Compliance is knowing

October 2017 Information Security, Infrastructure

You cannot swing a laptop without hitting a major data breach these days. Internationally there are lawsuits launched every day. Security officers are being raked over the coals and their integrity and qualifications are being scrutinised and questioned. People are infuriated by the losses, financial and reputational (even worse) to their businesses and themselves.

John Mc Loughlin MD, J2 Software.
John Mc Loughlin MD, J2 Software.

Does anyone really think there is anything different in South Africa?

The latest string of major breaches are aimed at businesses with security budgets that are larger than the annual turnover of most South African businesses. It is nothing short of naïve to think this can’t happen or is not actually happening, to you.

I live by the mantra that there are two types of businesses – those who have been breached and those that don’t know that they have been breached. Do you know where your business fits in? We live in a South Africa driven by digital migrations and evolving data security and compliance laws and regulations, the life of the chief information officer (CIO) is complex. Where should they start?

The CIO must work with the business to work out how to provide data to internal staff for them to do their jobs while keeping it secure, preventing external leaks and stopping data theft. This individual is also the one who is responsible to ensure that the business or public entity complies with PAIA and PoPI.

Is there any way this can be achieved without real visibility? Policies will always be the starting point, but without effective visibility on real usage there is no way to know that there is compliance.

Let me give you an example: your policy states that any data stored or used on a corporate asset that contains personal information must be encrypted and should not be moved or copied outside of the organisation’s secured environment. This makes sense, right? So now think about your environment, do you know:

1. How many external storage devices were inserted into any corporate asset in the last 24 hours, 7 days, etc.?

2. How many users are accessing free cloud storage platforms like Google Drive, OneDrive, Dropbox, etc.?

3. What data was copied or moved or uploaded to any of these?

4. What about a user who has copied data onto their PC desktop and renamed a file? Can you tell what they did next?

5. Has data been copied out of the ERP, HR or other system and then placed into a Word document or Excel spreadsheet?

6. Do you still think your data is secure and you are compliant with laws and your own internal policies?

The other method to help with these issues often means a business will buy a string of solutions or tools to protect data. A bit of encryption here, a firewall analysis platform there, desktop DLP over there. We then end up having a large group of tools and nobody to check them. The silky tongued sales person showed them this amazing solution and yet it sits unmanaged, reporting to nobody or simply not deployed.

You do not need to look at new tools, you need to get visibility and a partner. Please ensure that you do not simply find a product provider; make sure the information security company is a strategic business partner. The right partner will identify holes, develop a plan to cover them and also guarantee ongoing support and guidance to continually improve your data security compliance and become an integral part of your continued business success.

When you choose the right partner you will be able to rest easy and focus on your business, knowing that your data security is in good hands. The right partner can provide you with the necessary action, remediation, monitoring, alerting and should then also provide the management and risk committee reports to ensure ongoing compliance.

For more information contact J2 Software, +27 (0)87 238 1870, [email protected], www.j2.co.za





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Hytera supports communication upgrade for Joburg
News & Events Infrastructure Government and Parastatal (Industry)
By equipping Johannesburg’s metro police and emergency services with multimode radios which integrate TETRA and LTE networks, Hytera is bridging coverage gaps and improving response times across the city.

Read more...
Want effective Attack Surface Management? Think like an attacker.
Information Security
Effective ASM requires companies to think like attackers, anticipate risks, and act decisively to reduce exposure by knowing their environment, deploying a structured approach, leveraging capable tools, and addressing both internal and external risks.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
POPIA non-compliance puts municipalities at risk
Information Security Government and Parastatal (Industry)
Digital responsibility must go beyond POPIA compliance to recognising that privacy and service delivery are fundamentally linked. Despite this, only 51 out of 257 municipalities submitted their mandatory data protection and access to information reports in 2024.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Most wanted malware
News & Events Information Security
Check Point Software Technologies unveiled its Global Threat Index for June 2025, highlighting a surge in new and evolving threats. Eight African countries are among the most targeted as malware leaders AsyncRAT and FakeUpdates expand.

Read more...
IoT-driven smart data to stay ahead
IoT & Automation Infrastructure AI & Data Analytics
In a world where uncertainty is constant, the real competitive edge lies in foresight. Businesses that turn real-time data into proactive strategies will not just survive, they will lead.

Read more...
Hydrogen is green but dangerous
Fire & Safety Infrastructure Power Management
Hydrogen infrastructure is developing quickly, but it comes with safety challenges. Hydrogen is flammable, and its small molecular size means it can leak easily. Additionally, fires caused by hydrogen are nearly invisible, making them difficult to detect and respond to.

Read more...
Welcome to the new cyber battleground
Information Security
The Iran-Israel conflict is rapidly redefining modern warfare, pushing the boundaries of cyber capabilities and creating a new, borderless digital battlefield. Fortinet’s CISO, Dr Carl Windsor, offers a critical, in-depth analysis of the escalating tactics and global implications in his latest report.

Read more...
A whole-site solution to crack the data centre market
Fire & Safety Infrastructure Facilities & Building Management
Fire safety consultants and contractors who can offer a comprehensive fire safety solution to the data centre market can establish themselves as a supplier of a key safety features that help guarantee the smooth operation of critical infrastructure.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.