Criminal focus is on apps

March 2013 Information Security

The growth in cybercrime generally is well reported, but South African businesses are still not taking it seriously enough – particularly when it comes to application security. According to research firm Gartner, 75% of attacks are directed at the application layer and 75% of successful attacks target vulnerabilities that were already known.

“These statistics tell us both that not enough attention is being given to security in general, and application security in particular,” says Ziaan Hattingh, managing director of IndigoCube, a company that focuses on improving the productivity and predictability of key business processes in large organisations. “And when one considers that South Africa is the third most targeted country for cybercrime, then it is clear we have a major threat on our hands.”

Because there is no legislation mandating the reporting of cybercrime, local statistics are not accurate, and the real picture could be much more serious than we think. Cybercrime cost South African citizens and businesses more than R1 billion in 2011, according to Sebastian von Solms, research professor in the Academy for Computer Science and Software Engineering at the University of Johannesburg. And Symantec said that cybercrime in South Africa was moving down the value chain to target even smaller businesses.

A key problem, Hattingh believes, is that many leaders focus their attention on access control and infrastructure security. What gets left out is Web application testing and source code analysis – the two methods for testing the security of the application layer. Common vulnerabilities include SQL injection and cross-site scripting, which enable hackers to obtain access to systems and, crucially, the data they contain.

“Data is the big prize, because it is the key to unlocking access to individual and corporate funds,” Hattingh says. “Security testing is vital to understand where your applications are vulnerable – without that understanding, it would be impossible to fix it.”

Software testing came into being because developers do make mistakes, and some of these mistakes could lead to security vulnerabilities. Therefore, it stands to reason that security testing should form part of the bigger software testing or quality control function. And, as Hattingh points out, the sooner a security breach is detected in the software development process, the cheaper it is to fix.

Pending legislation is set to compel South African companies to take the protection of personal data more seriously – the Protection of Personal Information Bill will, when it becomes law, impose liability on an organisation for security breaches. This will bring South Africa into line with other countries that have already enacted data-protection legislation.

It is not all doom and gloom, though. There are numerous resources to help managers come to grips with security in general, and Web applications in particular, Hattingh notes. More particularly, the Open Web Application Security Project (OWASP) has developed a Software Assurance Maturity Model that provides a guide to building security into software development.

“Business today is all about opening up to partners and customers, and that openness increases both the opportunity for growth and the risk of data loss,” says Hattingh. “We need to take action to secure our applications.”

For more information contact IndigoCube, +27 (0)11 749 4950, [email protected], www.indigocube.co.za





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Want effective Attack Surface Management? Think like an attacker.
Information Security
Effective ASM requires companies to think like attackers, anticipate risks, and act decisively to reduce exposure by knowing their environment, deploying a structured approach, leveraging capable tools, and addressing both internal and external risks.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
POPIA non-compliance puts municipalities at risk
Information Security Government and Parastatal (Industry)
Digital responsibility must go beyond POPIA compliance to recognising that privacy and service delivery are fundamentally linked. Despite this, only 51 out of 257 municipalities submitted their mandatory data protection and access to information reports in 2024.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Most wanted malware
News & Events Information Security
Check Point Software Technologies unveiled its Global Threat Index for June 2025, highlighting a surge in new and evolving threats. Eight African countries are among the most targeted as malware leaders AsyncRAT and FakeUpdates expand.

Read more...
Welcome to the new cyber battleground
Information Security
The Iran-Israel conflict is rapidly redefining modern warfare, pushing the boundaries of cyber capabilities and creating a new, borderless digital battlefield. Fortinet’s CISO, Dr Carl Windsor, offers a critical, in-depth analysis of the escalating tactics and global implications in his latest report.

Read more...
African industries may overestimate cyber defences
Information Security
] A significant perception gap exists in security awareness training: 68% of leaders believe training is tailored to roles, yet only a third of employees feel adequately trained. Many organisations only conduct annual or biannual generic training that may not effectively change behaviour.

Read more...
SMARTpod talks to Sophos and Phishield
SMART Security Solutions Technews Publishing Sophos Videos Information Security News & Events
SMARTpod recently spoke with Pieter Nel, Sales Director for SADC at Sophos, and Sarel Lamprecht, MD at Phishield, about ransomware and their new cyber insurance partnership.

Read more...
Cybersecurity and insurance partnership for sub-Saharan Africa
Sophos News & Events Information Security Security Services & Risk Management
Sophos and Phishield Announce first-of-its-kind cybersecurity and insurance partnership for sub-Saharan Africa. The SMARTpod podcast, discussing the deal and the state of ransomware in South Africa and globally, is now also available.

Read more...
Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.