Innovating your way to better cybersecurity

Issue 1 2022 Information Security

It is estimated that the largest 1000 companies in the world spend US$782 billion[1] on research and development (R&D) – an indication of its importance in the global marketplace.


Edison Mazibuko.

Research from Stanford University highlights the growing cost pressure involved in R&D, with productivity declining by a factor of 41 since the 1930s, working out at around 5% per year. The university translates this into organisations needing to spend considerably more to achieve the same outputs.

Despite the cost implications jumping off the carousel has even worse consequences. Studies from the London School of Economics[2] shows that firms who achieve at least one new product launch per year boost their revenue productivity an estimated 17%, with each new launch adding an extra 22% to their productivity rating. What’s more, the University of Houston found that investing in one’s innovation capacity had a significant impact on both the profitability of firms and their share price – that fact should garner the interest of all business leaders.

Each year, consulting firm PwC conducts an Annual Global CEO Survey[3] with the purpose of understanding which hot-button issues are on the minds of today’s global business leaders. It is reported that over the years, innovation has remained at the forefront of their concerns. This is understandable in light of the number of companies that have entered the market with new disruptive technologies set to upset the apple carts of established businesses, industries and even countries. Media reports abound with stories of agile start-ups upending venerable institutions who failed to remain on the cutting edge of innovation. Innovation wars can leave many companies in their wake.

Part of the problem is that innovation is such a catch-all term that it makes it very difficult to pin down precisely what it means. The reality is that the term can be applied to everything from business models to new processes.

What has innovation got to do with cybersecurity?

The answer to that is – everything. Just look at the innovation applied by criminals on an annual basis, constantly inventing different ways to gain access to your valuable data and ransom it back to you. They constantly reinvent themselves, their technologies, attack methods – why would you think that if you stand still, you can deal with this incredible rate of innovation?

Deloitte[4] notes that definitions of cybersecurity conjure up ideas of technology and IT, particularly centred around the confidentiality, integrity and availability of data. However, as the pace of digital transformation accelerates, cyber risks will continue to manifest through business operations, product launches and other areas of enterprise. They go on to note that as a result, the definition of cybersecurity in the modern world is increasingly diverse and responsive to new and emerging threats.

These threats can manifest from rapid technological innovation if an holistic view of cyber risk is not included in the innovation process. Basically, what that is saying is that as we innovate and produce incredible new technologies that change our lives and businesses, we also need to look at them critically and assess what risks they bring to the business and how these can be mitigated.

As the 4th industrial revolution gains pace with 5G rollouts and more, business leaders and innovators seek to rapidly mobilise new technologies within the transformation process, with the challenge being rapid rollout with mitigated risk. This goal developed into an urgent imperative as the need to operate remotely hit world businesses in the wake of the pandemic.

Cybersecurity policies and strategies need to be designed to support and now halt or slow, the progress of innovation. New technologies and innovations which understand the importance of cybersecurity are better equipped for long-term success and customer trust.

Deloitte confirms that factoring in cyber risks from the outset often leads to more successful outcomes and lower cost when compared with any post implementation fix or bolt-on. They go on to emphasise that cybersecurity augmented by innovation, can propel us forward to an exciting and digitally-enabled world. I would agree with that statement and with one they also put forward and that by being cyber savvy, you can be confident in taking full advantage of every technological opportunity.

The downside is that without business leader education and awareness programmes on this topic, in conjunction with the mitigation of security risk at a company level, companies miss the opportunity to position themselves for sustainable future transformation through innovation.

In Mazibuko’s second article on the topic of innovation and cybersecurity, he will outline how the combination of these two powerful factors can act as business enablers.

[1] https://ideadrop.co/innovation-management/different-types-of-innovation/

[2] https://cep.lse.ac.uk/pubs/download/dp1607.pdf

[3] https://www.pwc.com/ceosurvey

[4] https://www2.deloitte.com/au/en/blog/innovation-blog/2020/what-cybersecurity-do-with-innovation.html




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...
Cyber resilience is the real defence
Security Services & Risk Management Information Security Infrastructure
Cyber resilience has evolved into a form of strategic agility, ensuring that when an interruption occurs, the business does not just survive; it snaps back into place before the market even notices a pause.

Read more...
You will not get your files back with VECT
Information Security
If the newbie to the ransomware scene, VECT, comes knocking at your organisation’s door, do not pay the ransom! The decryption keys simply do not exist. They were discarded at the moment of encryption by the malware itself.

Read more...
Industrial sector is a primary cyber target
Information Security
Threats in industrial environments are distributed with striking uniformity: APT-driven incidents constitute 17,8%, malware 14,9% and social engineering 13,9%. This pattern suggests that industrial organisations attract a broad range of adversaries with different capabilities and objectives.

Read more...
Key attributes of an effective cybersecurity leader
BlueVision Information Security
In an evolving technology landscape, an effective cyber leader must combine technical acumen, foresight, and adaptive leadership to mitigate risks, and risks can only be mitigated once accurately identified and remedial processes are in place.

Read more...
Employees are SA’s biggest cyber threat
Security Services & Risk Management Information Security
South Africa experienced a 46% increase in insider cyber risk in 2026, surpassing the global average of 44%. What is more, 63% of South African companies surveyed expect insider-driven data losses to increase.

Read more...
Surge in AI-enabled cybercrime and a 389% increase in ransomware
News & Events Information Security
Cybercrime no longer functions as a series of isolated campaigns; it operates as a system, with malicious hackers operating across an end-to-end life cycle and compressing the attack life cycle with shadow agents.

Read more...
Tackling enterprise security ‘tool sprawl’
NEC XON Information Security
South African ICT solutions provider NEC XON is advocating a shift away from fragmented cybersecurity toolsets towards unified platforms, arguing that ‘tool sprawl’ is undermining the effectiveness of enterprise security operations.

Read more...
SilverFox campaign targeting companies in South Africa
Information Security News & Events
The APT campaign involved disguising malicious files as documents related to tax violations. Upon infection, attackers could gain remote access to affected devices and exfiltrate sensitive organisational data.

Read more...
Q-Day is closer than you think
Information Security
The accelerated 2029 quantum computing deadline turns current encryption into a looming crisis as Google brings its internal post-quantum cryptography migration deadline forward to 2029.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.