A back to basics layered approach

SMART Cybersecurity Handbook 2022 Information Security

Since the start of the Covid-19 pandemic, cyber-attacks have been on the increase on a global scale, inflicting financial losses across all sectors including manufacturing, banking and energy, to name a few. In South Africa, cyber-crime has become one of the biggest threats faced by companies, governments and individuals, as the spread of digital technology and connectivity makes every form of human activity vulnerable to attack.

We are certainly seeing phishing, whaling and hacking attempts happening with increasing frequency. Identity theft has become another big issue, with stolen IDs leveraged for financial gain. The real challenge facing security specialists is that a number of these cyber criminals appear to be state sponsored, which means they have enormous resources behind them.

This is important to note, as although there remain many amateurs out there, companies would do well to remember that there are also many professional criminals who are well-versed in hiding their attacks - and it tends to be that the more prominent the organisation, the more sophisticated such an attack will be.

One only has to look at the recent Transnet compromise to note the kind of impact a severe attack can have on vital institutions like our ports, through which so much commerce and capital flows.

The pandemic is certainly a driver behind the increase in cybercrime, due to a variety of factors. For one thing, there are more people working remotely, which inevitably makes it tougher for security tools. The anxiety created as a result also opens potential new vectors of attack, while the massive job losses caused by global lockdowns have led to more unemployed people seeking to earn an income via criminal activity.

Prevention is better than cure

When it comes to stopping cyber threats, I recommend a prevention-first approach. This means using an endpoint prevention tool, rather than one focused on endpoint detection and response (or augmenting the EDR tool with an EPP one). Ideally, you want a solution that applies advanced artificial intelligence (AI) to the task of preventing and detecting malware - something like Deep Instinct, a purpose-built, deep learning cybersecurity framework.

These types of solutions are extremely smart in the way they are designed, in that they use AI to understand exactly what constitutes a security issue. With advanced solutions like this, companies can move beyond the basics, such as ensuring that a user doesn’t have the same password for every service and apply greater levels of security through implementations like multi-factor authentication (MFA), or go passwordless where possible, which can be used to create additional layers of security.

Remember that in a digital world, a criminal infiltration of your business may begin somewhere far beyond the company’s own security perimeter. Think, for example, of a customer purchasing from a retailer, who uses the same password for their club card as they do for their work login. If the retailer is hacked, it becomes possible for the bad guys to use information gained there to break into your corporate network as well. This illustrates why proper password management is vital.

Another big issue is e-mail, which is one of the key infiltration methods used by criminals, as it is seen as one of the easiest methods to use to break into a network. While a user may not always be able to tell if a link is dangerous, AI-based security solutions are able to rapidly scrutinise the URLs of anything a user may wish to click on, making it far more difficult for criminals to gain access through malicious links.

Remember too that while there is no silver bullet for cybersecurity, eliminating the challenges around passwords is a great first step. Essentially you need a multi-pronged approach to security, since good security is all about layers and making it as complex as possible for criminals to break in.

Get the basics right

Much like good home security starts with a wall and electric fence, but also likely includes a watch dog, an alarm and a security gate, so you need to build multiple layers of security to protect your core. This way, even if one is cracked, the criminal finds they are faced with yet another obstacle.

It is also worth noting that security - even AI-based, multi-layer security - is only half the battle. It is just as imperative to train your employees properly, so that they know the basics, such as never to click on unknown links or open strange mails.

Security today is complex and most people really don’t know where to begin, which is why it is worthwhile talking to genuine security experts beforehand. And the advice they will give is the same as above: that security starts with a good endpoint cybersecurity solution; it should include an effective password management solution; MFA should be enabled; and you should implement a system like Tessian that checks and analyses inbound and outbound emails in real-time and uses machine intelligence to automatically detect if emails contain security threats.

Once you have these key security basics in place, you can continue to improve by crafting a security posture with multiple layers. Don’t forget that cyber criminals are constantly evolving and you should too.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Cybersecurity needs actual intelligence before artificial intelligence
Information Security AI & Data Analytics
Cybersecurity depends on interpretation. A tool can tell you that something unusual has happened, but people need to determine whether it is a genuine risk, the business impact, and how to respond without causing unnecessary disruption.

Read more...
Duxbury Cybersecurity sharpens reseller offering
Duxbury Networking Information Security News & Events
Duxbury Networking has strengthened its Duxbury Cybersecurity business unit by adding WatchGuard and Cynet, giving South African resellers broader, more integrated coverage for the security risks customers are now asking them to address.

Read more...
NEC XON detects and stops ransomware attack
NEC XON Information Security IoT & Automation
Ransomware attacks rarely begin with chaos. More often, they start quietly, with probing, mapping, and patient reconnaissance inside a target’s network. That was the situation facing a global recruitment firm when cybercriminals attempted to navigate its systems.

Read more...
Sara AI Pentesting available in South Africa
Information Security News & Events
Synack and Wolfpack Information Risk are offering Sara AI Pentesting to organisations across South Africa, helping companies move from point-in-time testing to continuous security validation with AI and human expertise.

Read more...
Sophos establishes South African legal entity to strengthen local operations
News & Events Information Security
Global cybersecurity company, Sophos, has announced the formation of its local legal entity, which will support local invoicing, partner enablement, compliance requirements and expanded regional investment.

Read more...
Cybersecurity in a digitally connected security industry
SA Technologies Information Security IoT & Automation
As more organisations move towards digital visitor management, cloud-based access control, mobile applications, biometric verification, and connected security platforms, cybersecurity must be viewed as part of the full security environment.

Read more...
Enterprises must prepare for digital conflict
Information Security
Cyberattacks can be launched remotely and at scale. A coordinated attack launched from anywhere in the world can disrupt supply chains, shut down utilities, or expose millions of customer records within minutes.

Read more...
71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...
Cyber resilience is the real defence
Security Services & Risk Management Information Security Infrastructure
Cyber resilience has evolved into a form of strategic agility, ensuring that when an interruption occurs, the business does not just survive; it snaps back into place before the market even notices a pause.

Read more...
You will not get your files back with VECT
Information Security
If the newbie to the ransomware scene, VECT, comes knocking at your organisation’s door, do not pay the ransom! The decryption keys simply do not exist. They were discarded at the moment of encryption by the malware itself.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.