{"id":29130,"date":"2019-09-25T09:33:29","date_gmt":"2019-09-25T08:33:29","guid":{"rendered":"https:\/\/www.intelligentcio.com\/africa\/?p=29130"},"modified":"2019-09-27T11:04:57","modified_gmt":"2019-09-27T10:04:57","slug":"the-reality-of-the-cybersecurity-landscape-in-africa","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2019\/09\/25\/the-reality-of-the-cybersecurity-landscape-in-africa\/","title":{"rendered":"The reality of the cybersecurity landscape in Africa"},"content":{"rendered":"\n<p>There is a misplaced\nconfidence in existing cybersecurity solutions and the beleaguered IT\ndepartment that is leaving corporate doors wide open for attack.&nbsp; <\/p>\n\n\n\n<p>The <em>World Wide Worx State of Enterprise Security in South Africa 2019<\/em> report found that 99% of IT departments feel confident that they can protect the company and yet 45% say they don\u2019t have the skills they need to cement this confidence and 43% don\u2019t think they would detect a breach within the first few minutes. There is a disconnect between the reality of the security systems in place and the overconfidence of the enterprise.<\/p>\n\n\n\n<p>\u201cThe security\nlandscape across the African continent is a complex mix of overconfident belief\nin the ubiquity and capability of the IT department and the complete lack of\nsecurity skills and employee awareness,\u201d said Karien Bornheim, CEO of FABS. <\/p>\n\n\n\n<p>\u201cCybersecurity isn\u2019t\nembedded into the culture of the organisation nor is it addressing the biggest\nvulnerabilities in the systems \u2013 outdated software, poor employee training, and\nthird-party vulnerabilities.\u201d<\/p>\n\n\n\n<p>The survey found that\na staggering 77% of IT decision-makers were concerned with the risks inherent\nin outdated software systems. That\u2019s a huge slice of the corporate pie left\nwide open for attacks that could cripple the business and its reputation. This\nisn\u2019t just hype. <\/p>\n\n\n\n<p>The Ponemon Institute\nfound that the lost assets and expenses experienced by a breach can damage\nbrands badly, often causing up to US$1.6 million in costs and taking nearly two\nmonths to resolve. Perhaps even more concerning is that the same research found\nthat 60% of these breaches were caused by a negligent employee or third-party\ncontractor. <\/p>\n\n\n\n<p>\u201cThe challenge\ndoesn\u2019t lie exclusively in the infrastructure that helps the organisation\nminimise the risk of cybercrime,\u201d added Bornheim. <\/p>\n\n\n\n<p>\u201cIt is equally\nreliant on the training that the company provides to its IT department, it\u2019s\nemployees and its third-party vendors. Without understanding the risks or the\nprotection against them, people will always be the weakest link in the security\nchain.\u201d<\/p>\n\n\n\n<p>It\u2019s surprising how few organisations invest in cybersecurity training programmes such as those offered by the EC Council, especially considering how easy it is for Goliath to fall to that worm. <br> <br>In July 2019, one of South Africa\u2019s largest electricity service providers fell foul of ransomware. <\/p>\n\n\n\n<p>One of the most\ncommon ways for ransomware to penetrate any defensive system is via that click\nmade by the untrained employee who really, really thinks that the email is\ngenuine. Human error was also the reason for the BlackRock data leak in January\n2019, SAA and Liberty were both victims of successful hack attempts, and the\nnumber of cyber-attacks per day in 2019 has risen to 13,842 according to\nKaspersky.<\/p>\n\n\n\n<p>\u201cThe risk isn\u2019t\nmanufactured by the media or only inherent in someone else\u2019s business,\u201d added Bornheim.\n<\/p>\n\n\n\n<p>\u201cEvery organisation\nof any size and in any market is at risk of being hacked, breached or subjected\nto the whims of ransomware. In fact, the research is increasingly pointing to a\nshift in cybercrime focus with many attacks directly targeting small to medium\ncompanies. They are less likely to have invested in training and security tools\nand more likely to have usable vulnerabilities as a result.\u201d<\/p>\n\n\n\n<p>The cost of training\nup staff is barely a scratch to the budget compared with the cost of recovering\nfrom a hack. The Accenture Cost of Cybercrime study that spans more than 11\ncountries and 16 industries found that the average cost of cybercrime rose to US$13\nmillion per company in 2018. <\/p>\n\n\n\n<p>That\u2019s far more than\nany company could spend on establishing a business culture that\u2019s cyber-aware\nand security savvy. The same applies to the training and management of third-party\nservice providers. Investing in training, policy development, skills\ndevelopment, and a cohesive cybersecurity posture is a small price to pay\nconsidering the potential business and reputational loss. <\/p>\n\n\n\n<p>The laws in Africa\nhave yet to deliver the robust smack to the business that they should, but any\nbusiness looking to expand its footprint is going to have to deal with the\ncompliance and regulatory requirements of&nbsp;the various cybersecurity and\ndata protection acts in the African countries, GDPR in Europe, the Australian\nPrivacy Principle 11 (APP 11) in Australia, and the Federal Trade Commission\nAct in the United States,&nbsp; to name just a few.<\/p>\n\n\n\n<p>\u201cTraining courses\nthat emphasise skills development, recognise the importance of educating\nemployees, and that focus on providing the business with robust third-party\ncyber-posturing, are essential,\u201d said Bornheim. <\/p>\n\n\n\n<p>\u201cThis will not only\nset robust, long-term foundations for the company\u2019s cybersecurity policy but\nensure that all compliance boxes are ticked, and that employee negligence is\nminimised significantly. There will always be the risk of a hack or a breach,\nbut with training, this is minimised and managed properly.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>There is a misplaced confidence in existing cybersecurity solutions and the beleaguered IT department that is leaving corporate doors wide open for attack.&nbsp; The World Wide Worx State of Enterprise Security in South Africa 2019 report found that 99% of IT departments feel confident that they can protect the company and yet 45% say they [&hellip;]<\/p>\n","protected":false},"author":25,"featured_media":29131,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,298,19,54,9059,13,262],"tags":[11175,11176,5519,9380,388,11173,10134,11177,445,11172,226,6571,285,11174,453,11171],"class_list":["post-29130","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-main-story-newsletter","category-regional-news","category-research","category-south-africa","category-top-stories","category-used","tag-accenture-cost-of-cybercrime","tag-australian-privacy-principle","tag-blackrock","tag-breach","tag-cybersecurity","tag-ec-council","tag-fabs","tag-federal-trade-commission-act","tag-gdpr","tag-karen-bornheim","tag-kaspersky","tag-liberty","tag-ponemon-institute","tag-saa","tag-south-africa","tag-world-wide-worx-state-of-enterprise-security-in-south-africa-2019"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/29130","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=29130"}],"version-history":[{"count":3,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/29130\/revisions"}],"predecessor-version":[{"id":29134,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/29130\/revisions\/29134"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/29131"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=29130"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=29130"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=29130"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}