Where does SA logistics stand as far as cybersecurity is concerned?

Issue 8 2022 Logistics (Industry), Security Services & Risk Management

South Africa’s logistics industry is battling a war on many fronts. Bad weather, equipment breakdowns and shortages and congestion continue to hamper the country’s ports, adding days to the supply chain and creating havoc downstream.

The conflict in Ukraine and the weakness of the rand are exacerbating the situation, with inflation skyrocketing to the detriment of consumers.

In addition, South Africa is now firmly in the cross hairs of cyber criminals. Antivirus provider Kaspersky’s research shows that ransomware attacks in South Africa doubled between January and April 2022 compared to the same period last year.

The 2021 cyberattack on Transnet was especially damaging, impacting ports, harbours and pipelines to the point that the state enterprise was forced to declare force majeure at several container terminals.

Lesiba Sebola, director of information technology at Bidvest International Logistics (BIL), says it is paramount to safeguard IT infrastructure given how central it has become to operations.

“The bottom line is the financial losses incurred. Transnet, not being able to operate their ports affects us, and obviously, if there are attacks in our own environment that necessitates downtime of the infrastructure, it would be difficult to conduct business.”

Sebola says the most prevalent form of attack is phishing, which seeks to get information from users. “You need a multifaceted approach to protecting your information. We have perimeter security, which involves firewalls, and with operating systems there is always updates you need to do, whether it is an operating system update or security update, to eliminate vulnerabilities the providers have identified.”

However, Sebola stresses that the most important aspect of cyber security is user awareness. “The majority of successful attacks happen here. If your users are not aware, it is like taking a key to your house and throwing it over the security fence for attackers to use.”

“At BIL, we have an online program where staff can learn about security and the different types of attacks: e-mail impersonations, for example. If they spot an e-mail that looks a bit suspicious, we have a special process they follow to alert us so that we can investigate. This forms part of our induction process and occurs on a quarterly basis.”

Like Sebola, Craig Rosewarne, MD of cyber security company Wolfpack Information Risk, believes everyone is at risk of cyberattacks. “You could be an individual, a non-profit, a small charity, it does not matter. The hacker does not care where the money comes from.”

“The harsh reality is that attacks cannot be prevented, but organisations can defend against them, provided they recognise the complexity of digital crimes and tackle them accordingly.”

For Sebola, this means continuously monitoring networks to establish any irregular patterns. “You have to have an incident response plan in place, but you also cannot have a prescriptive one that is generic. This plan will tell you who needs to be involved, who the contact people are, and not just from IT. You need to establish who is involved from legal, operations and the communications side, because there are various aspects that you want to consider.”

“When you have cyber insurance, part of the requirement is that you inform them of any breaches. It is important to keep logs from the IT side. Make sure you contain the attack so that you can preserve the evidence. This is important in terms of the analysis later on to prevent such a breach from happening again.”




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Deception technology crucial to unmasking data theft
Information Security Security Services & Risk Management
The ‘silent theft’ of data is an increasingly prevalent cyber threat to businesses, driving the ongoing leakage of personal information in the public domain through undetected attacks that cannot even be policed by data privacy legislation.

Read more...
Proactive strategies against payment fraud
Financial (Industry) Security Services & Risk Management
Amid a spate of high-profile payment fraud cases in South Africa, the need for robust fraud payment prevention measures has never been more apparent, says Ryan Mer, CEO of eftsure Africa.

Read more...
How to prevent and survive fires
Fire & Safety Security Services & Risk Management
Since its launch in August 2023, Fidelity SecureFire, a division of the Fidelity Services Group, has been making significant strides in revolutionising fire response services in South Africa.

Read more...
A long career in mining security
Technews Publishing Editor's Choice Security Services & Risk Management Mining (Industry)
Nash Lutchman recently retired from a security and law enforcement career, initially as a police officer, and for the past 16 years as a leader of risk and security operations in the mining industry.

Read more...
Risk management: There's an app for that
Editor's Choice News & Events Security Services & Risk Management
Zulu Consulting has streamlined the corporate risk management process with the launch of Risk-IO, a web-based app designed to consolidate and guide risk managers through the process, monitoring progress as one proceeds.

Read more...
Integrated information platform for risk management
Editor's Choice News & Events Security Services & Risk Management
Online Intelligence recently launched version 7 of its CiiMS risk and security platform. Speaking to SMART Security Solutions after the launch event, the company’s Arnold van den Bout described the enhancements in version 7.

Read more...
Global Identity Fraud Report revealing eight-month ‘mega-attack’
Editor's Choice Security Services & Risk Management
AU10TIX recently released its Q4 Global Identity Fraud Report, with the research identifying two never-before-seen attack patterns, with the worst case involving 22 000+ AI-generated variations of a single U.S. passport.

Read more...
Linking of security officers by security businesses
PSiRA (Private Security Ind. Regulatory Authority) News & Events Security Services & Risk Management
[Sponsored] By law, all security businesses are required to declare their employees to PSiRA so that they can be accounted for administratively. Failure to link employees by security businesses is a contravention of the Code of Conduct and a criminal offence.

Read more...
Understanding the power of digital identity
Access Control & Identity Management Security Services & Risk Management Financial (Industry)
The way we perceive business flourishing is undergoing a paradigm shift, as digital identity and consumer consent redefine the dynamics of transactions, says Shanaaz Trethewey.

Read more...
What you can expect from digital identity in 2024
Access Control & Identity Management Security Services & Risk Management
As biometric identity becomes a central tenet in secure access to finance, government, telecommunications, healthcare services and more, 2024 is expected to be a year where biometrics evolve and important regulatory conversations occur.

Read more...