Its About Training, Stupid.

In South Africa, the private and public sectors need to move with the times and start training employees, the new weak point in an organisation’s information technology (IT) defences, in how to deal with cyber threats, experts say.

There has been "a seismic shift in how we work", with mobile devices allowing remote work to increasingly become the norm, says David Emm, a UK-based principal security researcher at cyber security firm Kaspersky Lab. That means the old model of building security "moats" around company networks no longer works, and many businesses have not moved on from that strategy.

Emm says the shift to working on mobile devices, phones, tablets and laptops, means hackers have more entry points into a company’s network.

Riaan Graham, Ruckus Networks sales director for sub-Saharan Africa, agrees. "With mobile devices becoming effectively a computer in your pocket and where a lot of your communication happens on a daily basis, I think the one thing all corporates are guilty of at some level is the lack of training given to employees regarding cyber security," says Graham.
Since all employees have access to a company’s network, if a cyber-criminal hacks into a staff member’s device, "their work’s already half done".

"So I think the first thing that’s needed is continued training with regard to security risks for employees, from the base all the way up to C-level employees. All of them need to understand the threats out there today," Graham tells the Financial Mail.
Employees should be trained in how to deal with possible malware, spyware or "rogue security software", for instance.

"The software might tell you to update or remove certain functions, and if the employee is not aware of the company’s policies regarding change control, they might click and say ‘yes let’s update’, and then open up the whole network to a virus or a Trojan horse," Graham says.

Some hackers are even penetrating networks by leaving corrupted memory sticks in a company’s parking lot in the hope someone will pick them up and insert them into their computers, according to Paul Williams, Fortinet’s manager for Southern Africa.

Perhaps unsurprisingly, considering the hype around bitcoin and other digital currencies, Williams says hackers are also hijacking companies’ computers to mine crypto-currencies. He says "crypto-jacking", or the unauthorised use of someone else’s computing resources to mine crypto-currencies, has become a major threat to both consumers and enterprises.
It is an attractive ploy for cyber criminals as it does not require strong technical skills and, unlike ransomware, offers a potential 100% payout ratio, Williams says.

Meanwhile, besides their employees, companies’ supply chains are also being identified as a weak link by cyber criminals, according to a recent Dimension Data report. Mark Thomas, Dimension Data’s group cybersecurity strategist, says there are many moving parts to supply chains and outsourcing companies, and these often run on disparate and outdated networks, "making them easy prey" for the cyber-criminals.

"Service providers and outsourcers are also a prime target due to their trade secrets and intellectual property," Thomas says, adding that businesses "need to wise up".

New data protection rules in SA and Europe could prompt businesses to do just that, according to Roy Wright, head of risk solutions at financial advisory group GTC.

Wright believes companies should be taking out insurance against cyber-attacks because they need to safeguard themselves against lost income from systems outages, costs associated with identifying and rectifying a breach, litigation costs, and possible extortion from ransomware attacks.

He says cyber-insurance will probably be taken more seriously following the introduction of laws to ensure the protection of personal data including the General Data Protection Regulation (GDPR) in Europe and the Protection of Personal Information (PoPI) Act in South Africa.

The PoPI act will oblige companies to report and publish any data breaches as and when they occur. Organisations will also have to publish their strategies to rectify a breach and their plans to mitigate against such risks in the future.

"Companies that fail to comply with these requirements will be issued with fines, which will significantly impact small to medium businesses," says the risk expert.

Meanwhile, as organisations move their workloads into public cloud infrastructure, they will gain the added benefit of having better security.

This is because cloud vendors have to spend substantially more money on their security than most companies would ever choose to, says Richard Levine, co-founder and MD of Executive Solutions. Cloud computing providers such as Microsoft and Amazon also fork out a lot more than most companies can for the skills to manage and support these security technologies, Levine says.

"Companies moving to the cloud therefore benefit from economies of scale via their cloud vendor on all fronts, including IT security."

BusinesLive:        Image: Nick Youngson

You Might Also Read:

In S.Africa The Cybersecurity Skills Gap Is A Chasm:

Employees Are Key To Cybersecurity:

 


 

« The Pentagon's AI Program To Find Hidden Nuclear Missiles
AI Is Re-Inventing IT »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

SolarWinds

SolarWinds

SolarWinds as a worldwide leader in solutions for network and IT service management, application performance, and managed services.

QASymphony

QASymphony

QASymphony software testing and QA tools help companies create better software by improving speed, efficiency and collaboration during the testing lifecycle.

Kernelios

Kernelios

Kernelios is a simulator-based training center and an incubator for cyber experts worldwide.

CyberSift

CyberSift

CyberSift is a cyber security provider. We develop threat detection software which needs no infrastructure changes as it integrates with almost any security tool.

National Security Authority (NBU) - Slovakia

National Security Authority (NBU) - Slovakia

The National Security Authority (NBU) is the central government body in Slovakia for the Protection of Classified Information, Cryptographic Services, Trust Services and Cyber Security.

Harel Mallac Technologies

Harel Mallac Technologies

Harel Mallac Technologies is a Mauritian organisation that has developed a strong network of ICT specialists with nodes across the African continent.

Cyber Security Malta

Cyber Security Malta

Cyber Security Malta is part of Malta's National Cyber Security Strategy which aims to combat cybercrime, strengthen national cyber defence and provide cyber security awareness and education.

C3.ai

C3.ai

The C3 AI Suite supports configurable, pre-built, high value AI applications for predictive maintenance, fraud detection, anti-money laundering, sensor network health and more.

Learn How To Become

Learn How To Become

At LearnHowToBecome.org, our mission is to help any job-seeker understand what it takes to build and develop a career. We cover many specialist areas including cybersecurity.

Intraprise Health

Intraprise Health

Intraprise Health is a Certified HITRUST Assessor and award-winning provider of health information security products and services.

Bolster

Bolster

Bolster (formerly RedMarlin) is an AI-based cyber-security platform designed to detect phishing and fraudulent sites in real-time.

SecSign Technologies

SecSign Technologies

SecSign Technologies delivers user authentication, messaging, file sharing, and file storage with next generation security for company networks, websites, platforms, and devices.

Bedrock Systems

Bedrock Systems

BedRock Systems is on a mission to deliver a trusted computing base from edge to cloud, where safety and security isn’t just a perception, it’s a formally proven reality.

Xiarch Solutions

Xiarch Solutions

Xiarch Security is an global security firm that educates clients, identifies security risks, informs intelligent business decisions, and enables you to reduce your attack surface.

Pillr

Pillr

Pillr is a cybersecurity operations platform capable of adapting to the demands of your business and team — and the global threat landscape.

Excite Cyber

Excite Cyber

Excite Technology Services (formerly Cipherpoint) is focused on improving the security posture of our customers.