IMG-20240925-WA0023

SA is Africa’s cybercrime epicentre

By: Thobeka Ngema

South Africa has become the continent’s epicentre for cybercriminal activity, according to Interpol’s latest African Cyberthreat Assessment Report.

While the report highlights alarming statistics, such as South Africa accounting for 92% of all ransomware detections in Africa, industry experts warn that the true crisis lies not just in the frequency of attacks, but in a systemic failure to defend against them.

“South Africa accounted for 92% of all ransomware detections in Africa by TrendAI, with incidents affecting critical infrastructure such as the South African Weather Service, South African Airways, and Namibia’s Paratus Telecom,” the report read.

It said that regarding Distributed Denial-of-Service (DDoS) attacks, South Africa alone recorded 213 523 attacks, a single incident reaching 312 Gbps – dwarfing all other regions.

Moreover, phishing was rampant, with South Africa accounting for almost 40% of all African phishing detections, followed by Mauritius at 22%, according to SOCRadar.

The report said that despite mature regulatory frameworks like South Africa’s Cybersecurity Act and Mauritius’ Digital Transformation Blueprint, the region remains vulnerable to AI-enabled threats. Trends like Zambian scam centres and South African deepfake-sextortion highlight how advanced infrastructure often coexists with systemic exploitation.

“South Africa accounted for 92% of all ransomware detections in Africa, according to TrendAI data,” the report read.

In 2025, TrendAI data indicated that 70% of Business E-mail Compromise detections originated in South Africa and 29% from Nigeria. TrendAI also recorded 600 000 sextortion detections in Africa in 2025, with the majority originating from South Africa (30%), Kenya (13%), Côte d’Ivoire (11%), Ethiopia (8%), and Angola (4%).

Additionally, the Shadowserver Foundation identified more than 6 000 exploitable vulnerabilities across Africa in 2025, with the highest concentrations in South Africa (43.6%), Kenya, and Nigeria, the same countries with the largest internet user bases.

Specialist investigator Anthony Boucher said: “South Africa is ground zero for cybercrime in Africa. 92% of ransomware attacks? That’s not a statistic – that’s a crisis. We’re the most connected country on the continent, and we’ve basically rolled out the red carpet for criminals.”

Boucher said the 43% vulnerability figure tells him the country is not even doing the basics. Unpatched systems are being exploited.

He said the AI part is most shocking. Criminals are using deepfakes and automated attacks, while South African investigators lack the skills to spot it.

“The SA Weather Service attack should have been a wake-up call. They disrupted aviation systems – not for money, but for chaos,” said Boucher, who is the Mike Bolhuis’ Specialised Security Services, Cybercrimes Division national head.

He said that while good laws exist on paper, implementation is almost non-existent.

“Our police don’t have the tools or training. Some stations don’t even have working computers. How do you investigate a digital crime without digital forensics?” Boucher asked.

He said criminals exploit the lack of 24/7 monitoring by finding targets on weekends. Furthermore, critical information silos persist: banks cannot share real-time fraud data with police without a court order, causing delays that allow funds to be siphoned off before law enforcement can act.

“And we’ve got a massive skills gap. Crypto-tracing, malware analysis, AI detection – we’re short-staffed and under-trained,” Boucher said.

“The solution is for the government to cooperate with the private sector, and for the law to allow for the sharing of protected information on a basis of urgency. Training and resources should be a priority for law enforcement; without it, South Africa will continue to be a sitting duck.”

Professor of cybersecurity at the University of Johannesburg Basie von Solms said there is nothing dramatically new in the report. Many of the things reported on have been well-known for many years, but nothing is being done about it.

Von Solms said the major problem for cybercrime is the lack of political will from the government as revealed by Auditor-General reports from the past five years which consistently show that 50–70% of audited government IT systems contain known, unfixed vulnerabilities. A primary obstacle to addressing these security failures is the persistent lack of political will to act on these findings.

“It may be that there’s no money to do it, then we shouldn’t have the systems,” Von Solms said, adding that the Auditor-General reports that South Africa is using outdated systems and in some cases, the licence has expired.

Secondly, he said there is a lack of cybersecurity awareness from the general public.

“The government, I think, has got a duty because if you look at the Interpol report, if you look at cybercrime using attack methods like phishing, sextortion, these are all attack methods which are based on the fact that the end user does not recognise it, is not aware of the risk of using cyberspace,” Von Solms said.

Article Source: https://iol.co.za/mercury/news/2026-08-06-sa-is-africas-cybercrime-epicentre/

IMG_3211

AI is raising South Africa’s cybersecurity stakes

By: Kgomotso Lebele

South African organisations are facing a growing cybersecurity challenge at a time when AI is accelerating technological change across every sector of the economy. The country was already one of the most targeted cyber environments in Africa before the latest advances in AI. According to industry research, local organisations experienced a sharp increase in cyber attacks during 2025, while cyber crime continues to impose significant financial and operational costs on businesses, government institutions and consumers.

At the same time, AI is changing how cyber threats emerge and evolve. Tasks that once required significant time, specialised skills and large teams can increasingly be performed faster and at greater scale. For organisations that already have security weaknesses, this creates additional pressure to strengthen their cyber resilience. Research into advanced AI systems has highlighted the potential to identify previously unknown software vulnerabilities across widely used operating systems and browsers, capabilities that have significant implications for both attack and defence.

