Actualité _ Cyberattaques Bouygues et Air France _ comment savoir si vous êtes concernés _

Cyber risk: A test of leadership

Why South African organisations must stop treating cyber risk as a technical inconvenience.

By: Rennie Naidoo, Professor in Information Systems and Research Director at the Wits School of Business Sciences

At first glance, South African organisations appear to be modernising at an impressive pace. Cloud , hybrid work strategies,  experimentation,  (IOT) expansion, and an increasingly data-driven business culture are reshaping the corporate landscape.

But beneath this digital transformation lies a more complex story. Governance systems are not evolving quickly enough to manage the risks that come with innovation. Complexity is rising faster than control.

Interpol’s Africa Cyber Threat Assessment Report 2025 placed South Africa among the most targeted nations on the continent for ransomware. But the deeper concern is not the rise in cyber crime alone. It is the persistence of outdated thinking.

Too many business leaders still treat cyber security as a technical support function rather than an enterprise risk that requires oversight and strategic management.

That mindset is no longer sustainable.

The King IV Report on Corporate Governance emphasises that cyber risk is a governance responsibility connected to value, risk and assurance. Cyber security now belongs at the centre of business risk conversations.

If it continues to be viewed as an isolated IT problem managed through procurement or outsourced support, then no amount of spending will be enough to protect the organisation. Only through structured, transparent and accountable governance can cyber risk be managed effectively.

 
 

Shift in understanding risk

Effective cyber security risk management is not about eliminating threats. That ambition reflects a false promise that no longer fits the reality of the digital economy.

Instead, the work begins with understanding which risks actually matter, what levels of exposure can be tolerated, and how to make trade-offs between innovation, speed and control.

This process happens not on the technical fringes, but where strategy, operations and governance meet.

Emerging technologies are not simply introducing new risks. They are changing the nature of responsibility.

 

Five domains need to work together to enable sound risk decisions. These include clarity about which products and services are most critical to the business, which systems and data enable them, a realistic understanding of risk appetite, insight into the threat landscape, and clear ownership of controls and response.

 
 

The pressure on South African enterprises

The South African context brings additional urgency. Regulatory, legal and financial risks are mounting.

The Protection of Personal Information Act requires that data breaches be reported to both regulators and affected individuals. The Cyber Crimes Act formalises a range of offences that could turn routine breaches into criminal investigations.

The economic consequences of cyber incidents are also becoming more severe. IBM’s global breach reports, when applied to local conditions, show that losses can easily stretch into the tens of millions of rand.

These costs include not just recovery but legal exposure, reputational damage, customer churn and potential penalties. This makes it clear that cyber security cannot be treated as a badge of digital maturity.

 

The problem with tool-centric thinking

Many organisations believe they are secure because they have a long list of tools in place. Firewalls, endpoint protection, identity systems, e-mail security, backups and incident response plans are all well represented in corporate environments.

But attacks continue to succeed, and the reason is often not technical failure. It is because cyber security decisions are made in isolation, disconnected from the organisation’s broader strategy and risk priorities.

When controls are deployed without a clear risk rationale, three common problems emerge. The first is reactive investment. Security tools are chosen based on industry buzz or vendor influence rather than their relevance to actual threats.

The second is weak governance. Boards receive activity reports but lack visibility into posture or exposure.

The third is misplaced confidence. Dashboards show green, teams are busy, and yet the most dangerous scenarios remain untested and unresolved.

 

Building risk-led cyber security practice

To move cyber security into the realm of executive governance, organisations need a different starting point. That begins with identifying the business’s most critical assets and services. These are the systems that, if compromised, would disrupt operations immediately. They usually include customer platforms, payment services, identity infrastructure and sensitive data repositories.

From there, leadership must define what levels of risk are acceptable in concrete terms. Vague ratings like high or medium are no longer useful. Executives need to know how much downtime the organisation can afford, what level of data loss would be deemed tolerable, and what financial hit could be absorbed without significant disruption.

International frameworks such as NIST, ISO and FAIR can provide a starting point. But certification alone is not the goal. What matters is developing repeatable practices that align with the organisation’s specific context.

A dynamic risk register should be at the heart of this system. It should document risk scenarios with realistic impact narratives, provide reasoning for their likelihood, assign ownership, record associated controls and schedule reviews.

Decisions about risk treatment must also be visible and reasoned. Some risks will require active mitigation. Others may be accepted, transferred through contracts or insurance, or avoided through operational changes. What matters is that decisions are made consciously, documented properly and approved by leadership.

 

People remain most exploitable surface

Despite all the technical investment, human behaviour remains the most exploited vulnerability in the digital environment.

