Six-month lifespan of technology

April 2013 Information Security

In 2010, the South African government declared cybersecurity to be a national security priority. Since then, the country has been victim to trading stoppages at the Johannesburg Stock Exchange because of technological difficulties faced by its telecoms service provider, blackouts because of Eskom’s systems being disrupted, and the well-known January 2012 theft of R42 million from Postbank (the banking subsidiary of the country’s Post Office).

According to international technology provider, Thales SA, South Africa’s major institutions are at risk to a growing number of possibly debilitating cyberthreats because of the lack of continuous sophistication of cybercrime technology by the vast number of 'cybersecurity specialists' operating in the country. The reality is that the smarter technologies and modus operandi of cyber criminals – both locally and abroad – are not being effectively matched by preventative technologies that pass their sell-by date after six months of being developed.

Llewellyn Hartnick, cybersecurity specialist at Thales SA, says, “We are moving towards an electronic age. We have e-filing of citizens’ tax returns, a national online traffic fine system, electronic voice, video and written databases that are being built and maintained across sectors in the private and public sectors. It is therefore true that our growing dependence on technology naturally opens up the window of opportunity for criminal elements. Despite the recognition that cybersecurity is a growing issue of national importance there seems to be little understanding that technological developments have a global life span of, at most, six months. This means that effective security requires more than identification of the risks or sanctioning of the guilty criminals; it requires preventative mechanisms that are not only customised to specific sectors and operations but, that are more importantly, continuously upgraded in a way that consistently prevents the growing number of sophisticated attacks on one’s systems.

“Unlike countries that enjoy the benefits of cheap labour, as a country, South Africa cannot afford to invest huge portions of the national budget on continuously developing improved cybersecurity technologies. The responsibility therefore falls on individual organisations to maintain its electronic assets as best as possible, and it is there that lies the problem,” adds Hartnick.

“Having developed cyber security solutions over the past five years we know what is needed, from an organisational perspective, to protect electronic assets. Organisations (in the private and public sector) are specialists at what they do so it is unrealistic to expect our country’s stock exchange to be experts at cybercrime, or to expect our country’s energy distributor to maintain up-to-date cybersecurity technologies. South African organisations don’t and shouldn’t expend their time on developing and maintaining technologies that keep them and their customers safe.

This lack of in-house expertise and budget means that there is a greater reliance on South African service providers to use global best practices as a benchmark in preventing attacks, although in our experience this does not seem to be the case currently as our country’s major institutions remain at considerable risk because of a lack of awareness or implementation of evolving global technology standards,” comments Hartnick.

For more information contact Thales, +27 (0)11 313 9001, [email protected]





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

What are MFA fatigue attacks, and how can they be prevented?
Information Security
Multifactor authentication is a security measure that requires users to provide a second form of verification before they can log into a corporate network. It has long been considered essential for keeping fraudsters out. However, cybercriminals have been discovering clever ways to bypass it.

Read more...
SA's cybersecurity risks to watch
Information Security
The persistent myth is that cybercrime only targets the biggest companies and economies, but cybercriminals are not bound by geography, and rapidly digitising economies lure them in large numbers.

Read more...
Cyber insurance a key component in cyber defence strategies
Information Security
[Sponsored] Cyber insurance has become a key part of South African organisations’ risk reduction strategies, driven by the need for additional financial protection and contingency plans in the event of a cyber incident.

Read more...
Deception technology crucial to unmasking data theft
Information Security Security Services & Risk Management
The ‘silent theft’ of data is an increasingly prevalent cyber threat to businesses, driving the ongoing leakage of personal information in the public domain through undetected attacks that cannot even be policed by data privacy legislation.

Read more...
Data security and privacy in global mobility
Security Services & Risk Management Information Security
Data security and privacy in today’s interconnected world is of paramount importance. In the realm of global mobility, where individuals and organisations traverse borders for various reasons, safeguarding sensitive information becomes an even more critical imperative.

Read more...
Sophos celebrates partners and cybersecurity innovation at annual conference
News & Events Information Security
[Sponsored] Sun City hosted Sophos' annual partner event this year, which took place from 12 to 14 March. Sophos’ South African cybersecurity distributors and resellers gathered for an engaging two-day conference.

Read more...
The CIPC hack has potentially serious consequences
Editor's Choice Information Security
A cyber breach at the South African Companies and Intellectual Property Commission (CIPC) has put millions of companies at risk. The organisation holds a vast database of registration details, including sensitive data like ID numbers, addresses, and contact information.

Read more...
Navigating South Africa's cybersecurity regulations
Sophos Information Security Infrastructure
[Sponsored] Data privacy and compliance are not just buzzwords; they are essential components of a robust cybersecurity strategy that cannot be ignored. Understanding and adhering to local data protection laws and regulations becomes paramount.

Read more...
AI augmentation in security software and the resistance to IT
Security Services & Risk Management Information Security
The integration of AI technology into security software has been met with resistance. In this, the first in a series of two articles, Paul Meyer explores the challenges and obstacles that must be overcome to empower AI-enabled, human-centric decision-making.

Read more...
Milestone Systems joins CVE programme
Milestone Systems News & Events Information Security
Milestone Systems has partnered with the Common Vulnerability and Exposures (CVE) Programme as a CVE Numbering Authority (CNA), to assist the programme to find, describe, and catalogue known cybersecurity issues.

Read more...