Ransomware is a growing threat

29 July 2019 Security Services & Risk Management

The rise in cybercrime is unprecedented. Over one-third of South African IT decision-makers (35%) are on high alert and are expecting cyber-attacks on their businesses within days.

Moreover, besides expecting imminent attacks, another 31% of organisations are expecting an attack with the year. Fewer than one in five IT decision-makers in SA enterprises believe themselves safe from attack in the next two years.

These were two of the findings of a new research study dubbed “The State of Enterprise Security in South Africa 2019,” conducted by World Wide Worx in partnership with Trend Micro and VMware.

And it’s just as well companies are alert. Look for example at what happened recently when City Power in Johannesburg fell victim to a ransomware attack which crippled most of its systems and Web site, leaving the entity paralysed, and unable to supply services to its customers.

Unfortunately, City Power is far from the only sufferer. In the US alone, more than 20 public-sector organisations have fallen victim to ransomware attacks this year, including City Lake, Tallahassee and Riviera Beach in Florida, Augusta in Maine, and Albany in New York, to name but a few.

This goes to show that no organisation, even the ones with huge security budgets and the most state-of-the-art security systems in place, is safe. And unfortunately, with ransomware attacks, depending on the type and severity, the damage could take weeks or even months to repair, and costs organisations in terms of system downtime and disaster recovery are so exorbitant that many choose to pay the ransom instead.

Paying the ransom is a terrible idea. Not only does it encourage this type of scourge, but there is no guarantee that cybercriminals will hand over the decryption key once the ransom is paid. However, the alternative is the laborious recovery of data from backups, assuming these backups are current and unaffected, meaning that many companies end up forking out to save themselves downtime and money in the long run.

The study also revealed that a slim majority (57%), of businesses, say they can detect evidence of a malicious breach within a few minutes. However, nearly half of businesses (43%) say they won’t know they’ve been compromised until a few hours, or even longer, after a security breach.

These organisations could be in for a nasty surprise, particularly if they are hit with ransomware, which can lock down almost every file on a user’s computer within a few hours, meaning that any response by then would be too late.

The fact that SA businesses are unable to detect threats in a timely fashion, means they have yet to fully grasp the nature of the threat and will end up facing huge losses thanks to ransomware.

And unfortunately, ransomware isn’t going anywhere soon, as cybercriminals have cottoned on to just how lucrative these types of attacks can be. Although a slew of other attacks exists, attackers who are after a quick payday, are turning to extortion-type attacks.

The research also highlighted that the biggest shortcoming in cybersecurity preparedness is outdated software, with a whopping 77% of IT decision-makers claiming that it makes their organisations highly vulnerable.

With ransomware claiming victims left, right and centre, organisations simply cannot afford to not keep their software up to date. Who can forget the notorious WannaCry and NotPetya attacks from 2017 that brought some of the biggest organisations around the world to their knees? Both attacks targeted outdated Windows systems.

Out of date software and systems simply can’t defend themselves from ransomware attacks. There were thousands of computers running vulnerable systems before the WannaCry breakout, and in its wake, there are still machines out there that haven’t installed the Windows EternalBlue vulnerability patch.

This highlights the fact that the approach to IT security in a cloud and digital era must change rapidly and dramatically. The research was clear: there is a massive need for senior financial decision-makers to learn that when it comes to data protection, an ounce is worth a pound of lost data and productivity.

The report stresses where local organisations are strong and reveals the areas of IT security that they still need to work on. Having strong information and data security solutions in place is essential, and also a cultural shift towards security awareness and collaboration across all parts of the business. No business can afford to be lax when it comes to keeping their systems and software updated, and their staff educated on basic security hygiene.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The line between locking residents out and restricting their access
News & Events Security Services & Risk Management Residential Estate (Industry)
A June 2026 High Court judgment has clarified one of the most contested issues in modern estate governance: when an HOA's digital access restrictions amount to unlawful self-help or spoliation, and when they do not.

Read more...
Modernise field communications with Push-to-Talk over Cellular
Products & Solutions Security Services & Risk Management
Sentiv is bringing Hytera’s Push-to-Talk over Cellular (PTToC) portfolio to organisations that need a more structured and controlled way to coordinate field teams, without extending a full private radio model to every team, site, or function.

Read more...
SAFPS urges taxpayers to remain alert to fraud
Security Services & Risk Management News & Events
The SAFPS warns taxpayers about evolving SARS scams this tax season, highlighting common fraud tactics, practical prevention tips, and trusted reporting channels to stay protected.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Fire safety in South Africa
Technoswitch Fire Detection & Suppression Technews Publishing SMART Security Solutions Fire & Safety Security Services & Risk Management Editor's Choice
Fire safety is sometimes ignored, sometimes relegated to whatever is cheapest, and sometimes treated with the seriousness it deserves, given that it focuses on protecting life and assets. SMART Security Solutions asked Brett Birch, MD of Technoswitch, for some insights into the realities of fire safety in South Africa.

Read more...
Nimbus remote fire alarm management
Technoswitch Fire Detection & Suppression Security Services & Risk Management Fire & Safety
Nimbus connects key stakeholders to their fire alarm systems, simplifying compliance with fire safety standards and greatly improving visibility into critical events, thereby augmenting first responder processes that save lives and protect assets.

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
Stop supplier fraud at the moment of payment
News & Events Security Services & Risk Management
Cape Town-built platform bridges the gap between onboarding and transaction by securing identity inside the live channels where companies exchange invoices and banking details.

Read more...
Ungoverned AI agents and deepfakes pose critical threats
Information Security Security Services & Risk Management
Global study reveals 64% of South African organisations already deploy autonomous AI agents with little to no governance, while 63% of employees admit they are unlikely to be able to spot attacks such as deepfakes

Read more...
A risk-based approach to fire safety
Fire & Safety Security Services & Risk Management Industrial (Industry) Agriculture (Industry)
A report by fire engineering consultancy ASP Fire is challenging blanket assumptions around combustible-core sandwich panels, arguing instead for a rational, risk-based approach that balances fire safety requirements with commercial realities in sectors such as agriculture, manufacturing and industrial processing.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.