As advanced AI systems become more accessible, organisations will need to prepare for a future where cyber threats can be identified, developed and executed far more quickly than before. For South African businesses, the concern is not simply the technology itself, it is whether existing security foundations are strong enough to respond to a rapidly changing threat landscape.

Accenture’s State of Cybersecurity research found that only 44% of technology leaders in South Africa acknowledge that AI is advancing faster than their organisations’ cyber security capabilities. Yet assessments conducted across organisations revealed security gaps that could become increasingly difficult to manage as AI capabilities continue to evolve.

Several areas stand out, and cloud security is one. Many digital transformation and AI initiatives rely heavily on cloud environments, yet Accenture’s research found that only 18% of South African organisations have full visibility into their cloud security configurations, while just 6% have approved security baselines in place. Without strong governance and oversight, cloud platforms can create unnecessary risk exposure.

Data governance presents a similar picture. AI systems depend on access to data, making it increasingly important for organisations to understand what information they hold, where it resides, and how it is protected. Only 18% of South African organisations have classified their data according to sensitivity, and just 24% have established clear policies governing AI use. Without these controls, it becomes harder to manage risk and apply appropriate safeguards.

Identity security is another critical area. Modern organisations must manage access across employees, contractors, third parties, applications and, increasingly, AI agents. Yet only 28% of organisations have adopted a continuous verification approach to access management, while just 8% enforce least-privilege access controls. As digital ecosystems become more complex, identity management is becoming one of the most important components of cybersecurity.

Software development practices also require attention. Only 8% of South African organisations integrate security testing throughout the software development lifecycle rather than treating it as a final step before deployment. As AI accelerates the discovery of vulnerabilities, embedding security from the outset becomes increasingly important.

South Africa has already experienced the consequences of major cyber incidents. The 2021 cyber attack on a state-owned freight company disrupted operations at key ports and affected supply chains across multiple sectors of the economy. The incident demonstrated that cybersecurity is no longer solely a technology concern; it has direct implications for business continuity, economic activity and public confidence.

As AI capabilities continue to mature, the potential impact of cyber incidents may become even more significant. Reports suggest that AI is already being used to support activities such as vulnerability discovery, reconnaissance and elements of attack planning. While human oversight remains involved, automation is increasing the speed and scale at which these activities can occur.

Building resilience

Organisations should ensure that security is considered at the beginning of digital and AI initiatives rather than after deployment. Cloud governance, data management, identity controls and application security should form part of planning and implementation processes from the start. As AI becomes more embedded across business functions, security needs to be integrated into decision making from the outset.

Businesses should also explore how AI can strengthen their own defensive capabilities. AI-powered monitoring, threat detection, and vulnerability management tools can help security teams identify risks earlier and respond more effectively. Used responsibly, these capabilities can improve visibility across increasingly complex technology environments and help organisations keep pace with a rapidly evolving threat landscape.

South African organisations have spent years investing in digital capabilities to improve customer experiences, drive innovation and support growth. Those investments will continue to create opportunities, but they also increase the importance of cyber resilience. As AI becomes more embedded in business operations, organisations that strengthen their security foundations and build resilience into their digital strategies will be better positioned to realise the benefits of AI while managing the risks that accompany it.

 

Article Source: https://www.instrumentation.co.za/27921r

 

 

IMG_3216

Six Cybersecurity Trends Shaping South Africa in 2026

By: Yesh Surjoodeen

South Africa is operating in one of the most complex cyber threat environments globally. Hybrid work is now entrenched, digital infrastructure is expanding rapidly, and organisations are more distributed than ever. At the same time, cybercriminal syndicates are becoming more coordinated, more automated and increasingly driven by artificial intelligence.

The impact is already significant. SABRIC estimates cybercrime costs South Africa around R2.2 billion annually, with phishing responsible for 78% of all digital banking fraud in 2025. Accenture reports that 54% of local breaches involved compromised user identities. These figures underscore a hard truth: traditional, perimeter-based security models are no longer sufficient.

Looking ahead to 2026, South African organizations must rethink cyber resilience across people, devices, identities and data. Based on HP’s global security research, six trends will shape the next phase of cybersecurity locally.

  • Cookie theft will overtake password theft
    As multi-factor authentication becomes standard, attackers are shifting from stealing passwords to hijacking browser cookies and session tokens bypassing MFA entirely. This poses serious risk for high-value sectors such as financial services, telecoms, retail, healthcare and government. Protecting the browser through isolation, stronger application controls, regular token rotation and tighter privilege management is now critical.
  • AI will industrialize cyber reconnaissance
    Cybercrime groups are rapidly adopting AI agents to automate reconnaissance, map environments and tailor attacks at scale. INTERPOL reported a 17% rise in AI-assisted cybercrime across Africa in 2025, with South Africa among the most affected. In this context, organizations must assume some attacks will evade detection. Resilience will depend on containment-first strategies, including device isolation, automated rollback and rapid fleet recovery.
  • Physical device attacks will increase
    South African organizations are uniquely exposed to physical device risk. From mining operations and hospitals to retail branches and municipal offices, devices often operate in uncontrolled environments. As tampering tools become cheaper, attackers can extract firmware, compromise BIOS integrity or physically exfiltrate data. Hardware-level protections including tamper resistance and self-healing firmware are becoming essential, particularly for distributed sectors.
  • Print, IoT and edge devices will be prime targets
    South Africa’s reliance on distributed devices ATMs, POS systems, branch printers, routers and IoT sensors has expanded the attack surface. SABRIC reports that 38% of breaches in 2025 involved compromised peripheral devices. Outdated firmware and limited visibility create entry points for attackers. Future-ready security requires full device lifecycle visibility, automated patching and identity-anchored controls.
  • Quantum resilience will shape procurement
    With quantum-safe cryptography standards now formalized, South African organizations especially in the public sector and critical infrastructure; must plan for long-term cryptographic risk. While quantum attacks are not yet mainstream, “harvest-now, decrypt-later” strategies already exist. Hardware purchased today will still be in use when these threats emerge, making quantum-resilient architecture a procurement priority.
  • Identity and data governance will dominate boardrooms
    As POPIA enforcement matures and the Cybercrimes Act expands obligations, regulators are scrutinizing how data is accessed and protected. Security strategies are shifting toward centralized identity orchestration, provenance verification and continuous data lifecycle oversight. With more than half of local breaches tied to identity compromise, trust must be engineered through unified, simplified access frameworks.
  • SECURING SOUTH AFRICA’S DIGITAL FUTURE

