Necessary evil or critical ingredient?

June 2016 News & Events

You can say it a million times and a billion people will agree with you, but we all do it anyway. Security is still not seen as a necessary component of business, not even IT, and is therefore still a necessary evil in the eyes of most people – or a grudge purchase as so many people keep saying. The result of this is a minimalist approach to security where cheaper is better and the budget makes your decisions for you.

And then security gets a bad reputation when things aren’t miraculously 100% secure.

An online site devoted to security recently wrote an article about a Chinese surveillance manufacturer, Hikvision, which had changed its terms and conditions to exclude any liability for its kit being hacked. This naturally caused a few people to comment and complain, but the reality is they are doing the same thing Microsoft, Cisco, Oracle and every other company does. Microsoft’s history of producing secure software speaks for itself, that’s why we need firewalls and anti-virus and other third-party applications on our computers.

Which surveillance manufacturers take responsibility for hacks? I’m guessing the number would be very close to zero, actually exactly zero. I would suggest that the cyber security problem the surveillance industry is now starting to face is not the fault of the manufacturers – they have partial fault through the production of poor software and through using untrusted components – but it is a shared responsibility.

Installers and integrators must also share in the blame. Understanding the risks of the information world is essential if you are going to be adding something to a network, whether it’s your home network or a large organisation’s. Moreover, catering for the risks in collaboration with your client’s IT people should be a given. Of course that doesn’t happen because we all have our things to do and security is that guy’s domain.

The end user also shares the blame. The customer should make the rules and ensure, for example, that all the changed passwords are in the hands of the security manager (or whoever is responsible) and not left as defaults or a secret the installer keeps to himself. That is probably the simplest step in ensuring your own surveillance system. It might also be worthwhile doing your homework and dictating what you want your products and infrastructure to do instead of going for the cheapest, or the one the salesperson gets the best commission on.

Whether you are making your home more comfortable, securing an estate, buying a new laptop or installing a new Internet of Things platform, the reality is that you will have problems if you see security as a necessary evil that you have to pay for just in case.

Security needs to be an integrated component of everything we do. This will automatically make us as users more aware of what we need and how we should use what we have, and it will make the systems we rely on more secure. With security designed into the architecture from the start, there will be fewer hassles trying to add it on later when your budget is already spent.

Andrew Seldon

Editor



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Woolworths attack raises bomb preparedness questions
News & Events
Two explosions have been reported at Woolworths stores in South Africa over the past week. SMART Security Solutions asked Jimmy Roodt, an experienced and accredited explosive ordnance disposal specialist from Gauntlet Security Solutions, for his insight into the events.

Read more...
Growing adoption of AI at work
News & Events AI & Data Analytics
AI adoption accelerates worldwide, with South Africa making gains amid uneven diffusion. Locally, South Africa ranks 46th of 147 economies measured, and its AI usage increased to 23,1% in Q1 2026.

Read more...
Enterprise AI hits the wall
News & Events AI & Data Analytics
Demands for AI privacy and sovereignty expose the limits of architectures built for centralised and borderless data flows. Organisations that redesign early are gaining a measurable edge in AI readiness and scale.

Read more...
71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...
From the Editor's desk: Security goes mainstream
Technews Publishing News & Events
      Welcome to SMART Security’s SMART Mining & Industrial Security Handbook 2026. While the world is focused on cybersecurity and AI, physical security has become a board-level concern across South Africa’s ...

Read more...
Global security in 2026
Editor's Choice News & Events Security Services & Risk Management Industrial (Industry) Mining (Industry)
The World Security Report 2026 states: “In a world of increasing volatility, physical security has evolved. It is no longer just a defensive measure; it is a critical driver of corporate value.”

Read more...
Industry perspective on industrial cybersecurity
Technews Publishing News & Events Infrastructure Industrial (Industry)
The Industrial Security Harmonization Group has released a joint industry perspective highlighting a critical truth in industrial cybersecurity: secure communication is not determined by protocols alone, but by how they are deployed and managed in real-world environments.

Read more...
The control room problem that nobody wants to talk about
Technews Publishing Editor's Choice
WhatsApp has become the unofficial backbone of security communications across the mining and industrial sectors, but it was never designed to be a security tool.

Read more...
Controlling access for people and vehicles
IDEMIA STid Security Technews Publishing Editor's Choice Access Control & Identity Management Asset Management Industrial (Industry) Mining (Industry)
When it comes to access control, the security requirements of mines and the industrial sector are similar, requiring a layered approach that combines physical barriers, digital authentication, and continuous monitoring to protect personnel, assets, and operational continuity.

Read more...
Aerial firefighter training revolution
Fire & Safety News & Events
Sophisticated new flight simulation software capable of accurately modelling the performance of firefighting helicopters could help train pilots to tackle wildfires more effectively and safely in the future.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.