Black Cygnet Group, Technology Operations 1 July to 30 September 2026 Prepared by Stan Naidoo

Q3 2026
in review

123,543 emails in 89 daysEvery day of the quarter through Mimecast. Weekdays run near 1,900; weekends fall below 300.
Hover or tap a day

The quarter at a glance

Demand on the helpdesk held steady while resolutions slipped, so the backlog grew, though September finally closed more than it opened. Email threats returned to normal after the Q2 flood, but phishing is climbing.

71 unresolved tickets

Up 42% on Q2. The backlog peaked at 106 in July, then September closed more tickets than it opened.

48% of tickets were QContact

Up from about 35% in Q1, driven by Keveko moving onto the BCL instance, CLI spam-flagging and lead routing.

Helpdesk

549 tickets across the Bugs and IT Support groups, and 530 resolved in the period. Reopens halved to 24, which suggests fixes are holding. The backlog ended the quarter at 71, up 42% on Q2, but the trend turned: September was the only month to close more tickets than it opened.

Tickets by month

Unresolved is the open backlog at month end.

JulyAugustSeptember
Created Resolved Unresolved

Against Q2

Created549−3.4%
Resolved530−12.8%
Unresolved71+42%
Reopened24−51%

Live check on 30 September: 46 open tickets were past their due date, 5 were unassigned, and three IT Support tickets had been waiting since mid-August. No tickets are marked high or urgent, so priority isn't yet being used to triage.

Emails sent to both bugs@ and support@ create a ticket in each group, so volumes are slightly inflated. The new four-channel routing model should fix this.

What the tickets were about

Share of Q3 tickets. The dark marker shows Q1's average share.

What kept coming back

  • CLI spam-flaggingOutbound numbers flagged as spam by caller-ID apps, forcing frequent number changes.
  • Dispositions and do-not-call requestsA steady stream of changes, much of it relayed from lead-provider partners.
  • Lead allocationLeads not reaching agents, or shared between them, after queue changes.
  • QContact call audioClients unable to hear agents; daily workarounds while a root-cause fix was requested.
  • Keveko's move to the BCL instanceProfile defaults, disposition sets and WhatsApp delivery failures after the migration.
  • Mailboxes, licences and attachment blocksNew-agent mailboxes, shared access, and Mimecast blocking legitimate .ODS reports.

Email security

Mimecast handled 123,543 emails and rejected 10,781 at the gateway. Rejection rates are back in their usual 12 to 18% band after the May–June surge. Threats that did get inspected are rising, led by phishing.

8.7% of mail rejected

10,781 rejections, back to normal after May and June, when over 90% of inbound mail was refused.

Why mail got rejected

Share of the quarter's rejections, by reason.

Mostly sender reputation and authentication checks rather than content; spam and virus signatures together are under 5%.

Share of inbound mail rejected, last 12 months

May and June 2026 saw about 371,000 messages rejected while legitimate mail stayed normal. Q3 months are shown in blue.

Threats blocked, June to September

1,820 blocked in July, August and September combined.

Phishing
295
JunJulAugSep
Credential harvesting
9
JunJulAugSep
Malware
3
JunJulAugSep

Credential harvesting rose to 27 in August before dropping back to 9 in September. Phishing detections jumped from 31 in August to 295 in September.

Detections per user

August's 0.99 is the highest since June 2025, yet still well below the South African and finance-industry averages of around 5.

The human risk score is rated Very Low but reached 0.11 in August, its highest in 12 months. Mimecast notes it lacks training and simulated-phishing data, and Business Email Compromise protection isn't subscribed.

Mail by recipient domain

28 June to 27 September, 126,838 emails. Keveko's share rose from 14.6% in Q2 as its staff moved onto BCL systems.

Looking back, looking ahead

Our online and email security controls performed effectively throughout the quarter. During the May-June threat surge and again on 29 July, our security gateway successfully blocked all unauthorized activity, with no security incidents resulting from these events. Uptime remained stable across all core systems, and all endpoint-related issues were resolved.

Looking ahead, our priority is to strengthen the human element of cybersecurity through targeted security awareness training while further leveraging Microsoft's security ecosystem and platform enhancements to address potential vulnerabilities and reinforce our overall security posture.

Virus protection

ESET blocked or cleaned 223 detections across 33 computers this quarter, and every one was resolved. Most were risky websites stopped before they loaded. Detections fell every month, from 145 in July to 26 in September.

223detections blocked or cleaned
100%resolved
48viruses and unwanted apps removed
79computers managed by ESET

What ESET stopped

Websites blocked for phishing or unwanted software Trojans and unwanted programs cleaned from disk Firewall blocks of network scans and address conflicts

From the ESET PROTECT detections report for 1 July to 30 September 2026. The 12 open incidents were reviewed and resolved on 30 September.

System uptime

All eight core systems met the 99.5% target. The other six ran at 100% with no outages. QContact reached 99.86% after about 3 hours of downtime, and the SafriCloud voice carrier service was the weakest at 99.77%, with about 5 hours down across the quarter.

Internet, primary lineFibre, ISP
100%
No outages recorded
Core networkLAN and switching
100%
No outages recorded
WANInter-site links
100%
No outages recorded
Microsoft 365Email, Teams, SharePoint
100%
No outages recorded
FreshdeskHelpdesk
100%
No outages recorded
QContactContact centre
99.86%
Cumulative downtime amounted to roughly 3 hours
SafriCloud voice carrierVoice carrier service
99.77%
About 5h downtime in total
Internet, backup lineFailover link
100%
No outages recorded
99.0%99.5% target100%

Projects

Keveko's move to the BCL QContact platform, the CLI Manager rollout and the Truecaller upgrade were all completed this quarter. Seven more pieces of work are in flight, most of them automating how we reach clients and handle requests.

ProjectOwnerStatusNotes
QContact migration, Keveko to BCLTech teamCompletedKeveko moved onto the BCL QContact instance.
CLI Manager implementationSafriCloudCompletedProof of concept, now in its second month live and showing strong results.
Truecaller Business, upgraded to EnterpriseStanCompletedKey strategic partner for cold-calling credibility and multi-channel servicing.
Truecaller optimisation, phase 2Jacqui, Raksha and StanIn progressWorking with the success team to use Truecaller more strategically.
Infrastructure and security reviewWill, Stan and GQIn progressReviewing infrastructure, security tooling and licensing; moving toward one Microsoft-managed security ecosystem.
Microsoft license audit and reviewWill, Stan and GQIn progressAuditing current Microsoft licensing against actual usage to right-size spend.
Q Contact WhatsApp initiativesTech teamIn progressRetentions debit-order notifications, cover upsell and MultiNet bond follow-up. Target end of October.
Contactability and Preview DiallerJacqui, Raksha and SafriCloudPilotEfforts are underway to improve inbound IVR performance and outbound answer rates. The Preview Dialler pilot has been successfully launched on the XDS campaign, with a phased rollout planned for all agents across all campaigns. Jacqui and Raksha are working with the SafriCloud team to ensure milestones are met.
Tech Ops request routingStanIn progressFour channels for bugs, support, features and projects, with a reset Trello board.
X-Plan integration into QContactKim, Will and StanIn progressEfforts are also underway to integrate X-Plan with QContact in this next quarter.