    Cybersecurity in South Africa is no longer just an IT concern it is a business continuity imperative. Attacks are more automated, threats span devices and identities, and the margin for error is shrinking. Organizations that succeed will be those that embed security into hardware, automate recovery and build resilience for the long term. The question is no longer whether attacks will occur, but whether environments are designed to withstand them.

Article Source: Six Cybersecurity Trends Shaping South Africa in 2026 – Africa Outlook Magazine

Will Generative AI Empower Cybercriminals_ Visa___

SA ‘overwhelmingly’ targeted by cybercriminals says Interpol

By: eNCA

CAPE TOWN – South Africa is facing far more cyberattacks than most other countries on the continent.

INTERPOL says while no African country is immune to cybercrime South Africa’s position as a financial and digital hub makes it a prime target.

The country records significantly more ransomware and distributed denial-of-service attacks than elsewhere in Africa.

According to the recent Cyber Assessment Report, cybercrimes losses in Africa have more than doubled since 2024 reaching $484 million.

The 40-page report, released Monday and based on survey data from 36 African member countries, describes a shift from isolated criminal incidents to what it calls an industrialised, borderless ecosystem.

Losses rose from $192 million in 2024 to $484 million, driven largely by AI-assisted scams, credential theft and automated social engineering.

Neal Jetton, Interpol’s cybercrime unit director says criminals are not necessarily targeting South Africa itself. Instead, they are searching for weaknesses in networks and systems.

“I think because of increased digitalisation and perhaps a lack in some areas of data and network security, there are vulnerabilities. Financially motivated criminals do not focus on targeting countries. They are looking specifically for vulnerabilities.”

An where they find vulnerabilities, they strike, Jetton adds.

“They [criminals] are going across, scanning networks and seeing where there are vulnerabilities that they can they can exploit.”

Article Source: SA ‘overwhelmingly’ targeted by cybercriminals says Interpol – eNCA

Download premium image of Woman scanning fingerprint with futuristic interface smart technology by Kut about digital, security, fingerprint, interface, and biometric 2808165

Bridging the gap between cybersecurity and physical security in South Africa

By 

October’s Cybersecurity Awareness Month presents an ideal opportunity for South African businesses to review existing security measures and consider how they might be improved.

Cybersecurity risks are becoming more advanced and sophisticated worldwide.

The rise of generative AI and intelligent social engineering strategies is exposing new vulnerabilities in everyday systems, with 72% of organisations believing risks have increased in recent years.

South African businesses face unique challenges, ranging from infrastructural and financial constraints to a 14% year-over-year increase in cyber-attacks nationwide.

In addition, a 2024 report found as many as 63% of cybersecurity roles in the nation are partially or fully unfilled.

The importance of security convergence

As the digital and physical worlds become more interconnected, businesses are afforded new opportunities to merge previously siloed technologies.

This practice, known as security convergence, is instrumental in bridging the gap between cyber and physical security.

In a converged security environment, physical and cybersecurity solutions are controlled and managed within a unified, integrated platform.

Stakeholders are empowered to consider how changes made to aspects of one system could expose vulnerabilities in the other, promoting knowledge-sharing and skill development across both physical and cybersecurity practices.

Security convergence is becoming increasingly important as physical security technologies become more advanced.

Modern security devices like cameras and access control systems leverage intelligent analytics, AI and cloud management features to improve awareness and speed up threat responses, but their reliance on web connectivity can expose vulnerabilities.

By taking a converged approach to security, leaders can benefit from smart technologies while minimising cyber-risks.

At the same time, they can help teams experienced in physical security understand more about contemporary cybersecurity risks, best practices and trends.

The benefits of converged security systems

64% of surveyed South African companies agree that shortages in dedicated cybersecurity roles are creating more cyber threats, leaving local businesses exposed to targeted attacks.

Pursuing internal security convergence enables businesses to upskill existing security teams in the field of cybersecurity while equally strengthening responses to physical security risks.

The benefits of security convergence include:

  • Improved threat detection: In an integrated system, suspicious activities can be observed in real-time across both practices, helping to address threats proactively.
  • Faster incident responses: Real-time communication between cyber and physical security systems enables teams to enact swifter, better-informed incident responses.
  • Streamlined management: By providing teams with a holistic view of all active security systems, businesses can reduce the complexity of day-to-day security management.
  • Reduced operational costs: Integrating both practices helps to reduce bloat and promote streamlined system management, often resulting in lower operational costs.
  • Strengthened security posture: With a holistic view of all security systems and measures it becomes easier to perform comprehensive risk assessments and audits.

