What’s a little fact or two?

May 2018 News & Events

In the last issue of Hi-Tech Security Solutions we carried an article that reported on a security vulnerability in Hanwha Techwin cameras. As it turns out, the report was correct, but it wasn’t all that correct. By this I mean that although there definitely was a vulnerability, the specifics of how and which users could be impacted were not clear.

As it turns out, the problems were with the consumer versions of the camera and not the professional range. This makes a huge difference to those who may be using those particular cameras, especially these days when a security breach could have a significant impact.

Of course, it’s embarrassing that Hi-Tech Security Solutions only provided some of the story and we apologise for that, but it also raises an interesting issue. There is a trend nowadays to lament the lack of cybersecurity skills in the market, with some figures claiming there are more than a million positions unfilled in the world. Personally, I tend to scoff at these big numbers as there are in fact lots of skills out there, but companies either don’t want to pay for the top skills because supply-and-demand laws are only good when they work in your favour, or they don’t want to have the burden of training people who may not have the experience they require.

Perhaps that’s a bit cynical, but the fact is that when it comes to cybersecurity it’s easy to miss some important facts because too many people don’t know enough about the topic to understand and clearly communicate the issues. And those that do understand may not be very good at putting their knowledge into words that non-technical people can understand.

When someone discovers a security issue, they obviously should notify the manufacturer and provide their data to show the vulnerability at work. The manufacturer should then make haste to resolve the issue. But when does the news get sent out to the rest of the world? We need to know if there are security issues and resolutions for any products we use, but we need to be accurately informed without marketing hype. More specifically, we (users) don’t always need to know the exact technical details of the issue, but rather that there is a fix and how to apply it.

But what about companies that don’t attend to security breach notifications from researchers? How long should they have to resolve an issue before they are exposed for their poor understanding and perhaps even contempt for customers’ security?

And who do they tell? Intel apparently told its Chinese manufacturers about security holes in its processors before it informed the US government (https://www.wsj.com/articles/intel-warned-chinese-companies-of-chip-flaws-before-u-s-government-1517157430).

Perhaps security vulnerabilities need to be dealt with via a documented, consistent process as do so many other issues in the security world (and everywhere for that matter). And perhaps the world needs some serious investment in real risk-based cybersecurity training instead of the endless quick-fix courses that provide a certificate of attendance instead of a certificate of actually learning something.

Andrew Seldon

Editor



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Woolworths attack raises bomb preparedness questions
News & Events
Two explosions have been reported at Woolworths stores in South Africa over the past week. SMART Security Solutions asked Jimmy Roodt, an experienced and accredited explosive ordnance disposal specialist from Gauntlet Security Solutions, for his insight into the events.

Read more...
Growing adoption of AI at work
News & Events AI & Data Analytics
AI adoption accelerates worldwide, with South Africa making gains amid uneven diffusion. Locally, South Africa ranks 46th of 147 economies measured, and its AI usage increased to 23,1% in Q1 2026.

Read more...
Enterprise AI hits the wall
News & Events AI & Data Analytics
Demands for AI privacy and sovereignty expose the limits of architectures built for centralised and borderless data flows. Organisations that redesign early are gaining a measurable edge in AI readiness and scale.

Read more...
71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...
From the Editor's desk: Security goes mainstream
Technews Publishing News & Events
      Welcome to SMART Security’s SMART Mining & Industrial Security Handbook 2026. While the world is focused on cybersecurity and AI, physical security has become a board-level concern across South Africa’s ...

Read more...
Global security in 2026
Editor's Choice News & Events Security Services & Risk Management Industrial (Industry) Mining (Industry)
The World Security Report 2026 states: “In a world of increasing volatility, physical security has evolved. It is no longer just a defensive measure; it is a critical driver of corporate value.”

Read more...
Industry perspective on industrial cybersecurity
Technews Publishing News & Events Infrastructure Industrial (Industry)
The Industrial Security Harmonization Group has released a joint industry perspective highlighting a critical truth in industrial cybersecurity: secure communication is not determined by protocols alone, but by how they are deployed and managed in real-world environments.

Read more...
The control room problem that nobody wants to talk about
Technews Publishing Editor's Choice
WhatsApp has become the unofficial backbone of security communications across the mining and industrial sectors, but it was never designed to be a security tool.

Read more...
Controlling access for people and vehicles
IDEMIA STid Security Technews Publishing Editor's Choice Access Control & Identity Management Asset Management Industrial (Industry) Mining (Industry)
When it comes to access control, the security requirements of mines and the industrial sector are similar, requiring a layered approach that combines physical barriers, digital authentication, and continuous monitoring to protect personnel, assets, and operational continuity.

Read more...
Aerial firefighter training revolution
Fire & Safety News & Events
Sophisticated new flight simulation software capable of accurately modelling the performance of firefighting helicopters could help train pilots to tackle wildfires more effectively and safely in the future.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.