Cybersecurity comment: Securing the real endpoint

1 June 2020 Information Security

Hi-Tech Security Solutions asked a few cybersecurity experts to tell us about the current threat landscape, including what individuals and companies can do to protect themselves. We will be publishing each expert’s answer in Hi-Tech Security Solutions’ news briefs over the next few weeks (the answers will naturally also be online).

This article features insights from Sebastiaan Rothman, cloud solutions architect at Altron Karabina.

Sebastiaan Rothman

No matter the size of organisations, the ever-growing cybersecurity threat landscape is a risk to everyone. With solution providers pushing the adoption of cloud technologies and global events such as the COVID-19 pandemic, more organisations not only support but promote remote work, and the case for adequate endpoint protection and security awareness has never been stronger.


Sebastiaan Rothman.

As the use of cloud technologies become more mainstream, and people access resources from a broad range of devices, one thing is clear. The corporate perimeter is fast becoming irrelevant, as the so-called security boundary extends to wherever an Internet connection exists.

“Off to the cloud!” often comes long before “Let’s secure the cloud!” and as employees, partners and customers start consuming these services at their leisure, the introduction, management and enforcement of security policies and controls end up being an afterthought, funded with whatever budget is left.

The inside-out approach is pretty much the status quo for organisations implementing security control. Let’s protect the core systems, working in logical rings outward, covering on-premises and corporate-managed devices, down to the personal laptops and devices. This is a very noble activity, and for the most part will tick the box come audit time, but we haven’t quite made it to the endpoints yet, have we?

Protecting the tech is the easy bit – putting measures in place to detect and respond to activities matching certain behaviour or patterns. We’ve been doing it, with varying degrees of success, for a very long time. One thing we have not quite gotten right is getting proper anti-malware and phishing protection installed on the real endpoints in our organisations: the people.

Cybersecurity and risk awareness training should be a priority for organisations looking to secure their environment. Stolen credentials, or even worse, shared credentials, lead to all sorts of problems such as data breaches or insider threats, either negligent or deliberate. Both issues have been listed in the Cloud Security Alliance publication of ‘Top Threats to Cloud Computing’ (CSA, 2019).

The ‘Cloud Security Risks and Concerns Report’ (Netwrix, 2018) indicated that 58 percent of companies attributed security breaches to insiders. Of these, 64 percent cited negligence as the cause, with 13 percent due to credential theft. 23 percent of incidents related to criminal or malicious insiders. That’s 77 percent of incidents that could have potentially been reduced with stronger controls.

A study conducted by Digital Guardian (Digital Guardian, 2019) on the cost of a data breach, suggests that the average cost of a breach can range anything from $1,25 million to $8,19 million, depending on the country and industry. The average cost per record stolen was recorded at $150 per record. Now, that might not seem like a lot, but once you add up a few thousand records, suddenly it’s not small change anymore. South Africa weighs in at $3,06 million.

Helping employees understand the impact poor account handling could have on an organisation is as important as ensuring that antivirus is installed on end devices, or that data centre systems and servers are adequately patched. Landing the notion that a blasé attitude to their own identity and credential security could have a financial impact could go a long way in helping reduce the incidents.

Security awareness workshops, well-defined and readily available policy, and continuous enforcement of strong identity management practices will promote an attitude of security with the people accessing all your valuable information.

While it is important to recognise the human element in the risk associated with breaches, organisations need to also make sure they bring their part. It’s impossible to have a security-conscious workforce if they are not enabled. Processes should be of such a nature that they do not impede operational efficiency, allowing for collaboration and the fluid sharing of the information that helps the organisation tick over.

Data centre security, device protection, and end-user security awareness should enjoy an equal piece of the security budget pie, lest we all starve!

• CSA Top Threats to Cloud Computing 2019: here

• Cloud Security Risks and Concerns in 2018: here

• What's the Cost of a Data Breach in 2019?: here




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Managed security solutions for organisations of all sizes
Information Security News & Events
Cyber attackers have become significantly more sophisticated and determined, targeting businesses of all sizes. PwC’s Global Digital Trust Insights Survey 2025 Africa and South Africa highlights the urgent need for organisations to implement robust cyber risk mitigation strategies.

Read more...
Data resilience at VeeamON
Technews Publishing SMART Security Solutions Infrastructure Information Security
SMART Security Solutions attended the VeeamON Tour in Johannesburg in August to learn more about data resilience and Veeam’s initiatives to enhance data protection, both on-site and in the cloud.

Read more...
Troye exposes the Entra ID backup blind spot
Information Security Infrastructure
If you trust Microsoft to protect your identity, think again. Many organisations naively believe that Microsoft’s shared responsibility model covers Microsoft Entra?ID – formerly Azure AD – but it does not.

Read more...
Secure data protection without hardware lock-in
Infrastructure Information Security News & Events
New Veeam Software Appliance empowers IT teams to achieve instant protection with Veeam’s fully preconfigured, software-only appliance, delivering enterprise-ready simplified deployment and operational efficiency, robust cyber resilience.

Read more...
Check Point launches open, vendor-neutral MDR services
Information Security News & Events Products & Solutions
New Check Point MDR 360° and MXDR 360° offerings deliver 24/7 managed continuous threat monitoring protection across endpoints, cloud and network environments with built-in identity threat detection and 160+ integrations across hybrid, multi-vendor environments.

Read more...
Credential theft surges in South Africa
NEC XON Information Security
NEC XON issues a critical cybersecurity warning about the dual threat of massive credential theft and AI-powered cyberattacks sweeping across the region, with an increasing number of incidents and evolving threat tactics.

Read more...
Want effective Attack Surface Management? Think like an attacker.
Information Security
Effective ASM requires companies to think like attackers, anticipate risks, and act decisively to reduce exposure by knowing their environment, deploying a structured approach, leveraging capable tools, and addressing both internal and external risks.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
POPIA non-compliance puts municipalities at risk
Information Security Government and Parastatal (Industry)
Digital responsibility must go beyond POPIA compliance to recognising that privacy and service delivery are fundamentally linked. Despite this, only 51 out of 257 municipalities submitted their mandatory data protection and access to information reports in 2024.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.