Organisations fear AI-driven cyberattacks, but lack key defences

December 2024 Information Security, News & Events, Training & Education

A recent Kaspersky study reveals that businesses are increasingly worried about the growing use of artificial intelligence (AI) in cyberattacks. According to the findings, 56% of surveyed companies in South Africa reported a rise in cyber incidents over the past year, with almost half of respondents (47%) noting that many of these attacks were likely AI-driven.

The study underscores the reality that AI, which has revolutionised numerous industries, is now also empowering cybercriminals, adding an additional layer of complexity to the threats businesses face.

In its latest study titled Cyber defence & AI: Are you ready to protect your organisation? Kaspersky gathered the opinions of IT Security and Information Security professionals working for SMEs and Enterprise-level companies regarding new challenges in protecting their organisations against cyberattacks involving AI.

Leveraging AI by cybercriminals is a serious concern for 76% of respondents from South Africa. The pressure of this challenge is pushing companies to re-assess their cybersecurity strategies and look for proactive and comprehensive solutions. To effectively tackle AI-amplified threats, businesses in South Africa consider regular training to build internal expertise (98%), highly qualified personnel (98%), and relevant external cybersecurity expertise (98%) as the most important factors for protecting their organisations. They also recognise the importance of having enough staff in their IT teams (96%) and using third-party security solutions (91%).

Despite rising awareness, the study reveals a concerning gap in readiness among many companies. Just under half of the organisations surveyed in South Africa lack crucial resources needed to address these sophisticated threats – 44% do not have the relevant external cybersecurity expertise at their disposal, 38% report that their IT teams are not large enough, 36% lack highly qualified staff, and 31% fall short in regular training efforts.

Additionally, 42% of respondents do not think they have adequate security solutions, exposing them to potential vulnerabilities. While most respondents claim to know how to address this lack of resources, the fact remains that they are not in place.

“The cybersecurity landscape today mirrors past challenges, with businesses questioning if current solutions suffice. Ransomware, once a primary threat, now demonstrates a dangerous surge, and business decision-makers start questioning the causes of this resurgence. The recent hype around AI offers an easy, if not entirely correct, explanation. In reality, while using AI to create convincing phishing messages or more effective reconnaissance may be of some help, the root causes are most often more straightforward; cybercriminals have become more organised, better at collaborating, developing innovative attack strategies, and lowering the barriers for less skilled and resourceful attackers.”

“So, while it is useful to keep an eye on AI progress that can enable both attackers and defenders with new options, there are solid strategies companies can – and should – implement immediately. Companies should prioritise securing critical IT infrastructure with robust, multi-layered solutions that offer a unified security context. An XDR ecosystem, combined with skilled expertise – whether in-house or through a managed service – can greatly enhance defences.

Additionally, ongoing employee training, including cybersecurity basics and safe AI practices, adds another critical layer of protection for the organisation,” says Oleg Gorobets, a corporate infrastructure protection expert at Kaspersky.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

What is your ‘real’ security posture?
BlueVision Editor's Choice Information Security Infrastructure AI & Data Analytics
Many businesses operate under the illusion that their security controls, policies, and incident response plans will hold firm when tested by cybercriminals, but does this mean you are really safe?

Read more...
What is your ‘real’ security posture? (Part 2)
BlueVision Editor's Choice Information Security Infrastructure
In the second part of this series of articles from BlueVision, we explore the human element: social engineering and insider threats and how red teaming can expose and remedy them.

Read more...
The HR Trap
Security Services & Risk Management Training & Education
When human resources becomes a risk factor. Andre du Venage examines why your CCTV security and other technology risks are covered, but human resources are often overlooked.

Read more...
Sophos announces evolution of its security operations portfolio
Information Security
Sophos has announced significant enhancements to its security operations portfolio via Sophos XDR and Sophos MDR offerings, marking an important milestone in its integration journey following the acquisition of Secureworks in February 2025.

Read more...
Kaspersky finds security flaws that threaten vehicle safety.
News & Events Information Security Transport (Industry)
At its Security Analyst Summit 2025, Kaspersky presented the results of a security audit that exposed a significant security flaw enabling unauthorised access to all connected vehicles of one automotive manufacturer.

Read more...
The overlooked risks of everyday connectivity
Information Security
That free Wi-Fi you are using could end up costing you a lot more money than your hotspot data if it has been compromised, says Richard Frost, head of technology solutions and consulting at Armata Cyber Security.

Read more...
Syndicates exploit insider vulnerabilities in SA
Information Security Security Services & Risk Management
Today’s cyber criminals do not just exploit vulnerabilities in your systems; they exploit your people, turning trusted team members into unwitting accomplices or deliberate collaborators in their schemes.

Read more...
GenAI fraud forcing banks to shift from identity to intent
AI & Data Analytics Information Security Financial (Industry)
The complexity and velocity of modern fraud schemes, from deepfakes to fraud and scams involving social engineering, demand more than just investment in new tools; they need adaptability and expanding the security net.

Read more...
Global Threat Intelligence Report for October 2025
Information Security News & Events
Africa was pipped to the post as the most attacked region by Latin America, which averaged 2966 attacks per organisation per week (+16% YoY). Africa followed with (2782, – 15%) and APAC (2703, – 8%).

Read more...
Business logic vulnerabilities: the silent cyberthreat
Information Security
New Magix R&D Lab white paper helps local businesses identify hidden cybersecurity weaknesses that do not stem from the usual coding errors or configuration flaws that security tools are designed to detect.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.