Case Study

Virtual Desktops and POPIA Compliance for an Education Provider

A South African private education provider running shared computer labs across multiple campuses struggled to keep learner devices consistent, secure and compliant. OAS delivered virtual desktops so every workstation booted to a clean, managed session, and layered SentinelOne, centralised logging and immutable backup to build a POPIA-aligned posture around sensitive learner data.

Note: This case study is illustrative. Client details are anonymised and figures are representative of typical OAS engagements.

The challenge

A private education provider operating several campuses across South Africa relied on shared computer labs used by hundreds of learners each day. The model created persistent problems. Every shared workstation drifted out of configuration — different software versions, leftover files, inconsistent updates — and each was a potential foothold for malware spread by an infected USB drive or a careless download.

Underlying it all was sensitive personal information. The provider held learner records, identity numbers, assessment results and guardian contact details — exactly the kind of data the Protection of Personal Information Act (POPIA) requires organisations to protect with appropriate safeguards. Yet the provider had limited visibility into who accessed what, no consistent endpoint protection, and backups that had never been properly tested.

A small IT team, stretched across multiple sites, simply could not keep hundreds of individually-managed lab machines patched, clean and compliant by hand.

The approach

OAS proposed shifting the labs from individually-managed PCs to virtual desktops. Instead of each workstation holding its own software and data, every machine now boots into a clean, centrally-managed desktop session delivered from the data centre. When a session ends, it resets — no leftover files, no configuration drift, no malware persisting from one user to the next.

This single change transformed manageability. The IT team maintains one master image rather than hundreds of machines, and a lab full of mixed hardware presents learners with an identical, current environment every time. Learner data stays in the data centre rather than scattered across lab drives, which directly supports POPIA's principles of controlled access and minimised data sprawl.

OAS layered the broader Protect, Detect, Recover discipline over the top. SentinelOne behavioural-AI endpoint protection was deployed across the estate, autonomously containing threats such as USB-borne malware before they could spread between labs. Centralised log management gave the provider, for the first time, an audit trail of access across campuses — the kind of evidence the Information Regulator expects. Cove Data Protection provided immutable, off-network backup of learner records and systems, with automated recovery testing to confirm the data was genuinely restorable.

The outcome

Shared labs moved to clean, managed virtual desktop sessions

, ending configuration drift and persistent malware

One master image to maintain

instead of hundreds of individual machines, freeing a stretched IT team

Learner personal information kept in the data centre

, supporting POPIA's access-control and data-minimisation principles

Autonomous endpoint protection

containing USB-borne and download-borne threats before they spread between campuses

Centralised access logging and immutable, tested backups

, giving the provider auditable evidence of its security safeguards

The provider now runs the environment under an ongoing managed service. OAS handles image management, monitoring, patching and backup verification across campuses, giving leadership confidence that learner data is protected and that the organisation can demonstrate its compliance posture when asked.

Ready to strengthen your defences?

Book a no-obligation security assessment. We'll map your gaps across Protect, Detect and Recover — and show you exactly where you stand.