In 2024, Kaspersky reported tens of millions of phishing link clicks across African networks, many from inside corporate systems. This reveals that human behaviour is not a mere soft concern. It is a fundamental part of the organisation’s risk surface, as critical to security as any technical system.

When organisations treat employees as unpredictable and unchangeable, they give up the opportunity to design systems that guide and support secure behaviour. This mindset weakens overall security. Fatigue, urgency and learned responses are all known factors that attackers leverage.

Unless behavioural controls are taken seriously, technical defences will continue to be undermined from within.

 

Scenarios organisations must prepare for

Resilience is not proven by the absence of breaches. It is tested through the ability to recover from them.

Organisations should focus their preparation on the scenarios that truly threaten their continuity. These scenarios include ransomware attacks that encrypt systems while exfiltrating sensitive data, identity breaches that enable attackers to move laterally across networks, compromises of high-trust third-party suppliers, executive impersonation using deepfake audio or video, and data leaks triggered by uncontrolled AI behaviours.

These are not fringe possibilities. They are defining risks that require rehearsal, not just theoretical discussion.

 

New technologies reshape the risk landscape

Emerging technologies are not simply introducing new risks. They are changing the nature of responsibility.

AI systems may quietly expand access to personal data or make decisions that lack explainability. IOT deployments multiply entry points into environments that were never designed for cyber defence. Big data platforms can amplify the impact of a single breach. And social media can turn misinformation and impersonation into a fast-moving risk factor.

Boards and executives must begin to ask harder questions. What trade-offs are being made in the name of innovation or efficiency? Which of these trade-offs are defensible? And who will be held accountable if those decisions fail?

 

Talent as a control surface

Talent is part of frontline defence. Even the best-designed cyber security plan will fail without people who can deliver it.

South Africa’s shortage of cyber security talent remains a material constraint. While outsourcing can support execution, it cannot replace internal judgement, contextual awareness, or institutional learning.

This means that training is not a secondary concern. It is a primary control. Investing in skills directly improves the quality of decisions, the speed of response and the credibility of reporting.

The local cyber security skills gap is not just about technical expertise or executive literacy. It is about the missing link in between.

Organisations need professionals who can turn strategic direction into operational clarity. These are not necessarily the most certified individuals. They are the ones who can build risk registers that boards can understand, justify investments with clear logic and explain exposure without relying on jargon.

Without this layer, security governance remains fragmented and disconnected from enterprise priorities.

 

A closing thought

A technical breach is rarely a failure of security controls alone. More often, it is the visible symptom of deeper governance failures and business decisions that did not fully account for risk.

In the digital economy, resilience is no longer defined by the number of tools in place or the speed of compliance. It is shaped by how deliberately organisations govern risk, how consistently they oversee it, and how clearly leadership understands its role in shaping outcomes.

In South Africa’s high-risk and fast-evolving environment, the organisations most likely to succeed will be those that stop treating cyber risk as a technical issue to be delegated.

They will recognise it for what it truly is – a reflection of leadership quality, institutional accountability and the capacity to make tough decisions under pressure.

View Article Source:

Cyber risk: A test of leadership | ITWeb

600GB of Data and 308 Hrs Deadline Given Post USCS Cyberattack

Why cyber insurance claims are increasingly being rejected

Jeremy Maggs 

‘Cybersecurity insurance companies will assist you through a cyber attack, through a ransomware attack, but it does not guarantee that they will provide a payout, and that’s the misconception,’ says Muhammad Ali of WWISE.

JEREMY MAGGS: Now this is worrying. Nearly half of cyber insurance claims are now being rejected or partially denied, as insurers take a harder line on cybersecurity standards and governance.

A new global study shows many businesses are losing out because what they declared in their policies don’t actually match what is happening in the workplace when an attack occurs.

Listen/read: SA earns top spot as target for cyber attacks [2025]

I want to explore this in a little more detail. I’m in conversation with Muhammad Ali, managing director of cybersecurity and ISO specialist at World Wide Industrial & Systems Engineers (WWISE).

Muhammad, a very warm welcome. I want to start with this headline figure, 47% of claims rejected. Is this about insurers dodging payouts or companies overselling their cyber readiness?

MUHAMMAD ALI: Yeah, I think it’s a very valid question. I think it’s a combination of both factors.

Firstly, I think a lot of corporate organisations feel that they have everything in order. The IT team give them a report, and the top management or the board are all comfortable in terms of what’s going on.

Very little investment is taken into cybersecurity and protecting their privacy and information, personal information as well as their data.

