Deception technology crucial to unmasking data theft

March 2024 Information Security, Security Services & Risk Management


Iniel Dreyer.

The ‘silent theft’ of data is an increasingly prevalent cyber threat to businesses, driving the ongoing leakage of personal information in the public domain through undetected attacks that cannot even be policed by data privacy legislation. As the term implies, the exfiltration of data from corporate networks is often done without even the target themselves being aware of the attack. In such cases, cybercriminals only want to steal personal information—without being detected. This data is then sold for a tidy profit.

While the Protection of Personal Information Act (PoPIA) in South Africa was designed to safeguard personal data from theft, misuse, and malicious activities, the legislation cannot be applied to undetected and thus, unreported attacks.

Unlike a ransomware attack, the ‘silent theft’ of data does not involve financial extortion and the encryption of information. Instead, hackers steal valuable data from organisations to sell on the dark web. This illicit practice is largely behind the proliferation of spam calls and marketing that flood ordinary people's lives, not to mention the increase in banking fraud.

Lack of alignment

The gap between PoPIA's aims and companies’ approaches to data protection can be found in the lack of alignment between the business and IT divisions' goals. The business, which has certain legal requirements to meet in terms of data privacy, must be able to rely on the IT division to ensure compliance.

Unfortunately, the two divisions often talk past each other, resulting in the acquisition of technology tools and solutions that ultimately do not meet business needs. Since the money has been spent, companies tend to try to reverse-engineer the solutions to make them work, which is often when things go wrong.

Most organisations only realise they have been compromised when they are asked for a ransom, so ‘silent theft’ continues undetected. That is because most organisations do not have the right security tools in place to detect this type of attack.

To defeat attackers whose aim it is to stay on a corporate network for as long as they can before being caught, organisations must look towards deception technology, which will help them respond proactively to an infiltration before any real damage is done. With data theft, it is crucial to be proactive as, once the information is stolen, nothing can be done about it.

Fooling the hacker

Deception technology deploys honeypots, which are fake assets and systems on an organisation’s network that a hacker perceives as a real system. These decoys can imitate any IT equipment or applications and typically have a vulnerability that makes them tempting to attack.

When attacked, honeypots will alert the network administration team that an intrusion has been detected. Deception technology can also detect the origin of the attack, where access was gained to the network, and the type of device used to carry out the hack. This allows IT teams to take the necessary steps to prevent the attackers from causing any real harm.

It is key that companies have a security framework and posture in place, and must understand what products they have and whether these meet their specific requirements for cyber resiliency. Cyber resiliency enables companies to defend against cyberattacks, and part of this is proactive data management to prevent unauthorised access to sensitive data.

A backup and recovery strategy is not enough to stop the ‘silent theft’ of data. A more proactive stance should be adopted through the deployment of deception technology. However, organisations must ensure that they engage a competent service provider to implement and support cyber resiliency within their environment.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

New ransomware using BitLocker to encrypt data
Technews Publishing Information Security Residential Estate (Industry)
Kaspersky has identified ransomware attacks using Microsoft’s BitLocker to attempt encryption of corporate files. It can detect specific Windows versions and enable BitLocker according to those versions.

Read more...
Using KPIs to measure smart city progress
Axis Communications SA Residential Estate (Industry) Integrated Solutions Security Services & Risk Management
United 4 Smart Sustainable Cities is a United Nations Initiative that encourages the use of information and communication technology (including security technology) to support a smooth transition to smart cities.

Read more...
Enhancing estate security, the five-layer approach
Fang Fences & Guards Residential Estate (Industry) Integrated Solutions Security Services & Risk Management
Residential estates are designed to provide a serene and secure living environment enclosed within gated communities, offering residents peace of mind and an elevated standard of living.

Read more...
Create order from chaos
Information Security
The task of managing and interpreting vast amounts of data is akin to finding a needle in a haystack. Cyberthreats are growing in complexity and frequency, demanding sophisticated solutions that not only detect, but also prevent, malicious activities effectively.

Read more...
Trend Micro launches first security solutions for consumer AI PCs
Information Security News & Events
Trend Micro unveiled its first consumer security solutions tailored to safeguard against emerging threats in the era of AI PCs. Trend will bring these advanced capabilities to consumers in late 2024.

Read more...
Kaspersky finds 24 vulnerabilities in biometric access systems
Technews Publishing Information Security
Customers urged to update firmware. Kaspersky has identified numerous flaws in the hybrid biometric terminal produced by international manufacturer ZKTeco, allowing a nefarious actor to bypass the verification process and gain unauthorised access.

Read more...
Responsible AI boosts software security
Information Security
While the prevalence of high-severity security flaws in applications has dropped slightly in recent years, the risks posed by software vulnerabilities remain high, and remediating these vulnerabilities could hinder new application development.

Read more...
AI and ransomware: cutting through the hype
AI & Data Analytics Information Security
It might be the great paradox of 2024: artificial intelligence (AI). Everyone is bored of hearing it, but we cannot stop talking about it. It is not going away, so we had better get used to it.

Read more...
Local manufacturing is still on the rise
Hissco Editor's Choice News & Events Security Services & Risk Management
HISSCO International, Africa's largest manufacturer of security X-ray products, has recently secured a multi-continental contract to supply over 55 baggage X-ray screening systems in 10 countries.

Read more...
NEC XON shares lessons learned from ransomware attacks
NEC XON Editor's Choice Information Security
NEC XON has handled many ransomware attacks. We've distilled key insights and listed them in this article to better equip companies and individuals for scenarios like this, which many will say are an inevitable reality in today’s environment.

Read more...