Dealing with the people risk factor

Issue 7 2021 Security Services & Risk Management

The insider threat has become more complex to mitigate. Access control lists, both from a network and user perspective, as well as physical security of data storage have in the past been used to prevent breaches. The trouble nowadays is that data needs to be easily accessible and with that comes additional risk.


Peter Clarke.

Moreover, one would assume employees need to understand that they must be sceptical about emails and scrutinise the source to ensure they are from whom they purport to be. One would think with the amount of publicity around email scams that staff would be wary about clicking on links in emails, but it is still one of the most successful routes into a company’s confidential data.

Damaging behaviours like this and oversharing on social media, or believing requests delivered through electronic channels without first verifying them, remain common access points for threat actors.

Mimecast research revealed that the most pressing security concerns remain focused on data breaches, phishing, spear-phishing and ransomware. The report notes that these are all areas in which good security awareness training can be highly effective at reducing risk.

Tools to help prevent the threat from within

Multi-factor authentication(MFA) is an effective and relatively inexpensive way to limit access to data. Users are required to verify identity through an authentication code before company resources can be accessed. This can be deployed via SMS, or better still, a more efficient authenticator app.

Switches: this technology has been around for some time. If the right hardware is in place, one could look at deploying technologies such as 802.1x where every device on the network needs to be authenticated before it can gain access to network resources.

Data leak prevention(DLP) is something that most well-known firewall brands should have enabled. Depending on the technology being used, DLP allows you to prevent sensitive information, such as bank account details; ID numbers etc., from leaving your network.

Zero trust: Attackers that breach the perimeter one way or another are either a staff member or impersonate an insider. As such the ‘Zero Trust’ security model is being adopted at a fast rate globally. The Zero Trust model was created in 2010 by a principal analyst at Forrester. Today it is repeatedly implemented as organisations scramble to protect enterprise systems against increasingly sophisticated attacks. The focus for organisations should be to work on a Zero Trust network model.

Phishing protection and education</i>: One of the best defences for phishing attempts is education. Threat actors are finding ways to bypass mail and other security systems by composing authentic looking mails and directing users to authentic looking, as well as genuinely authentic websites. These sites would then ask for sensitive information, which is promptly sent to the attacker.

Simple things for staff to look out for include:

1. If something looks too good to be true, it probably is. Do some research and ask around to verify.

2. If a staff member is not expecting a PO or payment instructions from someone, report it to IT immediately.

3. If a staff member sees that a CFO, or other high-ranking exec has asked them to expedite a payment, they must confirm that the mail originated from the specific address and is from the true source, or, if suspicious, report to IT immediately.

Edge protection: Protecting the network edge has become more important than ever because of the increasing number of endpoints organisations rely on, including but not limited to desktops, laptops, mobiles and IOT devices. As networks expand so does the potential attack service.

At an absolute minimum, a well-configured next-generation firewall needs to be put in place that makes use of web filtering, application control and intrusion prevention to aid in the protection of the network edge. Larger organisations may need to look at specific appliances such as Web Application Firewalls and Application Delivery controllers for additional layers of security – the one caveat is that this approach can be quite costly.

Server and data centre security: This area has several similarities to edge protection in that servers and data centres are still sitting on their own network edge. Depending on requirements, a capable next-generation firewall should be one of the first things to look at deploying. Dedicated security appliances for web and application security can be an asset. Servers and data centre resources are generally more exposed to threats as this is where most of an organisations’ crucial data or applications sit.

Anti-virus might seem like an obvious thing to consider, but there are several things that organisations can overlook. You need to consider if the AV solution you are using is designed to be run on server infrastructure. Servers are far more complex by design than a normal PC and often run applications and systems that need AV solutions that can work with these.

Lastly, backup: this is of the utmost importance.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

“This Is Theft!” SASA slams Mafoko Security
News & Events Security Services & Risk Management Associations
The Security Association of South Africa (SASA) has issued a stark warning that the long-running Mafoko Security Patrols scandal is no longer an isolated case of employer misconduct, but evidence of a systemic failure in South Africa’s regulatory and governance structures.

Read more...
Making a mesh for security
Information Security Security Services & Risk Management
Credential-based attacks have reached epidemic levels. For African CISOs in particular, the message is clear: identity is now the perimeter, and defences must reflect that reality with coherence and context.

Read more...
Privacy by design or by accident
Security Services & Risk Management Infrastructure
Africa’s data future depends on getting it right at the start. If privacy controls do not withstand real-world conditions, such as unstable power, fragile last-mile connectivity, shared devices, and decentralised branch environments, then privacy exists only on paper.

Read more...
From friction to trust
Information Security Security Services & Risk Management Financial (Industry)
Historically, fraud prevention has been viewed as a trade-off between robust security and a seamless customer journey, with security often prevailing. However, this can impair business functionality or complicate the customer journey with multiple logins and authentication steps.

Read more...
Security ready to move out of the basement
AI & Data Analytics Security Services & Risk Management
Panaseer believes that in 2026, a board member at a major corporation will lose their job amid rising breaches and legal scrutiny, as organisations recognise that cyber risk is a business risk that CISOs cannot shoulder alone.

Read more...
Cyber remains top business risk, but AI fastest riser at #2
News & Events Security Services & Risk Management
The Allianz Risk Barometer 2026 ranks cybersecurity, especially ransomware attacks, as the #1 risk, while AI is the biggest riser and jumps from #10 to #2, highlighting the emerging risks for companies in almost all industry sectors.

Read more...
OT calculator to align cyber investments with business goals
Industrial (Industry) Information Security Security Services & Risk Management
The OT Calculator has been developed specifically for industrial organisations to assess the potential costs of insufficient operational technology (OT) security. By offering detailed financial forecasts, the calculator empowers senior management to make well-informed decisions.

Read more...
From digital transformation to digital sovereignty
Security Services & Risk Management IoT & Automation
As cyberthreats grow, data regulations tighten, and AI becomes central to economic competitiveness, countries are recognising the need to control and protect their own digital assets.

Read more...
The age of Lean 4.0: Orchestrating intelligence and efficiency
Security Services & Risk Management
The convergence of Lean principles and AI (what we now call Lean 4.0) is no longer a theoretical exercise; it is the defining operational paradigm for survival and growth in a complex, data-intensive economy.

Read more...
Risks of open-source intelligence escalating in crime
Security Services & Risk Management Residential Estate (Industry) Smart Home Automation
CMS estimates that open-source intelligence has played a role in 20 - 30% of robberies over the past 12 months. In cybercrime, global research consistently shows that many offences rely on some form of open-source data exploitation.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.