Managing data privacy concerns when moving to the cloud

Issue 7 2022 Information Security


Gary Allemann.

While the cloud offers many business benefits, it can also raise concerns around compliance, and some organisations have taken the approach of staying out of the cloud for this reason. However, while legislation such as the Protection of Personal Information Act (PoPIA) does add a layer of complexity to a cloud migration, the reality is that these laws apply regardless of where data is stored, and we need one policy to govern data across the entire environment.

When it comes to PoPIA compliance, it is important to understand that the law has several classifications of data that needs to be protected, including data that deals with children, sensitive information such as religious affiliation and medical history, and personally identifying information such as ID numbers. It all needs to be protected under the law, but how that is done may differ according to the classification it falls under.

For businesses, data protection isn’t just about the law either. All sorts of data is generated and contained within a business which could be detrimental if it falls into the wrong hands, including intellectual property such as new products and business innovation, as well as financial information.

The danger lies on the inside

Every business is different, and every business’s data is unique, so there is no one-size-fits-all approach that will work, either for compliance or business reasons and whether data is stored on-premises or in the cloud. However, one common factor seen with the majority of recent breaches and security incidents is that they have arisen through the abuse of authorised privileges. What does this mean? It simply means that malicious actors have gained access to a data profile – through whatever means, including phishing or another cyberthreat – that has permission to access data that it should not be able to access.

Data permissions are frequently too broad, granting far too much access. This means that should someone with malicious intentions gain access to an authorised user profile, they will be able to see more than they should and do things like delete, copy or share data, which also should not be permitted. Data security and data privacy both come down to the need for more granular access control and permissioning.

So how do we manage data privacy?

We need to define policies that limit data access only to that which people need to do their job, based on the individual and their context within the organisation. Data access can be filtered by role, by geography, by specific region and even by data subject, and once segmented it can be further limited at an aggregate level. Then, if someone with malicious intent gains access, the damage they are able to do is extremely limited.

Requirements for data security and privacy have evolved and it has become imperative to deliver fine-grained access control down to the individual level, irrespective of whether data is housed in the cloud or not. Security policies must be applied, consistently measured to ensure they are being followed, and processes need to be put into place to alert to unusual behaviours that may signal a breach or malicious activity, respond to a breach and identify what has been compromised.

The bulk of data breaches are caused by too much access to data and these privileges being abused. This needs to be addressed, and while the cloud obviously adds a layer of technical complexity to this exercise, the principles remain the same. It all comes back to data management and data governance – if you haven’t defined what data you have and classified it, it is impossible to apply data access control.

At a media briefing in late June, advocate Lebogang Stroom-Nzama, a full-time member of the Information Regulator, announced that its patience with transgressors was wearing thin. Whilst the stance to date has been to educate, in the future, potential fines of up to R10 million, as legislated by PoPIA, will be a more likely outcome of breaches.

An integrated solution that provides a consistent, reusable, repeatable and auditable process across multiple platforms is the answer to addressing this technical complexity and managing data privacy and PoPIA compliance, both on-premises and when moving into the cloud.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Cybersecurity needs actual intelligence before artificial intelligence
Information Security AI & Data Analytics
Cybersecurity depends on interpretation. A tool can tell you that something unusual has happened, but people need to determine whether it is a genuine risk, the business impact, and how to respond without causing unnecessary disruption.

Read more...
Duxbury Cybersecurity sharpens reseller offering
Duxbury Networking Information Security News & Events
Duxbury Networking has strengthened its Duxbury Cybersecurity business unit by adding WatchGuard and Cynet, giving South African resellers broader, more integrated coverage for the security risks customers are now asking them to address.

Read more...
NEC XON detects and stops ransomware attack
NEC XON Information Security IoT & Automation
Ransomware attacks rarely begin with chaos. More often, they start quietly, with probing, mapping, and patient reconnaissance inside a target’s network. That was the situation facing a global recruitment firm when cybercriminals attempted to navigate its systems.

Read more...
Sara AI Pentesting available in South Africa
Information Security News & Events
Synack and Wolfpack Information Risk are offering Sara AI Pentesting to organisations across South Africa, helping companies move from point-in-time testing to continuous security validation with AI and human expertise.

Read more...
Sophos establishes South African legal entity to strengthen local operations
News & Events Information Security
Global cybersecurity company, Sophos, has announced the formation of its local legal entity, which will support local invoicing, partner enablement, compliance requirements and expanded regional investment.

Read more...
Cybersecurity in a digitally connected security industry
SA Technologies Information Security IoT & Automation
As more organisations move towards digital visitor management, cloud-based access control, mobile applications, biometric verification, and connected security platforms, cybersecurity must be viewed as part of the full security environment.

Read more...
Enterprises must prepare for digital conflict
Information Security
Cyberattacks can be launched remotely and at scale. A coordinated attack launched from anywhere in the world can disrupt supply chains, shut down utilities, or expose millions of customer records within minutes.

Read more...
71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...
Cyber resilience is the real defence
Security Services & Risk Management Information Security Infrastructure
Cyber resilience has evolved into a form of strategic agility, ensuring that when an interruption occurs, the business does not just survive; it snaps back into place before the market even notices a pause.

Read more...
You will not get your files back with VECT
Information Security
If the newbie to the ransomware scene, VECT, comes knocking at your organisation’s door, do not pay the ransom! The decryption keys simply do not exist. They were discarded at the moment of encryption by the malware itself.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.