-effectiveness assessments
  • Clear fix priorities and follow-up checks
04ICT audit & data analysisICT audits · Control reviews · Data-led anomaly detectionIndependent checks of systems, controls and large data sets, written for leaders and oversight teams.
What you gain

Turn complex systems and large records into clear findings, tracked exceptions and useful reports.

Core capabilities
  • ICT governance, general controls and systems audits
  • Data interrogation and anomaly detection
  • Process, access and control-effectiveness reviews
  • Audit-ready findings and executive reporting
05Risk & probity advisoryProbity audits · Risk advisory · Governance supportIndependent review of procurement, oversight and high-risk decisions where openness is essential.
What you gain

Build trust in sensitive processes through independent review, clear reasoning and reliable records.

Core capabilities
  • Procurement and tender probity reviews
  • Governance, compliance and regulatory assessments
  • Operational and enterprise risk advisory
  • Independent oversight for high-risk decisions

When to call us

Call us when you need clear facts.

01

An allegation has surfaced

Agree on what must be investigated, protect the evidence and find the facts.

↗
02

A system has been compromised

Stop further harm, find out what happened and plan a safe recovery.

↗
03

Leadership needs assurance

Turn technical and business risks into clear decisions for the board.

↗

How we work

A clear, carefulprocess.

Our five-step process keeps the purpose, evidence, quality and responsibilities clear from the first call to the final action.

01

Initial Consultation

We listen to your concern, learn what you need and agree on the first steps.

02

Engagement Design

We agree on the purpose, scope, legal needs, roles, evidence and reporting dates.

03

Evidence & Analysis

We protect and examine the right records, systems and files. We confirm important facts with more than one source.

04

Findings & Validation

We check early findings, close important gaps and explain what the evidence does and does not show.

05

Reporting & Action

Leaders receive clear findings, practical priorities and a plan for action.

“We do not sensationalise findings. We present facts, analysis and conclusions that decision-makers can rely on.”

About SIFTCON

Independent advice when the stakes are high.

SIFTCON Forensic Services is an African professional services firm established in 2019. We help organisations establish facts, strengthen security and improve oversight through careful work based on evidence.

Our name comes from “sift”: to examine information carefully and separate facts from assumptions. This guides every investigation, security check, audit and advisory project.

IntegrityConfidentialityIndependenceAccountability

Who we work with

  • Government departments & public institutions
  • State-owned enterprises & agencies
  • Financial services & regulated industries
  • Healthcare, energy & infrastructure
  • Private-sector organisations
  • Regulators & oversight bodies

Regional presence

Johannesburg · East London · HarareVirtual coverage in Zambia, Botswana and Mozambique

Current company profile

Find the facts.Secure what follows.

Download the current SIFTCON company profile.

Current published versionVersion 1.021 June 2026 · 7.2 MB
Download company profile

Our clients

Trusted organisations.Shared standards.

Some of the public institutions, regulators, businesses and regional organisations we have supported.

GAAL logo
GAAL
ARIPO logo
ARIPO
Department of Basic Education logo
Department of Basic Education
Eastern Cape Provincial Treasury logo
Eastern Cape Provincial Treasury
Office of Health Standards Compliance logo
Office of Health Standards Compliance
NHBRC logo
NHBRC
City of Tshwane logo
City of Tshwane
Cure Chem logo
Cure Chem
Gambling Authority logo
Gambling Authority
Tshwane Economic Development Agency logo
Tshwane Economic Development Agency
Sesfikile Capital logo
Sesfikile Capital

Institutions & partners

Professional networks.Technology alliances.

Professional bodies and technology companies in SIFTCON's wider network.

South African Institute of Chartered Accountants logo
South African Institute of Chartered Accountants
The Institute of Internal Auditors logo
The Institute of Internal Auditors
EC-Council logo
EC-Council
Institute of Commercial Forensic Practitioners logo
Institute of Commercial Forensic Practitioners
Institute of Information Technology Professionals South Africa logo
Institute of Information Technology Professionals South Africa
Sophos logo
Sophos
Kaspersky logo
Kaspersky
Association of Certified Fraud Examiners logo
Association of Certified Fraud Examiners
eScan logo
eScan
Chartered Institute for Business Accountants logo
Chartered Institute for Business Accountants
Institute of Risk Management South Africa logo
Institute of Risk Management South Africa
McAfee Institute logo
McAfee Institute
Teramind logo
Teramind

The SIFTCON difference

Careful work.Clear decisions.

01

Independent by design

Our findings and advice can stand up to close review. We remain separate from the decisions we support.

02

Led by evidence

Our findings are factual and easy to trace. We clearly state what is known, what is likely and what is still unclear.

03

Connected services

Investigation, cybersecurity, audit, data, risk and training work together as one response.

04

Clear accountability

We turn complex work into clear priorities that leaders can own and act on.

02

SIFTCON Academy

Practical training

Build the skills to respond.

Practical cybersecurity, digital forensics and incident response training made by working professionals. Choose technical courses, short briefings for leaders or training made for your team.

Hands-on technical programmesExecutive & board briefingsCustom in-house training
Visit SIFTCON Academy

Confidential enquiries

When the facts matter, start here.

Tell us what you are facing. We will help you identify the right first step with discretion and professional care.

Confidential enquiryWhatsApp us
WhatsApp