Compliance is knowing

October 2017 Information Security, Infrastructure

You cannot swing a laptop without hitting a major data breach these days. Internationally there are lawsuits launched every day. Security officers are being raked over the coals and their integrity and qualifications are being scrutinised and questioned. People are infuriated by the losses, financial and reputational (even worse) to their businesses and themselves.

John Mc Loughlin MD, J2 Software.
John Mc Loughlin MD, J2 Software.

Does anyone really think there is anything different in South Africa?

The latest string of major breaches are aimed at businesses with security budgets that are larger than the annual turnover of most South African businesses. It is nothing short of naïve to think this can’t happen or is not actually happening, to you.

I live by the mantra that there are two types of businesses – those who have been breached and those that don’t know that they have been breached. Do you know where your business fits in? We live in a South Africa driven by digital migrations and evolving data security and compliance laws and regulations, the life of the chief information officer (CIO) is complex. Where should they start?

The CIO must work with the business to work out how to provide data to internal staff for them to do their jobs while keeping it secure, preventing external leaks and stopping data theft. This individual is also the one who is responsible to ensure that the business or public entity complies with PAIA and PoPI.

Is there any way this can be achieved without real visibility? Policies will always be the starting point, but without effective visibility on real usage there is no way to know that there is compliance.

Let me give you an example: your policy states that any data stored or used on a corporate asset that contains personal information must be encrypted and should not be moved or copied outside of the organisation’s secured environment. This makes sense, right? So now think about your environment, do you know:

1. How many external storage devices were inserted into any corporate asset in the last 24 hours, 7 days, etc.?

2. How many users are accessing free cloud storage platforms like Google Drive, OneDrive, Dropbox, etc.?

3. What data was copied or moved or uploaded to any of these?

4. What about a user who has copied data onto their PC desktop and renamed a file? Can you tell what they did next?

5. Has data been copied out of the ERP, HR or other system and then placed into a Word document or Excel spreadsheet?

6. Do you still think your data is secure and you are compliant with laws and your own internal policies?

The other method to help with these issues often means a business will buy a string of solutions or tools to protect data. A bit of encryption here, a firewall analysis platform there, desktop DLP over there. We then end up having a large group of tools and nobody to check them. The silky tongued sales person showed them this amazing solution and yet it sits unmanaged, reporting to nobody or simply not deployed.

You do not need to look at new tools, you need to get visibility and a partner. Please ensure that you do not simply find a product provider; make sure the information security company is a strategic business partner. The right partner will identify holes, develop a plan to cover them and also guarantee ongoing support and guidance to continually improve your data security compliance and become an integral part of your continued business success.

When you choose the right partner you will be able to rest easy and focus on your business, knowing that your data security is in good hands. The right partner can provide you with the necessary action, remediation, monitoring, alerting and should then also provide the management and risk committee reports to ensure ongoing compliance.

For more information contact J2 Software, +27 (0)87 238 1870, [email protected], www.j2.co.za





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Cybersecurity needs actual intelligence before artificial intelligence
Information Security AI & Data Analytics
Cybersecurity depends on interpretation. A tool can tell you that something unusual has happened, but people need to determine whether it is a genuine risk, the business impact, and how to respond without causing unnecessary disruption.

Read more...
Duxbury Cybersecurity sharpens reseller offering
Duxbury Networking Information Security News & Events
Duxbury Networking has strengthened its Duxbury Cybersecurity business unit by adding WatchGuard and Cynet, giving South African resellers broader, more integrated coverage for the security risks customers are now asking them to address.

Read more...
NEC XON detects and stops ransomware attack
NEC XON Information Security IoT & Automation
Ransomware attacks rarely begin with chaos. More often, they start quietly, with probing, mapping, and patient reconnaissance inside a target’s network. That was the situation facing a global recruitment firm when cybercriminals attempted to navigate its systems.

Read more...
Sara AI Pentesting available in South Africa
Information Security News & Events
Synack and Wolfpack Information Risk are offering Sara AI Pentesting to organisations across South Africa, helping companies move from point-in-time testing to continuous security validation with AI and human expertise.

Read more...
Sophos establishes South African legal entity to strengthen local operations
News & Events Information Security
Global cybersecurity company, Sophos, has announced the formation of its local legal entity, which will support local invoicing, partner enablement, compliance requirements and expanded regional investment.

Read more...
From drone market growth to application-level commercialisation
IoT & Automation Infrastructure
After years of pilot projects and technology validation, the question for the market is shifting from whether drones can fly safely and collect data, to where they can deliver repeatable operational value at scale.

Read more...
Cybersecurity in a digitally connected security industry
SA Technologies Information Security IoT & Automation
As more organisations move towards digital visitor management, cloud-based access control, mobile applications, biometric verification, and connected security platforms, cybersecurity must be viewed as part of the full security environment.

Read more...
Enterprises must prepare for digital conflict
Information Security
Cyberattacks can be launched remotely and at scale. A coordinated attack launched from anywhere in the world can disrupt supply chains, shut down utilities, or expose millions of customer records within minutes.

Read more...
AI-enabled NVR for Milestone XProtect
Surveillance Infrastructure Products & Solutions
As surveillance environments continue to grow in scale and complexity, organisations need infrastructure that is easy to deploy, simple to manage, and ready for AI-driven workloads.

Read more...
71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.