Sometimes I feel like people consider cybersecurity as a cost, as opposed to an investment. In today’s time, it’s about when am I getting attacked, as opposed to if.

You need to know that you are going to go through an attack. Now, there are multiple factors where organisations have misinterpretation of their security controls.

Maybe they have policies that are well written, but it does not talk to what’s actually on the ground. Or perhaps they have very incorrect policies or outdated policies that are in place.

Read: IT consultants also need business interruption insurance [2024]

Now, when a cyber insurance company comes in and let’s look at it from their point of view, and you’re perhaps paying a premium. They’ve done an assessment and analysis. They actually look at all of these things. They look at your misrepresented controls, weak governance, outdated practices.

The assumption is that I’m going to get a payout because I’ve got a cybersecurity insurance that’s going on. That’s not the case, due to noncompliance businesses are exposing themselves without investing and following the actual protocols within their policies. So it’s a factor of both.

JEREMY MAGGS: What you’re suggesting to me is that buying cyber insurance these days is not a cyber strategy.

MUHAMMAD ALI: Not at all. I think cybersecurity is in the top ten risks in most corporate blue-chip companies; and thinking that cyber insurance is going to protect them and their assets, it’s a misconception.

Cybersecurity insurance companies will assist you through a cyber attack, through a ransomware attack, but it does not guarantee that they will provide a payout, and that’s the misconception.

Read: SA businesses vulnerable to cyberattacks [2024]

That is totally due to the fact that the organisation themselves have not read the terms and conditions and been able to fulfil their side of the things, which is actually good governance when it comes to cybersecurity.

They are negligent and they are unfortunately not following the basic parameters of what cybersecurity is all about.

JEREMY MAGGS: Let me throw another big number at you. Ransom demands in South Africa have jumped to around R17 million. At that level, is cyber insurance still affordable or, Muhammad, even viable at this point?

MUHAMMAD ALIYeah, it would depend. I think there are multiple factors. If you look at denial of service, I think that is perhaps one of the key factors. If a cyber attack occurs with ransomware coming in, they can deny you from operating. So your production or operations may stop.

Now, depending on the number of days you are basically stationary, this can result in millions and millions of dollars, aside from the reputational damage.

If you are listed to a to a stock market, then you have to – whether you are attacked or non-attacked – you have to inform the regulator of the attack, because that’s law. This can have significant reputational damage. I think you need to weigh up the investment and the return thereof.

If you are paying a significant amount on cyber insurance and you need to look at the attack or the downtime that it can have, the impact it can have to your processes, your systems, your applications, your users, the data in itself, whether there’s sensitive information and the regulator getting involved.

It’s a catch-22, so I think it’s a good assessment to make to be able to determine whether the premiums you’re paying are actually worthwhile. But there are ways of reducing these premiums.

JEREMY MAGGS: Another trend is a move away from the annual audit to continuous assurance. I understand what you’re saying, but I would also ask whether most South African firms are technically capable of that shift.

MUHAMMAD ALI: Right now, as it stands, we do have a lack of skills, and we do have a lack of practical skills, I think that’s the key word.

A lot of people grow within the ranks quite quickly and they get into a leadership role, a management role, and there’s nothing wrong with that, but the technical ability of being able to read firewall rules, to be able to understand the network security parameters and be able to understand the default settings, are not your golden or silver bullet.

Listen: Insurance trends: Storm-proofing your business

You need to be able to be technically inclined to understand what types of threats there are, what types of vulnerabilities there are, and not only just keeping the basics of awareness throughout the users up to date, but it’s about keeping your systems and applications up to date.

I think there is a gap in South Africa when it comes to that understanding.

This is why we are where we are in South Africa when we are sitting ducks, if you want to call it that, because ransomware attackers or cybersecurity attackers, you will see around the world, look at South Africa from the healthcare perspective, from a banking perspective, or just from an industry perspective.

Listen/read: AI-powered scams target SA banks, insurers and retailers

They see that we’re negligent or we do not have the necessary skills, so we become a threat or an easy target. I think we still need to educate ourselves and get the right skills and stop fooling ourselves by misinterpreting that we do know what’s going on.

JEREMY MAGGS: All right. Just a quick answer, as we come to the end of this conversation. If a chief executive officer or chief information officer is listening to this conversation and wants to avoid becoming part of that 40% that I mentioned at the beginning, what’s the one control then they need to get right immediately?

MUHAMMAD ALI: I think it’s very important to align yourself to an internationally best practice standard. That’s the first thing.