Efforts to pursue security convergence can help South African businesses address growing cybersecurity concerns while equally enhancing physical security responses.

In addition, businesses position themselves to make effective use of cutting-edge security technologies.

Core technologies in a converged security system

To successfully build a converged security system and bridge the gap between cyber and physical security, business leaders must leverage a few important technologies and devices.

Unified management platforms

To effectively manage a converged security system, leaders must combine the operation of all physical and cybersecurity technologies within a unified management platform.

An ideal solution will enable operators to link access control, video security, intrusion detection and cybersecurity systems in a centralized platform that can be accessed by operators remotely.

Smart security cameras

Smart security cameras like the Avigilon H6A Dual Head leverage AI-powered analytics to keep operators informed of suspicious motion and sounds consistent with threats.

When connected to a unified management platform, teams can receive real-time alerts and view feeds remotely, with dual camera sensors providing maximal coverage over target areas.

Access control systems

Intelligent access control systems help to prevent unauthorized access events by securing high-risk areas behind traceable credentials.

Avigilon access control solutions can work in tandem with our video security systems to improve situational awareness.

Users can visually verify access events and review logs remotely from an integrated management platform.

Intelligent analytics solutions

AI analytics solutions empower operators to identify and respond to potential threats across both physical and cyber environments, supporting prompt responses and informed decision-making across converged security systems.

Solutions can also be used to monitor network traffic across digital platforms to address suspicious user activity and combat cyber-attacks.

A proactive approach to physical and cybersecurity

Working with a trusted third-party vendor like Avigilon can help South African businesses bridge the gap between cyber and physical security.

By developing a converged security system built using proactive components designed to work in unison, leaders can improve awareness and address complex threats swiftly across cyber and physical environments.

Article Source: Bridging the gap between cybersecurity and physical security in South Africa – MyBroadband

unnamed (1)

Why managed cryptographic services will become the next evolution of cybersecurity

Presented by SmartCrypto

Cybersecurity teams spend millions trying to keep attackers out. Modern security strategy assumes they’ll get in anyway.

Whether through a software vulnerability, a phishing campaign, a compromised third party, or a stolen credential, the question is no longer whether attackers can reach your systems. It’s what they find when they do.

The 2026 Thales Data Threat Report found that 67% of security teams are already seeing credential theft and misappropriated secrets on the rise.

If your cryptography is working correctly, the answer is nothing useful.

Stolen data is unreadable. Transactions can’t be forged. Identities can’t be impersonated.

That’s not a theoretical argument. It’s the only reliable safety net when perimeter controls fail.

The problem is that implementing and operating cryptography at enterprise scale is genuinely hard. Most businesses don’t have the people to do it properly.

The sprawl you probably haven’t mapped

Think about where encryption lives in your environment right now.

  • Your databases encrypt sensitive records.
  • Your APIs exchange signed tokens.
  • Your payment systems run through hardware security modules.
  • Your cloud platforms have their own key management services.
  • Your certificates secure communication across applications and identities.

Now ask: who owns all of that? Who tracks it? Who knows when a certificate is about to expire?

For most enterprises, the honest answer is: nobody does. Not fully.

Encryption underpins everything from payment systems and cloud workloads to digital identities and API security.

According to the 2026 Thales Data Threat Report, only 34% of security teams know where all their data is stored, and 46% are managing five or more separate key management systems.

The keys, certificates and trust infrastructure behind your encryption are almost certainly fragmented across your environment.

The term the industry has settled on for this is cryptographic sprawl.

It’s not dramatic. It’s what happens when encryption is treated as a feature of individual systems rather than a discipline in its own right.

The consequences are quiet but costly: certificates expire unexpectedly and take down critical services.

Keys aren’t rotated because nobody knows what depends on them. Compliance audits expose gaps that nobody knew existed.

Hardware security modules are the physical devices that generate and store the root cryptographic keys protecting your most sensitive systems, and they’re among the hardest components to move or modernise.

Banks know this better than most.

While application workloads shift to the cloud, HSM infrastructure tends to sit exactly where it was installed, often without the operational expertise that the original implementation team brought with them.

A different model

SmartCrypto has introduced Managed Cryptographic Services (MCS) in South Africa.

The idea is simple: cryptographic infrastructure shouldn’t be something your team also has to run.

MCS delivers three core capabilities as managed services:

  • HSM as a Service – enterprise-grade hardware security modules hosted at Teraco, delivered with full key management and operational support
  • PKI as a Service – managed public key infrastructure for certificate issuance, lifecycle management and trust hierarchy
  • Key Management as a Service – centralised key management covering cloud and on-premise environments

Your team gets the capability. SmartCrypto manages the complexity.

As a Thales Platinum Partner and one of a small number of Thales Level 1 Support Partners globally, SmartCrypto builds its services on the same cryptographic stack used by the world’s largest banks and payment networks: the Luna Network HSM, the payShield payment HSM, and the CipherTrust Data Security Platform.

In fact, SmartCrypto is the first provider in Africa to deliver HSM infrastructure as a hosted, managed service.

For procurement, that’s one vendor relationship covering the full cryptographic stack.

