Compliance is knowing

October 2017 Information Security, Infrastructure

You cannot swing a laptop without hitting a major data breach these days. Internationally there are lawsuits launched every day. Security officers are being raked over the coals and their integrity and qualifications are being scrutinised and questioned. People are infuriated by the losses, financial and reputational (even worse) to their businesses and themselves.

John Mc Loughlin MD, J2 Software.
John Mc Loughlin MD, J2 Software.

Does anyone really think there is anything different in South Africa?

The latest string of major breaches are aimed at businesses with security budgets that are larger than the annual turnover of most South African businesses. It is nothing short of naïve to think this can’t happen or is not actually happening, to you.

I live by the mantra that there are two types of businesses – those who have been breached and those that don’t know that they have been breached. Do you know where your business fits in? We live in a South Africa driven by digital migrations and evolving data security and compliance laws and regulations, the life of the chief information officer (CIO) is complex. Where should they start?

The CIO must work with the business to work out how to provide data to internal staff for them to do their jobs while keeping it secure, preventing external leaks and stopping data theft. This individual is also the one who is responsible to ensure that the business or public entity complies with PAIA and PoPI.

Is there any way this can be achieved without real visibility? Policies will always be the starting point, but without effective visibility on real usage there is no way to know that there is compliance.

Let me give you an example: your policy states that any data stored or used on a corporate asset that contains personal information must be encrypted and should not be moved or copied outside of the organisation’s secured environment. This makes sense, right? So now think about your environment, do you know:

1. How many external storage devices were inserted into any corporate asset in the last 24 hours, 7 days, etc.?

2. How many users are accessing free cloud storage platforms like Google Drive, OneDrive, Dropbox, etc.?

3. What data was copied or moved or uploaded to any of these?

4. What about a user who has copied data onto their PC desktop and renamed a file? Can you tell what they did next?

5. Has data been copied out of the ERP, HR or other system and then placed into a Word document or Excel spreadsheet?

6. Do you still think your data is secure and you are compliant with laws and your own internal policies?

The other method to help with these issues often means a business will buy a string of solutions or tools to protect data. A bit of encryption here, a firewall analysis platform there, desktop DLP over there. We then end up having a large group of tools and nobody to check them. The silky tongued sales person showed them this amazing solution and yet it sits unmanaged, reporting to nobody or simply not deployed.

You do not need to look at new tools, you need to get visibility and a partner. Please ensure that you do not simply find a product provider; make sure the information security company is a strategic business partner. The right partner will identify holes, develop a plan to cover them and also guarantee ongoing support and guidance to continually improve your data security compliance and become an integral part of your continued business success.

When you choose the right partner you will be able to rest easy and focus on your business, knowing that your data security is in good hands. The right partner can provide you with the necessary action, remediation, monitoring, alerting and should then also provide the management and risk committee reports to ensure ongoing compliance.

For more information contact J2 Software, +27 (0)87 238 1870, john@j2.co.za, www.j2.co.za





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Making a mesh for security
Information Security Security Services & Risk Management
Credential-based attacks have reached epidemic levels. For African CISOs in particular, the message is clear: identity is now the perimeter, and defences must reflect that reality with coherence and context.

Read more...
What’s in store for PAM and IAM?
Access Control & Identity Management Information Security
Leostream predicts changes in Identity and Access Management (IAM) and Privileged Access Management (PAM) in the coming year, driven by evolving cybersecurity realities, hybridisation, AI, and more.

Read more...
The challenges of cybersecurity in access control
Technews Publishing SMART Security Solutions Access Control & Identity Management Information Security
SMART Security Solutions summarises the key points dealing with modern cyber risks facing access control systems, from Mercury Security’s white paper “Meeting the Challenges of Cybersecurity in Access Control: A Future-Ready Approach.”

Read more...
Access as a Service is inevitable
Technews Publishing SMART Security Solutions ATG Digital Access Control & Identity Management Infrastructure
When it comes to Access Control as a Service (ACaaS), most organisations (roughly 90% internationally) plan to move, or are in the process of moving to the cloud, but the majority of existing infrastructure (about 70%) remains on-premises for now.

Read more...
Securing your access hardware and software
SMART Security Solutions Technews Publishing RBH Access Technologies Access Control & Identity Management Information Security
Securing access control technology is critical for physical and digital security. Every interaction between readers, controllers, and host systems creates a potential attack point for those with nefarious intent.

Read more...
Privacy by design or by accident
Security Services & Risk Management Infrastructure
Africa’s data future depends on getting it right at the start. If privacy controls do not withstand real-world conditions, such as unstable power, fragile last-mile connectivity, shared devices, and decentralised branch environments, then privacy exists only on paper.

Read more...
From friction to trust
Information Security Security Services & Risk Management Financial (Industry)
Historically, fraud prevention has been viewed as a trade-off between robust security and a seamless customer journey, with security often prevailing. However, this can impair business functionality or complicate the customer journey with multiple logins and authentication steps.

Read more...
Phishing and social engineering are the most significant risks
News & Events Information Security
ESET Research found that phishing accounted for 45,7% of all detected cyberthreats in South Africa, with higher-quality deepfakes, signs of AI-generated phishing websites, and short-lived advertising campaigns designed to evade detection.

Read more...
Access trends for 2026
Technews Publishing SMART Security Solutions RR Electronic Security Solutions Enkulu Technologies IDEMIA neaMetrics Editor's Choice Access Control & Identity Management Infrastructure
The access control and identity management industry has been the cornerstone of organisations of all sizes for decades. SMART Security Solutions asked local integrators and distributors about the primary trends in the access and identity market for 2026.

Read more...
Zero Trust access control
Technews Publishing SMART Security Solutions CASA Software NEC XON Editor's Choice Access Control & Identity Management Information Security
Zero Trust Architecture enforces the rule of ‘never trust, always verify’. It changes an organisation’s security posture by assuming that threats exist both inside and outside the perimeter, and it applies to information and physical security.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.