{"id":19188,"date":"2018-05-30T12:56:19","date_gmt":"2018-05-30T11:56:19","guid":{"rendered":"http:\/\/www.intelligentcio.com\/africa\/?p=19188"},"modified":"2018-05-31T08:31:43","modified_gmt":"2018-05-31T07:31:43","slug":"mimecast-expert-on-tackling-cyberattacks-in-kenya","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2018\/05\/30\/mimecast-expert-on-tackling-cyberattacks-in-kenya\/","title":{"rendered":"Mimecast expert on tackling cyberattacks in Kenya"},"content":{"rendered":"<p><em>Brian Pinnock, Mimecast Africa and the Middle East, discusses how the country&#8217;s new cybercrime bill is a crucial move in Kenya\u2019s cybercrime war, but argues that all organisations will need to play their part.<\/em><\/p>\n<p>Cyberattacks in Kenya are on the rise. There\u2019s barely a day that goes by where you don\u2019t hear about a major data breach or an organisation that has unsuspectingly fallen victim to ransomware, spear-phishing or impersonation fraud. The government has seen the urgency and on May 16 signed the Computer Misuse and Cybercrimes Act into law.<\/p>\n<p>And while most of the news coverage has focused on the perceived negatives of the legislation \u2013 including restrictions around freedom of expression and access to information \u2013 individuals should be pleased that cybercriminals will now face consequences. According to a 2017 Serianu study, cybercrime cost Kenya 21.1 billion Kenyan shillings in 2017, so it seems that criminals have had free rein up until now.<\/p>\n<p>Public and private organisations in Kenya are moving in their droves to the cloud. The benefits of cloud email providers like Office 365 are clear as businesses of all sizes can now benefit from its collaboration capabilities, improving productivity.<\/p>\n<p>However, what a lot of organisations don\u2019t realise is that while email is the number one business application used by companies, it\u2019s also the number one vector used to execute cyberattacks like malware delivery, phishing and business email compromise. As businesses move to a cloud-based email environment, new challenges enter the landscape. The concentration of corporate mailboxes, and operational dependency on the Microsoft environment exposes many vulnerabilities.<\/p>\n<p>It\u2019s therefore clear that the new cybercrime bill comes at a critical time and will go a long way in fighting the epidemic currently gripping the country. The new legislation will assist in capturing and prosecuting these cybercriminals but what happens if you\u2019re the victim of an attack before they manage to track these malicious actors down?<\/p>\n<p>The cyberthreat landscape has evolved dramatically, hackers are smarter and more sophisticated, they have formed communities and share ideas and pursuits. Many organisations think that defending against spam, viruses and malware is enough, but attacks have changed. Hackers moved on years ago to using malicious URL links found within emails and documents and in recent years we\u2019ve seen a significant increase in impersonation attacks using social engineering.<\/p>\n<p>A recent global study by Mimecast and Vanson Bourne saw that 92% of surveyed organisations had seen targeted spear-phishing attacks with malicious links in the past 12 months.\u00a0A total of 87% had witnessed email-based impersonation attacks asking to initiate wire transfers. We\u2019re also seeing insider threats gaining traction and a recent trend of supply chain attacks from so-called \u2018trusted\u2019 third parties. The criminals are always one step ahead in this war and organisations are battling to keep up.<\/p>\n<p>Unfortunately, organisations are relying on mediocre email security that only touches the surface when it comes to protecting their business from threats. C-level executives are failing to see the importance of having advanced security, leaving IT decision makers to fight an uphill battle. Astonishingly, according to Serianu, as many as 10% of Kenyan organisations have zero budget allocated to cybersecurity products.<\/p>\n<p>Even more unbelievable is that this is an increase from 6% last year. Plus, the lack of skills in the country makes this war even harder \u2013 the study reports that there are only an estimated 1,600 certified security professionals in Kenya.<\/p>\n<p>With these factors in mind, it\u2019s not surprising that the government has had to take steps to help curb the growing instances of cybercrime but it\u2019s apparent that for many organisations it\u2019s only a matter of time until they become the next victim.<\/p>\n<p>Relying on the basic security provided by cloud email providers is a huge risk that could dramatically impact productivity, business operations or even bottom line. Furthermore, relying on defence only is no longer enough. Organisations need to be prepared for the possibility of a successful attack and have risk mitigation techniques in place.<\/p>\n<p>This involves ensuring the stability of your entire email environment before, during and after an attack, by implementing a cyberresilience strategy for email. So, if a breach occurs, you can keep email flowing with a continuity service and recover from ransomware quickly, with an archive service that allows you to recover data to the last known \u2018good\u2019 state.<\/p>\n<p>The new cybercrime bill is a crucial move in Kenya\u2019s cybercrime war, but it\u2019s up to all organisations to play their part. Laws can only do so much to protect businesses; leadership teams need to take responsibility and create a culture with targeted programs geared towards safeguarding their employees, customers and business partners.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Brian Pinnock, Mimecast Africa and the Middle East, discusses how the country&#8217;s new cybercrime bill is a crucial move in Kenya\u2019s cybercrime war, but argues that all organisations will need to play their part. Cyberattacks in Kenya are on the rise. There\u2019s barely a day that goes by where you don\u2019t hear about a major [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":19197,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[6,399],"tags":[5439,387,5440,297,277,5441,5442],"class_list":["post-19188","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-insights","category-more-news","tag-computer-misuse-and-cybercrimes-act","tag-cyberattack","tag-impersonation-fraud","tag-kenya","tag-ransomware","tag-serianu","tag-spear-phishing"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/19188","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=19188"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/19188\/revisions"}],"predecessor-version":[{"id":19192,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/19188\/revisions\/19192"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/19197"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=19188"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=19188"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=19188"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}