Cyber risks for companies escalate

Issue 4 2021 Security Services & Risk Management

In the last month alone, Johannesburg’s City Power, Transnet and a number of large South African firms fell victim to major cyber-attacks. These are just the latest additions in a rising tide of high profile local cyber-attacks over the past two years. However, these well documented attacks are only just scratching the surface. With the Protection of Personal Information Act of 2013 (PoPIA) having come into full effect at the start of July, South Africans are likely to see the full impact of cybercrime for the first time.

Bertus Visser, chief executive of distribution at PSG Insure, says that many companies were still taking a lax approach to cybersecurity before PoPIA came into full effect. “Data breaches have been massively under-reported to date and it is possible many businesses opted to sweep cyber incidents under the carpet, until now. Now that disclosure is a legal requirement that will be actively enforced by a regulator, we expect to see a huge spike in reported incidents, however, this poses its own set of risks that businesses will have to protect themselves against.”

Insurance doesn’t cover it all

Visser explains that businesses need complete cyber-risk management strategies that encompass much more than simply taking out cyber insurance. “More businesses will need good cyber insurance policies. However, these policies only cover first- and third-party losses as well as some regulatory exposures. In order to adequately manage the risks that cybercrime poses, businesses will have to consult with their advisers to develop a well-planned all-encompassing strategy.”

He points out that this begins by taking a closer look at the potential damages to a business. “Third-party claims and regulatory fines are just part of a company’s total losses. Business interruption and damages to physical assets are insured under different policies. As businesses increasingly move their operations online, the potential secondary losses have increased in severity. Businesses therefore need to review their insured amounts across all of their policies, bearing in mind that a single cyber incident could trigger a number of policies at once.”

Training is critical

Next, cybersecurity training is crucial. “The human element is still the greatest threat to cybersecurity and it's unlikely insurers will cover incidents of pure negligence. Ensuring that all employees and contractors are educated and informed on the latest cyber security attacks and trends is vital. Many IT service providers offer basic cybersecurity training for staff and it can even be included as an add-on to cyber policies.”

Lastly, he says that regularly reviewing cyber risk management strategies is crucial. “Cybercrime is evolving at a frightening pace, so it would be prudent for businesses to revisit their risk management procedures at least twice a year.”

With PoPIA now in full force, Visser says that this may be the catalyst that could finally set businesses on the right path toward becoming truly cyber-resilient. “Business owners should speak to their adviser to ensure they have all the right risk mitigation measures and policies in place to safeguard their business against cybercriminals and any potential liability following an incident,” he concludes.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Rewriting the rules of reputation
Technews Publishing Editor's Choice Security Services & Risk Management
Public Relations is more crucial than ever in the generative AI and LLMs age. AI-driven search engines no longer just scan social media or reviews, they prioritise authoritative, editorial content.

Read more...
How can South African organisations fast-track their AI initiatives?
AI & Data Analytics Security Services & Risk Management
While the AI market in South Africa is anticipated to grow by nearly 30% annually over the next five years, tapping into the promise and potential of AI is not easy.

Read more...
Efficient, future-proof estate security and management
Technews Publishing ElementC Solutions Duxbury Networking Fang Fences & Guards Secutel Technologies OneSpace Technologies DeepAlert SMART Security Solutions Editor's Choice Information Security Security Services & Risk Management Residential Estate (Industry) AI & Data Analytics IoT & Automation
In February this year, SMART Security Solutions travelled to Cape Town to experience the unbelievable experience of a city where potholes are fixed, and traffic lights work; and to host the Cape Town SMART Estate Security Conference 2025.

Read more...
Stallion repositions itself as a services provider
News & Events Security Services & Risk Management
Stallion has rebranded as Stallion Integrated Solutions to reflect its expanded capabilities beyond traditional security services to delivering integrated solutions that enhance safety, asset management, and operational efficiency.

Read more...
Seven tips to help ensure your backup batteries work
Power Management Security Services & Risk Management
Load shedding is back, officially or not. Lance Dickerson offers seven tips to prolong the life of your power backup systems and ensure they perform as intended when needed.

Read more...
Cybersecurity best practice
Information Security Security Services & Risk Management
Breach and attack simulation has become an essential element of cybersecurity strategies in any modern business by allowing companies to actively detect and resolve vulnerabilities through real-world attack simulations.

Read more...
Historic Collaboration cuts ATM Bombings by 30%
Online Intelligence Editor's Choice News & Events Security Services & Risk Management
Project Big-Bang, a collaborative industry-wide task team, has successfully reduced ATM bombings in South Africa by 30,7% during the predetermined measurement period of November, December and January 2024/5.

Read more...
Keeping safety central to enterprise risk management
Zulu Consulting Security Services & Risk Management
[Sponsored] As employee safety becomes an ever-more critical aspect of corporate risk management, Risk-IO assists risk managers in ensuring a safe working environment, whether in an industrial setting, an office, or anywhere.

Read more...
Empower individuals to control their biometric data
Information Security Access Control & Identity Management Security Services & Risk Management
What if your biometrics, now embedded in devices, workplaces, and airports, promising seamless access and enhanced security, was your greatest vulnerability in a cyberattack? Cybercriminals are focusing on knowing where biometric data is stored.

Read more...
Strategies for combating insider threats
Information Security Security Services & Risk Management
In Africa, insider threats pose an increasingly significant risk to businesses, driven by economic uncertainty, labour disputes, and rapid digital transformation. These threats can arise from various sources, including disgruntled employees and compromised third-party service providers

Read more...