The thread connecting it all

SmartCrypto’s approach is built on a nine-layer architectural model called the Crypto Framework. At its core is a concept called the Golden Thread.

Every identity in your environment needs to be cryptographically bound to the data it accesses.

That applies to users, devices, applications and services alike. When that chain is intact, access is verified by cryptography, not assumed.

That’s the technical reality of Zero Trust: not a product, not a policy document, but a cryptographic property of your infrastructure.

The framework structures how that property gets built, maintained and governed, from the hardware root of trust through to compliance and operational oversight.

Starting right for what’s coming

The transition to post-quantum cryptography is no longer a distant concern.

NIST finalised its first post-quantum algorithm standards in 2024, and regulatory guidance is following.

The “harvest now, decrypt later” threat is already active.

Adversaries are collecting encrypted traffic today on the assumption they’ll be able to break it once quantum computing matures.

The same Thales report found that 61% of security professionals already cite this as their top quantum concern.

For financial institutions, healthcare providers and anyone holding long-lived sensitive data, that’s not a theoretical risk.

The practical step most security teams should be taking now isn’t waiting for quantum to arrive.

It’s achieving cryptographic agility: the ability to rotate algorithms, replace keys and update trust infrastructure without rebuilding systems from scratch.

That means centralising key management, automating certificate lifecycle processes and establishing clear ownership of cryptographic systems.

The teams best positioned to respond the future challenges of quantum computing are those with centralised key management and certificate lifecycle processes already in place.

MCS provides that foundation now, so algorithm transitions are manageable when the time comes.

Article source: Why managed cryptographic services will become the next evolution of cybersecurity – MyBroadband

Actualité _ Cyberattaques Bouygues et Air France _ comment savoir si vous êtes concernés _

Cyber risk: A test of leadership

Why South African organisations must stop treating cyber risk as a technical inconvenience.

By: Rennie Naidoo, Professor in Information Systems and Research Director at the Wits School of Business Sciences

At first glance, South African organisations appear to be modernising at an impressive pace. Cloud , hybrid work strategies,  experimentation,  (IOT) expansion, and an increasingly data-driven business culture are reshaping the corporate landscape.

But beneath this digital transformation lies a more complex story. Governance systems are not evolving quickly enough to manage the risks that come with innovation. Complexity is rising faster than control.

Interpol’s Africa Cyber Threat Assessment Report 2025 placed South Africa among the most targeted nations on the continent for ransomware. But the deeper concern is not the rise in cyber crime alone. It is the persistence of outdated thinking.

Too many business leaders still treat cyber security as a technical support function rather than an enterprise risk that requires oversight and strategic management.

That mindset is no longer sustainable.

The King IV Report on Corporate Governance emphasises that cyber risk is a governance responsibility connected to value, risk and assurance. Cyber security now belongs at the centre of business risk conversations.

If it continues to be viewed as an isolated IT problem managed through procurement or outsourced support, then no amount of spending will be enough to protect the organisation. Only through structured, transparent and accountable governance can cyber risk be managed effectively.

 
 

Shift in understanding risk

Effective cyber security risk management is not about eliminating threats. That ambition reflects a false promise that no longer fits the reality of the digital economy.

Instead, the work begins with understanding which risks actually matter, what levels of exposure can be tolerated, and how to make trade-offs between innovation, speed and control.

This process happens not on the technical fringes, but where strategy, operations and governance meet.

Emerging technologies are not simply introducing new risks. They are changing the nature of responsibility.

 

Five domains need to work together to enable sound risk decisions. These include clarity about which products and services are most critical to the business, which systems and data enable them, a realistic understanding of risk appetite, insight into the threat landscape, and clear ownership of controls and response.

 
 

The pressure on South African enterprises

The South African context brings additional urgency. Regulatory, legal and financial risks are mounting.

The Protection of Personal Information Act requires that data breaches be reported to both regulators and affected individuals. The Cyber Crimes Act formalises a range of offences that could turn routine breaches into criminal investigations.

The economic consequences of cyber incidents are also becoming more severe. IBM’s global breach reports, when applied to local conditions, show that losses can easily stretch into the tens of millions of rand.

These costs include not just recovery but legal exposure, reputational damage, customer churn and potential penalties. This makes it clear that cyber security cannot be treated as a badge of digital maturity.

 

The problem with tool-centric thinking

Many organisations believe they are secure because they have a long list of tools in place. Firewalls, endpoint protection, identity systems, e-mail security, backups and incident response plans are all well represented in corporate environments.

But attacks continue to succeed, and the reason is often not technical failure. It is because cyber security decisions are made in isolation, disconnected from the organisation’s broader strategy and risk priorities.

When controls are deployed without a clear risk rationale, three common problems emerge. The first is reactive investment. Security tools are chosen based on industry buzz or vendor influence rather than their relevance to actual threats.

The second is weak governance. Boards receive activity reports but lack visibility into posture or exposure.

The third is misplaced confidence. Dashboards show green, teams are busy, and yet the most dangerous scenarios remain untested and unresolved.

 

Building risk-led cyber security practice

To move cyber security into the realm of executive governance, organisations need a different starting point. That begins with identifying the business’s most critical assets and services. These are the systems that, if compromised, would disrupt operations immediately. They usually include customer platforms, payment services, identity infrastructure and sensitive data repositories.

