Protecting South African systems through XDR cybersecurity

Issue 6 2023 Information Security, Security Services & Risk Management

More of our lives are experienced and managed online. We save our passwords, personal photos, and sensitive work on a variety of devices that eventually send all this data to the cloud.

The online world has transformed to incorporate every aspect of an individual’s life, meaning a blurring between work and personal realms across integrated devices and an array of digital accounts. This opens a new door for potential threat actors to gain access to an organisation’s secrets – through its people.

As we come to rely so much more on these increasingly complex systems, it is now more vital than ever to ensure that they themselves are protected from malicious forces from inside and outside of South Africa in real time.

In the latest Trellix Cyber Threat Report for the second quarter of 2023, the data measured by the company’s Advanced Research Centre found that threat actors are now even targeting our government institutions in coordinated campaigns. Rather than random hackers in a basement, professional threat actors are backed by foreign nations. For the first time, in 2023, South African government systems experienced the highest activity, followed by business service providers, wholesalers, and utilities.

Consulting firm Kearney’s recently published a white paper titled ‘Cybersecurity in Africa – a call to action’ reported that Africa is experiencing rapid growth in cybersecurity investments. This is in response to the region’s growing strategic relevance due to its economic development and evolving digital landscape, making it a prime target for cyberattacks.

With these growing threats, South African members of parliament proposed the establishment of a cyber commissioner, similar to a public protector or auditor-general, in the Cyber Commissioner Bill introduced in July.

Emerging attacks range from blocking legitimate users from their platforms, to stealing sensitive data, erasing data, remotely hijacking systems and a host of other actions using increasingly sophisticated automated tools that can stay undetected on systems for months and even years.

Even our closest allies may have their own reasons to infiltrate our systems and exfiltrate data, possibly to gain an edge in negotiations to make sure we are not keeping secrets that may harm them.

Whatever reasons our enemies and friends may have for cracking into our digital spaces, we need to keep abreast of the tools and tactics so threat actors of all stripes cannot do as they wish.

Traditional anti-malware tools, sold as packaged software bundles, will no longer be enough to keep those determined enough to infiltrate the most secure online environments at bay, for several reasons that we need to appreciate urgently.

Shortcomings of traditional cybersecurity

Firstly, traditional software bundles, provided by some of the most well -known developers, are siloed. This means they depend solely on their limited resources and data to identify threats and hopefully deal with them.

Secondly, they cannot keep up with the rapid advancements that cybercriminals are making, especially those funded by nations that may or may not be friendly to South Africa. Organisations might wait weeks before an update is available; even these may be dated when downloaded.

Finally, these individual solutions often need to be manually installed on each device, server and network, leaving entire segments of an organisation’s architecture vulnerable should an oversight happen.

In the current landscape, where data is emerging as the new gold, system operators must utilise the most comprehensive threat management tools, updated with every new threat in real time.

Trellix Extended Detection and Response (XDR) provides a critical connecting tissue between various networks, devices, and servers. By segmenting security systems onto the Trellix XDR platform, operators gain greater control, visibility, and support for their systems.

How XDR works

Trellix XDR is designed based on the native and open Trellix system architecture, allowing it to integrate with third-party data sources. Rather than relying on a single data source, XDR analyses data from 650 security tools, empowering organisations with enhanced visibility and control.

Organisations receive actionable insights for a highly responsive security strategy through the Trellix Advanced Research Centre, a powerful intelligence asset.

Core components include security operations (SecOps), data security, and endpoint security, with telemetry from network, email, and third-party sources. By integrating endpoint and security operations technology into a single XDR platform, Trellix harnesses the power of machine learning to predict and detect attacks, identify their root causes, and accelerate automated response.

Implementing Trellix XDR improves the efficiency of security operation centres (SOCs), safeguarding organisations from data loss, phishing attacks, and ransomware. This enhances efficacy while decreasing the meantime to response through automated security policy orchestration. By leveraging the advanced capabilities of Trellix XDR, South African organisations can significantly strengthen their security posture and protect their critical assets.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Want effective Attack Surface Management? Think like an attacker.
Information Security
Effective ASM requires companies to think like attackers, anticipate risks, and act decisively to reduce exposure by knowing their environment, deploying a structured approach, leveraging capable tools, and addressing both internal and external risks.

Read more...
Your Wi-Fi router is about to start watching you
News & Events Surveillance Security Services & Risk Management
Advanced algorithms are able to analyse your Wi-Fi signals and create a representation of your movements, turning your home's Wi-Fi into a motion detection and personal identification system.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
POPIA non-compliance puts municipalities at risk
Information Security Government and Parastatal (Industry)
Digital responsibility must go beyond POPIA compliance to recognising that privacy and service delivery are fundamentally linked. Despite this, only 51 out of 257 municipalities submitted their mandatory data protection and access to information reports in 2024.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Most wanted malware
News & Events Information Security
Check Point Software Technologies unveiled its Global Threat Index for June 2025, highlighting a surge in new and evolving threats. Eight African countries are among the most targeted as malware leaders AsyncRAT and FakeUpdates expand.

Read more...
Welcome to the new cyber battleground
Information Security
The Iran-Israel conflict is rapidly redefining modern warfare, pushing the boundaries of cyber capabilities and creating a new, borderless digital battlefield. Fortinet’s CISO, Dr Carl Windsor, offers a critical, in-depth analysis of the escalating tactics and global implications in his latest report.

Read more...
African industries may overestimate cyber defences
Information Security
] A significant perception gap exists in security awareness training: 68% of leaders believe training is tailored to roles, yet only a third of employees feel adequately trained. Many organisations only conduct annual or biannual generic training that may not effectively change behaviour.

Read more...
SMARTpod talks to Sophos and Phishield
SMART Security Solutions Technews Publishing Sophos Videos Information Security News & Events
SMARTpod recently spoke with Pieter Nel, Sales Director for SADC at Sophos, and Sarel Lamprecht, MD at Phishield, about ransomware and their new cyber insurance partnership.

Read more...
Cybersecurity and insurance partnership for sub-Saharan Africa
Sophos News & Events Information Security Security Services & Risk Management
Sophos and Phishield Announce first-of-its-kind cybersecurity and insurance partnership for sub-Saharan Africa. The SMARTpod podcast, discussing the deal and the state of ransomware in South Africa and globally, is now also available.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.