Compliance is knowing

October 2017 Information Security, Infrastructure

You cannot swing a laptop without hitting a major data breach these days. Internationally there are lawsuits launched every day. Security officers are being raked over the coals and their integrity and qualifications are being scrutinised and questioned. People are infuriated by the losses, financial and reputational (even worse) to their businesses and themselves.

John Mc Loughlin MD, J2 Software.
John Mc Loughlin MD, J2 Software.

Does anyone really think there is anything different in South Africa?

The latest string of major breaches are aimed at businesses with security budgets that are larger than the annual turnover of most South African businesses. It is nothing short of naïve to think this can’t happen or is not actually happening, to you.

I live by the mantra that there are two types of businesses – those who have been breached and those that don’t know that they have been breached. Do you know where your business fits in? We live in a South Africa driven by digital migrations and evolving data security and compliance laws and regulations, the life of the chief information officer (CIO) is complex. Where should they start?

The CIO must work with the business to work out how to provide data to internal staff for them to do their jobs while keeping it secure, preventing external leaks and stopping data theft. This individual is also the one who is responsible to ensure that the business or public entity complies with PAIA and PoPI.

Is there any way this can be achieved without real visibility? Policies will always be the starting point, but without effective visibility on real usage there is no way to know that there is compliance.

Let me give you an example: your policy states that any data stored or used on a corporate asset that contains personal information must be encrypted and should not be moved or copied outside of the organisation’s secured environment. This makes sense, right? So now think about your environment, do you know:

1. How many external storage devices were inserted into any corporate asset in the last 24 hours, 7 days, etc.?

2. How many users are accessing free cloud storage platforms like Google Drive, OneDrive, Dropbox, etc.?

3. What data was copied or moved or uploaded to any of these?

4. What about a user who has copied data onto their PC desktop and renamed a file? Can you tell what they did next?

5. Has data been copied out of the ERP, HR or other system and then placed into a Word document or Excel spreadsheet?

6. Do you still think your data is secure and you are compliant with laws and your own internal policies?

The other method to help with these issues often means a business will buy a string of solutions or tools to protect data. A bit of encryption here, a firewall analysis platform there, desktop DLP over there. We then end up having a large group of tools and nobody to check them. The silky tongued sales person showed them this amazing solution and yet it sits unmanaged, reporting to nobody or simply not deployed.

You do not need to look at new tools, you need to get visibility and a partner. Please ensure that you do not simply find a product provider; make sure the information security company is a strategic business partner. The right partner will identify holes, develop a plan to cover them and also guarantee ongoing support and guidance to continually improve your data security compliance and become an integral part of your continued business success.

When you choose the right partner you will be able to rest easy and focus on your business, knowing that your data security is in good hands. The right partner can provide you with the necessary action, remediation, monitoring, alerting and should then also provide the management and risk committee reports to ensure ongoing compliance.

For more information contact J2 Software, +27 (0)87 238 1870, john@j2.co.za, www.j2.co.za





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Who are you?
Access Control & Identity Management Information Security
Who are you? This question may seem strange, but it can only be answered accurately by implementing an Identity and Access Management (IAM) system, a crucial component of any company’s security strategy.

Read more...
Check Point launches African Perspectives on Cybersecurity report
News & Events Information Security
Check Point Software Technologies released its African Perspectives on Cybersecurity Report 2025, revealing a sharp rise in attacks across the continent and a major shift in attacker tactics driven by artificial intelligence

Read more...
What is your ‘real’ security posture?
BlueVision Editor's Choice Information Security Infrastructure AI & Data Analytics
Many businesses operate under the illusion that their security controls, policies, and incident response plans will hold firm when tested by cybercriminals, but does this mean you are really safe?

Read more...
What is your ‘real’ security posture? (Part 2)
BlueVision Editor's Choice Information Security Infrastructure
In the second part of this series of articles from BlueVision, we explore the human element: social engineering and insider threats and how red teaming can expose and remedy them.

Read more...
Onsite AI avoids cloud challenges
SMART Security Solutions Technews Publishing Editor's Choice Infrastructure AI & Data Analytics
Most AI programs today depend on constant cloud connections, which can be a liability for companies operating in secure or high-risk environments. That reliance exposes sensitive data to external networks, but also creates a single point of failure if connectivity drops.

Read more...
Sophos announces evolution of its security operations portfolio
Information Security
Sophos has announced significant enhancements to its security operations portfolio via Sophos XDR and Sophos MDR offerings, marking an important milestone in its integration journey following the acquisition of Secureworks in February 2025.

Read more...
Cybersecurity operations done right
LanDynamix SMART Security Solutions Technews Publishing Information Security
For smaller companies, the costs associated with acquiring the necessary skills and tools can be very high. So, how can these organisations establish and maintain their security profile amid constant attacks and evolving technology?

Read more...
AI security with AI Cloud Protect
Information Security
AI Cloud Protect is now available for on-premises enterprise deployments to secure AI model development, agentic AI applications, and inference workloads with zero impact on performance.

Read more...
Kaspersky finds security flaws that threaten vehicle safety.
News & Events Information Security Transport (Industry)
At its Security Analyst Summit 2025, Kaspersky presented the results of a security audit that exposed a significant security flaw enabling unauthorised access to all connected vehicles of one automotive manufacturer.

Read more...
The overlooked risks of everyday connectivity
Information Security
That free Wi-Fi you are using could end up costing you a lot more money than your hotspot data if it has been compromised, says Richard Frost, head of technology solutions and consulting at Armata Cyber Security.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.