Cybersecurity for your SMME

Issue 6 2022 Information Security

In today’s interconnected world, effective cybersecurity is as important to the success of any business as capital funding, skills mix, innovation and good management. This is especially true since the widespread move to remote and hybrid working over the past two years, which has made both individuals and organisations more vulnerable to cyberattacks. And not only are users on open networks more vulnerable to these attacks, cybercrime is becoming more sophisticated every day.

Large companies have the benefit of firewalls, dedicated IT departments and advanced security protocols, but even they are vulnerable to cybercrime, so SMMEs have to be alert to the threat it poses to both business information and continuity. Yet many don’t know where to start when it comes to preventing cyber intrusions, data theft and malicious attacks.

Forewarned is forearmed

The first line of defence against cybercrime is awareness and vigilance. In 2021 alone, there were 230 million cyber threat detections in South Africa, with phishing attempts being the most common. Around 96% of businesses and organisations in the country were targeted by this form of attack during the course of the year, with the number targeted by data and business email attacks not far behind.

And these are no longer simple end-point attacks. Criminal syndicates have developed complex, multi-stage operations that are designed to compromise computer networks through their most vulnerable points, usually their people. All it takes is a careless click on a suspicious link in an email and the damage is done. This is how most cybercriminals gain access to sensitive information and bank accounts, or deliver malicious software like ransomware.

Ransomware, which is designed to block access to a computer system until a ransom is paid, has become a widespread threat, with 75% of known ransomware having been used to initiate attacks on three out of four organisations worldwide.

What’s the solution?

In SMMEs, where entrepreneurs and their staff often perform multiple functions, protecting individual and networked computers from attack can seem like an overwhelming task. There are, of course, some important steps that everyone who uses a computer should take.

For a start, it’s important not to use the same password on multiple platforms as this makes it more difficult for hackers who’ve discovered a password to gain access to all of your online accounts. You should also be vigilant of suspicious links in an unexpected email, even one that looks as if it could come from a known service provider. Cybercriminals mirror the mails sent out by trusted organisations, hoping to catch users unawares. In fact, it’s a good discipline never to click on a hyperlink in an email. Make it a practice to copy hyperlinks and open them separately in your browser instead. And always remember the golden rule: think before you click.

The importance of training

Ideally, all members of staff who make use of computers, whether standalone or networked, should attend a cybersecurity training course conducted by an established and reputable provider so that they can learn to understand cybercriminals and the way they operate. As much as individuals and businesses benefit from new technologies, so do hackers. Many make use of AI tools such as machine learning to mine for data that may make computers or networks vulnerable – and many even use bots to maximise the reach of their phishing attacks.

Cybersecurity skills are as important to a business as functional, financial and managerial skills – and training helps entrepreneurs and their staff to understand more than just the basics. Formal training will, for example, help them to recognise and strengthen vulnerable points in the business’s IT and data systems. They’ll also learn more about how AI works, about the metaverse and blockchain technology, and about how using these technologies can create system vulnerabilities. Most importantly, they’ll learn all about ways to protect the business’s technology and data systems.

The bottom line is that data is one of the most valuable assets in any business today and, with so much sensitive information now online, nothing can be left to chance.

Fourth Industrial Revolution Incubator is an enabling technology platform for SMMEs. Find out more at https://4iri.co.za/




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Managed security solutions for organisations of all sizes
Information Security
Cyberattackers have become significantly more sophisticated and determined, targeting businesses of all sizes. PwC’s Global Digital Trust Insights Survey 2025 Africa and South Africa highlights the urgent need for organisations to implement robust cyber risk mitigation strategies.

Read more...
Multiple IoT devices targeted
Information Security Residential Estate (Industry)
Mirai remains one of the top threats to IoT in 2025 due to widespread exploitation of weak login credentials and unpatched vulnerabilities, enabling large-scale botnets for DDoS attacks, data theft and other malicious activities.

Read more...
Local-first data security is South Africa's new digital fortress
Infrastructure Information Security
With many global conversations taking place about data security and privacy, a distinct and powerful message is emerging from South Africa: the critical importance of a 'local first' approach to data security.

Read more...
Sophos launches advisory services to deliver proactive cybersecurity resilience
Information Security News & Events
Sophos has launched a suite of penetration testing and application security services, designed to identify gaps in organisations’ security programs, which is informed by Sophos X-Ops Threat Intelligence and delivered by world-class experts.

Read more...
Kaspersky highlights biometric and signature risks
Information Security News & Events
AI has elevated phishing into a highly personalised threat. Large language models enable attackers to craft convincing emails, messages and websites that mimic legitimate sources, eliminating grammatical errors that once exposed scams.

Read more...
Software security is a team sport
Information Security Infrastructure
Building and maintaining secure software is not a one-team effort; it requires the collective strength and collaboration of security, engineering, and operations teams.

Read more...
Stronger cloud protection
Kaspersky Information Security Products & Solutions
Kaspersky has announced the release of an enhanced version of its Kaspersky Cloud Workload Security, delivering advanced protection for hybrid and multi-cloud environments.

Read more...
AttackIQ enters South Africa with key appointment
Information Security News & Events
AttackIQ, a provider of continuous security validation and exposure management, has announced its entry into the South African market with the appointment of Luke Cifarelli as its country manager.

Read more...
Managed security solutions for organisations of all sizes
Information Security News & Events
Cyber attackers have become significantly more sophisticated and determined, targeting businesses of all sizes. PwC’s Global Digital Trust Insights Survey 2025 Africa and South Africa highlights the urgent need for organisations to implement robust cyber risk mitigation strategies.

Read more...
Data resilience at VeeamON
Technews Publishing SMART Security Solutions Infrastructure Information Security
SMART Security Solutions attended the VeeamON Tour in Johannesburg in August to learn more about data resilience and Veeam’s initiatives to enhance data protection, both on-site and in the cloud.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.