Growing cyber threats to SA’s critical infrastructure

Issue 6 2023 News & Events, Information Security, Industrial (Industry)

The increasing reliance on digital infrastructure makes critical sectors like utilities more susceptible to cyber threats. This concern has been highlighted by Kaspersky's recent discovery of a new SystemBC variant that has targeted a South African nation's critical infrastructure.

This backdoor was found alongside Cobalt Strike beacons, which are reminiscent of the 2021 Darkside Colonial Pipeline incident. Furthermore, Kaspersky research shows that malware was detected and blocked on 29,1% of Industrial Control System (ICS) computers in South Africa in the first half of 2023. Looking more broadly at the continent, Africa sits in first place among other regions with the highest number of industrial systems under attack in H1 2023, where attacks were detected on 40,3% of ICS computers, with the energy sector being the top industry under attack (45,9%).

South Africa is currently in the throes of persistent and varying stages of load shedding as a result of prevailing maintenance and upgrade constraints that continue to threaten the stability of the country’s power supply in the short term. Contending with additional clear and present cybersecurity risks further compounds the pressure on this very infrastructure and those charged with keeping the lights on.

"Cybercriminal activity is constantly evolving. While there is a decline in the number of global attacks, we are witnessing a surge in Advanced Persistent Threats (APTs) that are more strategically targeted, especially towards sectors like critical infrastructure," says Brandon Muller, technology expert and consultant for the MEA region at Kaspersky. "Such attacks are continuous, sophisticated, and when successful, can result in severe damage, financial loss, and extended downtime."

According to Kaspersky, threat actors are concentrating on specific targets to reap maximum benefits. The protection against these threats requires a layered approach. It begins with a focus on critical infrastructure protection; Kaspersky Industrial Cybersecurity solutions emphasise the need for strong cyber defences. Given the intricacies of cyberattacks on crucial sectors, businesses must stay updated with endpoint protection solutions, restrict VPN access where not needed, ensure backup copies are stored on dedicated servers, and consider implementing Endpoint Detection and Response-type (EDR) security solutions for both IT and OT networks. Kaspersky also recommends Managed Detection and Response (MDR) services for immediate access to top-tier security expertise.

The next evolutionary step in cybersecurity is Cyber Immunity. Kaspersky’s Secure by Design ideology underscores the need to think about security right from the design phase. By understanding specific security requirements for each project, businesses can create truly secure systems. A foundational understanding of security goals and assumptions is vital.

The utilities sector is undergoing unprecedented change. Digital transformation, decarbonisation, renewables, and regulatory challenges are shaping its future.

"South Africa's utilities sector is the lifeblood for many industries. The rapid changes, both in terms of digital transformation and the shift towards renewables, are commendable, however, cybersecurity cannot be an afterthought. The blend of innovative technology and top-tier security solutions is the key to ensuring uninterrupted services," Muller added.

Find local Kaspersky suppliers at https://hsbd.co.za/search.aspx?match=substring&type=all&string=kaspersky




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Woolworths attack raises bomb preparedness questions
News & Events
Two explosions have been reported at Woolworths stores in South Africa over the past week. SMART Security Solutions asked Jimmy Roodt, an experienced and accredited explosive ordnance disposal specialist from Gauntlet Security Solutions, for his insight into the events.

Read more...
Growing adoption of AI at work
News & Events AI & Data Analytics
AI adoption accelerates worldwide, with South Africa making gains amid uneven diffusion. Locally, South Africa ranks 46th of 147 economies measured, and its AI usage increased to 23,1% in Q1 2026.

Read more...
Enterprise AI hits the wall
News & Events AI & Data Analytics
Demands for AI privacy and sovereignty expose the limits of architectures built for centralised and borderless data flows. Organisations that redesign early are gaining a measurable edge in AI readiness and scale.

Read more...
71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...
From the Editor's desk: Security goes mainstream
Technews Publishing News & Events
      Welcome to SMART Security’s SMART Mining & Industrial Security Handbook 2026. While the world is focused on cybersecurity and AI, physical security has become a board-level concern across South Africa’s ...

Read more...
Global security in 2026
Editor's Choice News & Events Security Services & Risk Management Industrial (Industry) Mining (Industry)
The World Security Report 2026 states: “In a world of increasing volatility, physical security has evolved. It is no longer just a defensive measure; it is a critical driver of corporate value.”

Read more...
Who is to blame for autonomous mistakes?
Editor's Choice Security Services & Risk Management Industrial (Industry) Mining (Industry)
Most supply agreements for AI-integrated equipment still closely resemble plant hire contracts from ten years ago: bilateral, human-focused, and silent on who bears the risk when a machine makes a decision on its own.

Read more...
Industry perspective on industrial cybersecurity
Technews Publishing News & Events Infrastructure Industrial (Industry)
The Industrial Security Harmonization Group has released a joint industry perspective highlighting a critical truth in industrial cybersecurity: secure communication is not determined by protocols alone, but by how they are deployed and managed in real-world environments.

Read more...
Cyber resilience is the real defence
Security Services & Risk Management Information Security Infrastructure
Cyber resilience has evolved into a form of strategic agility, ensuring that when an interruption occurs, the business does not just survive; it snaps back into place before the market even notices a pause.

Read more...
Controlling access for people and vehicles
IDEMIA STid Security Technews Publishing Editor's Choice Access Control & Identity Management Asset Management Industrial (Industry) Mining (Industry)
When it comes to access control, the security requirements of mines and the industrial sector are similar, requiring a layered approach that combines physical barriers, digital authentication, and continuous monitoring to protect personnel, assets, and operational continuity.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.