From there, leadership must define what levels of risk are acceptable in concrete terms. Vague ratings like high or medium are no longer useful. Executives need to know how much downtime the organisation can afford, what level of data loss would be deemed tolerable, and what financial hit could be absorbed without significant disruption.

International frameworks such as NIST, ISO and FAIR can provide a starting point. But certification alone is not the goal. What matters is developing repeatable practices that align with the organisation’s specific context.

A dynamic risk register should be at the heart of this system. It should document risk scenarios with realistic impact narratives, provide reasoning for their likelihood, assign ownership, record associated controls and schedule reviews.

Decisions about risk treatment must also be visible and reasoned. Some risks will require active mitigation. Others may be accepted, transferred through contracts or insurance, or avoided through operational changes. What matters is that decisions are made consciously, documented properly and approved by leadership.

 

People remain most exploitable surface

Despite all the technical investment, human behaviour remains the most exploited vulnerability in the digital environment.

In 2024, Kaspersky reported tens of millions of phishing link clicks across African networks, many from inside corporate systems. This reveals that human behaviour is not a mere soft concern. It is a fundamental part of the organisation’s risk surface, as critical to security as any technical system.

When organisations treat employees as unpredictable and unchangeable, they give up the opportunity to design systems that guide and support secure behaviour. This mindset weakens overall security. Fatigue, urgency and learned responses are all known factors that attackers leverage.

Unless behavioural controls are taken seriously, technical defences will continue to be undermined from within.

 

Scenarios organisations must prepare for

Resilience is not proven by the absence of breaches. It is tested through the ability to recover from them.

Organisations should focus their preparation on the scenarios that truly threaten their continuity. These scenarios include ransomware attacks that encrypt systems while exfiltrating sensitive data, identity breaches that enable attackers to move laterally across networks, compromises of high-trust third-party suppliers, executive impersonation using deepfake audio or video, and data leaks triggered by uncontrolled AI behaviours.

These are not fringe possibilities. They are defining risks that require rehearsal, not just theoretical discussion.

 

New technologies reshape the risk landscape

Emerging technologies are not simply introducing new risks. They are changing the nature of responsibility.

AI systems may quietly expand access to personal data or make decisions that lack explainability. IOT deployments multiply entry points into environments that were never designed for cyber defence. Big data platforms can amplify the impact of a single breach. And social media can turn misinformation and impersonation into a fast-moving risk factor.

Boards and executives must begin to ask harder questions. What trade-offs are being made in the name of innovation or efficiency? Which of these trade-offs are defensible? And who will be held accountable if those decisions fail?

 

Talent as a control surface

Talent is part of frontline defence. Even the best-designed cyber security plan will fail without people who can deliver it.

South Africa’s shortage of cyber security talent remains a material constraint. While outsourcing can support execution, it cannot replace internal judgement, contextual awareness, or institutional learning.

This means that training is not a secondary concern. It is a primary control. Investing in skills directly improves the quality of decisions, the speed of response and the credibility of reporting.

The local cyber security skills gap is not just about technical expertise or executive literacy. It is about the missing link in between.

Organisations need professionals who can turn strategic direction into operational clarity. These are not necessarily the most certified individuals. They are the ones who can build risk registers that boards can understand, justify investments with clear logic and explain exposure without relying on jargon.

Without this layer, security governance remains fragmented and disconnected from enterprise priorities.

 

A closing thought

A technical breach is rarely a failure of security controls alone. More often, it is the visible symptom of deeper governance failures and business decisions that did not fully account for risk.

In the digital economy, resilience is no longer defined by the number of tools in place or the speed of compliance. It is shaped by how deliberately organisations govern risk, how consistently they oversee it, and how clearly leadership understands its role in shaping outcomes.

In South Africa’s high-risk and fast-evolving environment, the organisations most likely to succeed will be those that stop treating cyber risk as a technical issue to be delegated.

They will recognise it for what it truly is – a reflection of leadership quality, institutional accountability and the capacity to make tough decisions under pressure.

View Article Source:

Cyber risk: A test of leadership | ITWeb

600GB of Data and 308 Hrs Deadline Given Post USCS Cyberattack

Why cyber insurance claims are increasingly being rejected

Jeremy Maggs 

‘Cybersecurity insurance companies will assist you through a cyber attack, through a ransomware attack, but it does not guarantee that they will provide a payout, and that’s the misconception,’ says Muhammad Ali of WWISE.

JEREMY MAGGS: Now this is worrying. Nearly half of cyber insurance claims are now being rejected or partially denied, as insurers take a harder line on cybersecurity standards and governance.

A new global study shows many businesses are losing out because what they declared in their policies don’t actually match what is happening in the workplace when an attack occurs.

Listen/read: SA earns top spot as target for cyber attacks [2025]

I want to explore this in a little more detail. I’m in conversation with Muhammad Ali, managing director of cybersecurity and ISO specialist at World Wide Industrial & Systems Engineers (WWISE).

Muhammad, a very warm welcome. I want to start with this headline figure, 47% of claims rejected. Is this about insurers dodging payouts or companies overselling their cyber readiness?

MUHAMMAD ALI: Yeah, I think it’s a very valid question. I think it’s a combination of both factors.

Firstly, I think a lot of corporate organisations feel that they have everything in order. The IT team give them a report, and the top management or the board are all comfortable in terms of what’s going on.

Very little investment is taken into cybersecurity and protecting their privacy and information, personal information as well as their data.