Now, with your insurance firm, they don’t declare this out to you, but whether it’s ISO 27001 or a Nist (National Institute of Standards and Technology) framework, if you align yourselves to that particular standard by effectively implementing the controls – and I recommend ISO 27 because you can get an independent, impartial, accredited certification that is recognised around the world – it helps you reduce your cyber insurance premiums drastically, sometimes up to 50%.

More so that standard with your annual external audits and your rigorous internal audit controls, you will see that the awareness of users is going to improve because you are communicating the content of policies, and the actual policies that are embedded on your applications for security parameters are more understood.

Read: Sarb bolsters defences against cyberattacks [2025]

Not only are you improving the posture of the organisation, but enhancing the individual in the organisation for their practicality in the real world so they don’t become a victim of credit card fraud or a cyber attack. I would suggest that would be your go-to standard as a CEO or an executive.

JEREMY MAGGS: Thank you very much indeed, Muhammad Ali, managing director of cybersecurity and ISO specialist at WWISE, enjoy talking to you. Appreciate your time.

View Article source:

Why cyber insurance claims are increasingly being rejected – Moneyweb

IMG-20240925-WA0022

Why cybersecurity awareness is failing South African businesses and what to fix first

Why cybersecurity awareness is failing South African businesses and what to fix first

Charmé van der Westhuizen, New Business Development Manager at IPT

South African businesses are investing heavily in cybersecurity technology. Detection tools are becoming more sophisticated, monitoring is more advanced, and response capabilities are faster. Yet most breaches still begin with a human error. This shows that technology is not the problem. Instead, it is how cybersecurity is approached.

For many businesses, cybersecurity awareness remains a compliance activity rather than a risk discipline. Training is scheduled annually, attendance is recorded, and certificates are issued. From a governance perspective, the requirement has been met. From a risk perspective, little has changed.

Not a one-off event

In practice, behaviour is shaped by what is reinforced, not what is presented once a year. When training is concentrated into a single intensive session, it competes with operational pressures and fades quickly out of memory. The reality of South African business environments is that teams are stretched, inboxes are full, and urgency is constant. Under those conditions, knowledge without reinforcement does not stick.

If we accept that human behaviour remains the entry point for most cyber incidents, then awareness cannot sit on the periphery of the security strategy; it must be embedded in business operations.

Thinking differently

The first issue to fix is cadence. Short, consistent training delivered over time improves employee skills much more effectively than infrequent, high-intensity workshops. This is not because the content is different, but rather because repetition alters how employees respond to cyberattacks. When people are exposed more frequently to common threat scenarios, they can better identify any potential attack.

The second issue is relevance. Many organisations roll out uniform training across the entire business. That approach assumes that all employees experience the same risk exposure. In reality, risk varies by department. Finance teams face different attack patterns from sales teams. HR manages different types of sensitive information from operations. When awareness programmes fail to reflect those realities, they lose credibility.

Cybersecurity is often described as an IT responsibility. It is not. It is behavioural risk management embedded across departments. If awareness is not tailored to role-based exposure, engagement drops and risk remains unevenly distributed.

The third issue is measurement. Awareness programmes frequently rely on completion metrics rather than behavioural indicators. Attendance does not equal building a resilient organisation. A signed acknowledgement does not demonstrate that a company has now improved its cyber defences.

Identifying threats

When organisations assess behavioural vulnerabilities at the outset, they gain visibility into actual exposure. Automation can then deliver targeted reinforcement at regular intervals, addressing identified weak points rather than rotating generic topics. Over time, this produces measurable improvement instead of superficial coverage.

Automation, in this context, is not about sophistication for its own sake. It is about consistency and accountability. It ensures that awareness is not dependent on manual scheduling or shifting priorities. Weaknesses are identified, addressed, and re-evaluated systematically.

Without that structure, awareness remains reactive.

More than compliance

South African businesses operate in a regulatory and economic environment where reputational damage and operational disruption carry significant consequences. Clients, partners, and regulators increasingly expect demonstrable risk management, not theoretical commitment.

The uncomfortable reality is that many companies are investing more in detecting breaches than in preventing the human actions that trigger them.

Fixing cybersecurity awareness does not require a new platform as a starting point. It requires reframing awareness as an ongoing behavioural discipline supported by structured reinforcement, role-based relevance, and measurable improvement.

Technology will always be essential. But until awareness is integrated into operational processes and treated as a governed risk control, the human layer will remain inconsistently defended.

The number of tools deployed does not define cybersecurity maturity. It is reflected in how people behave under pressure. That is where the real work begins.

Article by:CBN 

View Article source:

Why cybersecurity awareness is failing South African businesses and what to fix first