Sometimes I feel like people consider cybersecurity as a cost, as opposed to an investment. In today’s time, it’s about when am I getting attacked, as opposed to if.

You need to know that you are going to go through an attack. Now, there are multiple factors where organisations have misinterpretation of their security controls.

Maybe they have policies that are well written, but it does not talk to what’s actually on the ground. Or perhaps they have very incorrect policies or outdated policies that are in place.

Read: IT consultants also need business interruption insurance [2024]

Now, when a cyber insurance company comes in and let’s look at it from their point of view, and you’re perhaps paying a premium. They’ve done an assessment and analysis. They actually look at all of these things. They look at your misrepresented controls, weak governance, outdated practices.

The assumption is that I’m going to get a payout because I’ve got a cybersecurity insurance that’s going on. That’s not the case, due to noncompliance businesses are exposing themselves without investing and following the actual protocols within their policies. So it’s a factor of both.

JEREMY MAGGS: What you’re suggesting to me is that buying cyber insurance these days is not a cyber strategy.

MUHAMMAD ALI: Not at all. I think cybersecurity is in the top ten risks in most corporate blue-chip companies; and thinking that cyber insurance is going to protect them and their assets, it’s a misconception.

Cybersecurity insurance companies will assist you through a cyber attack, through a ransomware attack, but it does not guarantee that they will provide a payout, and that’s the misconception.

Read: SA businesses vulnerable to cyberattacks [2024]

That is totally due to the fact that the organisation themselves have not read the terms and conditions and been able to fulfil their side of the things, which is actually good governance when it comes to cybersecurity.

They are negligent and they are unfortunately not following the basic parameters of what cybersecurity is all about.

JEREMY MAGGS: Let me throw another big number at you. Ransom demands in South Africa have jumped to around R17 million. At that level, is cyber insurance still affordable or, Muhammad, even viable at this point?

MUHAMMAD ALIYeah, it would depend. I think there are multiple factors. If you look at denial of service, I think that is perhaps one of the key factors. If a cyber attack occurs with ransomware coming in, they can deny you from operating. So your production or operations may stop.

Now, depending on the number of days you are basically stationary, this can result in millions and millions of dollars, aside from the reputational damage.

If you are listed to a to a stock market, then you have to – whether you are attacked or non-attacked – you have to inform the regulator of the attack, because that’s law. This can have significant reputational damage. I think you need to weigh up the investment and the return thereof.

If you are paying a significant amount on cyber insurance and you need to look at the attack or the downtime that it can have, the impact it can have to your processes, your systems, your applications, your users, the data in itself, whether there’s sensitive information and the regulator getting involved.

It’s a catch-22, so I think it’s a good assessment to make to be able to determine whether the premiums you’re paying are actually worthwhile. But there are ways of reducing these premiums.

JEREMY MAGGS: Another trend is a move away from the annual audit to continuous assurance. I understand what you’re saying, but I would also ask whether most South African firms are technically capable of that shift.

MUHAMMAD ALI: Right now, as it stands, we do have a lack of skills, and we do have a lack of practical skills, I think that’s the key word.

A lot of people grow within the ranks quite quickly and they get into a leadership role, a management role, and there’s nothing wrong with that, but the technical ability of being able to read firewall rules, to be able to understand the network security parameters and be able to understand the default settings, are not your golden or silver bullet.

Listen: Insurance trends: Storm-proofing your business

You need to be able to be technically inclined to understand what types of threats there are, what types of vulnerabilities there are, and not only just keeping the basics of awareness throughout the users up to date, but it’s about keeping your systems and applications up to date.

I think there is a gap in South Africa when it comes to that understanding.

This is why we are where we are in South Africa when we are sitting ducks, if you want to call it that, because ransomware attackers or cybersecurity attackers, you will see around the world, look at South Africa from the healthcare perspective, from a banking perspective, or just from an industry perspective.

Listen/read: AI-powered scams target SA banks, insurers and retailers

They see that we’re negligent or we do not have the necessary skills, so we become a threat or an easy target. I think we still need to educate ourselves and get the right skills and stop fooling ourselves by misinterpreting that we do know what’s going on.

JEREMY MAGGS: All right. Just a quick answer, as we come to the end of this conversation. If a chief executive officer or chief information officer is listening to this conversation and wants to avoid becoming part of that 40% that I mentioned at the beginning, what’s the one control then they need to get right immediately?

MUHAMMAD ALI: I think it’s very important to align yourself to an internationally best practice standard. That’s the first thing.

Now, with your insurance firm, they don’t declare this out to you, but whether it’s ISO 27001 or a Nist (National Institute of Standards and Technology) framework, if you align yourselves to that particular standard by effectively implementing the controls – and I recommend ISO 27 because you can get an independent, impartial, accredited certification that is recognised around the world – it helps you reduce your cyber insurance premiums drastically, sometimes up to 50%.

More so that standard with your annual external audits and your rigorous internal audit controls, you will see that the awareness of users is going to improve because you are communicating the content of policies, and the actual policies that are embedded on your applications for security parameters are more understood.

Read: Sarb bolsters defences against cyberattacks [2025]

Not only are you improving the posture of the organisation, but enhancing the individual in the organisation for their practicality in the real world so they don’t become a victim of credit card fraud or a cyber attack. I would suggest that would be your go-to standard as a CEO or an executive.

JEREMY MAGGS: Thank you very much indeed, Muhammad Ali, managing director of cybersecurity and ISO specialist at WWISE, enjoy talking to you. Appreciate your time.

View Article source:

Why cyber insurance claims are increasingly being rejected – Moneyweb

IMG-20240925-WA0022

Why cybersecurity awareness is failing South African businesses and what to fix first

Why cybersecurity awareness is failing South African businesses and what to fix first

Charmé van der Westhuizen, New Business Development Manager at IPT

South African businesses are investing heavily in cybersecurity technology. Detection tools are becoming more sophisticated, monitoring is more advanced, and response capabilities are faster. Yet most breaches still begin with a human error. This shows that technology is not the problem. Instead, it is how cybersecurity is approached.

For many businesses, cybersecurity awareness remains a compliance activity rather than a risk discipline. Training is scheduled annually, attendance is recorded, and certificates are issued. From a governance perspective, the requirement has been met. From a risk perspective, little has changed.

Not a one-off event

In practice, behaviour is shaped by what is reinforced, not what is presented once a year. When training is concentrated into a single intensive session, it competes with operational pressures and fades quickly out of memory. The reality of South African business environments is that teams are stretched, inboxes are full, and urgency is constant. Under those conditions, knowledge without reinforcement does not stick.

If we accept that human behaviour remains the entry point for most cyber incidents, then awareness cannot sit on the periphery of the security strategy; it must be embedded in business operations.

Thinking differently

The first issue to fix is cadence. Short, consistent training delivered over time improves employee skills much more effectively than infrequent, high-intensity workshops. This is not because the content is different, but rather because repetition alters how employees respond to cyberattacks. When people are exposed more frequently to common threat scenarios, they can better identify any potential attack.

The second issue is relevance. Many organisations roll out uniform training across the entire business. That approach assumes that all employees experience the same risk exposure. In reality, risk varies by department. Finance teams face different attack patterns from sales teams. HR manages different types of sensitive information from operations. When awareness programmes fail to reflect those realities, they lose credibility.

Cybersecurity is often described as an IT responsibility. It is not. It is behavioural risk management embedded across departments. If awareness is not tailored to role-based exposure, engagement drops and risk remains unevenly distributed.

The third issue is measurement. Awareness programmes frequently rely on completion metrics rather than behavioural indicators. Attendance does not equal building a resilient organisation. A signed acknowledgement does not demonstrate that a company has now improved its cyber defences.

Identifying threats

When organisations assess behavioural vulnerabilities at the outset, they gain visibility into actual exposure. Automation can then deliver targeted reinforcement at regular intervals, addressing identified weak points rather than rotating generic topics. Over time, this produces measurable improvement instead of superficial coverage.

Automation, in this context, is not about sophistication for its own sake. It is about consistency and accountability. It ensures that awareness is not dependent on manual scheduling or shifting priorities. Weaknesses are identified, addressed, and re-evaluated systematically.

Without that structure, awareness remains reactive.

More than compliance

South African businesses operate in a regulatory and economic environment where reputational damage and operational disruption carry significant consequences. Clients, partners, and regulators increasingly expect demonstrable risk management, not theoretical commitment.

The uncomfortable reality is that many companies are investing more in detecting breaches than in preventing the human actions that trigger them.

Fixing cybersecurity awareness does not require a new platform as a starting point. It requires reframing awareness as an ongoing behavioural discipline supported by structured reinforcement, role-based relevance, and measurable improvement.

Technology will always be essential. But until awareness is integrated into operational processes and treated as a governed risk control, the human layer will remain inconsistently defended.

The number of tools deployed does not define cybersecurity maturity. It is reflected in how people behave under pressure. That is where the real work begins.

Article by:CBN 

View Article source:

Why cybersecurity awareness is failing South African businesses and what to fix first

pexels-divinetechygirl-1181628

Gauteng e-Government invests in Cyber Security for the province

Gauteng e-Government invests in Cyber Security for the province

With the budget provided for the financial year 2024/25, the department of e-Government will execute robust cybersecurity initiatives to increase cyber security for the Gauteng Provincial Government. This is done to emphasize citizen data protection as well as government systems of the province.

One of the key functions of the Gauteng Department of e-Government is to build and manage cybersecurity for the Gauteng Provincial Government. The department’s total budget allocation is R1.7 billion. Among the department’s other initiatives, a portion of the money will be allocated to guarantee that the province government’s cyber security is well-equipped to withstand cyber-attacks.

Over the years, the department has successfully developed the Provincial Cybersecurity strategy and the Gauteng Security Operations Centre. These have played a critical role in safeguarding the provincial government against cybercrime.

Massive volumes of sensitive data are collected, managed, and stored by the Gauteng Provincial Government. As a result, the stakes in cybersecurity are considerable, from resident records and financial transactions to infrastructure control systems. Therefore, to avoid security breaches with far-reaching effects, e-Government must prioritize the protection of sensitive data.

According to Bonginkosi Dhlamini, MEC for e-Government, the provincial government is aware of cyberattacks formed against governments. These cyberattacks can cripple the systems of government by compromising citizen privacy and disrupting government functions.

“As a department housing critical state resources, we must remain vigilant. The recent cyberattack on strategic national departments underscores the vulnerability of government institutions. Hence, we must cover all angles to secure our infrastructure” MEC Dhlamini said.

The department’s proactive actions are intended to ensure that the province government’s networks, data, and systems are safe and robust to cyber threat circumstances.