Growing cyber threats to SA’s critical infrastructure

Issue 6 2023 News & Events, Information Security, Industrial (Industry)

The increasing reliance on digital infrastructure makes critical sectors like utilities more susceptible to cyber threats. This concern has been highlighted by Kaspersky's recent discovery of a new SystemBC variant that has targeted a South African nation's critical infrastructure.

This backdoor was found alongside Cobalt Strike beacons, which are reminiscent of the 2021 Darkside Colonial Pipeline incident. Furthermore, Kaspersky research shows that malware was detected and blocked on 29,1% of Industrial Control System (ICS) computers in South Africa in the first half of 2023. Looking more broadly at the continent, Africa sits in first place among other regions with the highest number of industrial systems under attack in H1 2023, where attacks were detected on 40,3% of ICS computers, with the energy sector being the top industry under attack (45,9%).

South Africa is currently in the throes of persistent and varying stages of load shedding as a result of prevailing maintenance and upgrade constraints that continue to threaten the stability of the country’s power supply in the short term. Contending with additional clear and present cybersecurity risks further compounds the pressure on this very infrastructure and those charged with keeping the lights on.

"Cybercriminal activity is constantly evolving. While there is a decline in the number of global attacks, we are witnessing a surge in Advanced Persistent Threats (APTs) that are more strategically targeted, especially towards sectors like critical infrastructure," says Brandon Muller, technology expert and consultant for the MEA region at Kaspersky. "Such attacks are continuous, sophisticated, and when successful, can result in severe damage, financial loss, and extended downtime."

According to Kaspersky, threat actors are concentrating on specific targets to reap maximum benefits. The protection against these threats requires a layered approach. It begins with a focus on critical infrastructure protection; Kaspersky Industrial Cybersecurity solutions emphasise the need for strong cyber defences. Given the intricacies of cyberattacks on crucial sectors, businesses must stay updated with endpoint protection solutions, restrict VPN access where not needed, ensure backup copies are stored on dedicated servers, and consider implementing Endpoint Detection and Response-type (EDR) security solutions for both IT and OT networks. Kaspersky also recommends Managed Detection and Response (MDR) services for immediate access to top-tier security expertise.

The next evolutionary step in cybersecurity is Cyber Immunity. Kaspersky’s Secure by Design ideology underscores the need to think about security right from the design phase. By understanding specific security requirements for each project, businesses can create truly secure systems. A foundational understanding of security goals and assumptions is vital.

The utilities sector is undergoing unprecedented change. Digital transformation, decarbonisation, renewables, and regulatory challenges are shaping its future.

"South Africa's utilities sector is the lifeblood for many industries. The rapid changes, both in terms of digital transformation and the shift towards renewables, are commendable, however, cybersecurity cannot be an afterthought. The blend of innovative technology and top-tier security solutions is the key to ensuring uninterrupted services," Muller added.

Find local Kaspersky suppliers at https://hsbd.co.za/search.aspx?match=substring&type=all&string=kaspersky




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Cybersecurity a challenge in digitalising OT
Kaspersky Information Security Industrial (Industry)
According to a study by Kaspersky and VDC Research on securing operational technology environments, the primary risks are inadequate security measures, insufficient resources allocated to OT cybersecurity, challenges surrounding regulatory compliance, and the complexities of IT/OT integration.

Read more...
Security and privacy: Is one without the other possible?
IoT & Automation Industrial (Industry)
OEMs have a duty to protect privacy as much as security. If security protection is about keeping people out of an embedded device, privacy protection safeguards the data inside the device.

Read more...
From the editor's desk: Showtime for Securex
Technews Publishing News & Events
We have once again reached the time of year when the security industry focuses on Securex. This issue includes a short preview, with more coming online and via our special Securex Preview news briefs. ...

Read more...
Chubbsafes celebrates 190 years
Gunnebo Safe Storage Africa News & Events Security Services & Risk Management
Chubbsafes marks its 190th anniversary in 2025 and as a highlight of the anniversary celebrations it is launching the Chubbsafes 1835, a limited edition 190th-anniversary collector’s safe.

Read more...
Suprema unveils BioStar Air
Suprema neaMetrics News & Events Access Control & Identity Management Infrastructure
Suprema launches BioStar Air, the first cloud-based access control platform designed to natively support biometric authentication and feature true zero-on-premise architecture. BioStar Air simplifies deployment and scales effortlessly to secure SMBs, multi-branch companies, and mixed-use buildings.

Read more...
New law enforcement request portal
News & Events Security Services & Risk Management
inDrive launches law enforcement request portal in South Africa to support safety investigations. New portal allows authorised South African law enforcement officials to securely request user data related to safety incidents.

Read more...
Igniting standards, powering protection
Securex South Africa News & Events Fire & Safety
Fire safety is more than compliance, it is a critical commitment to protecting lives, assets, and infrastructure. At Firexpo 2025, taking place from 3 to 5 June at Gallagher Convention Centre, that commitment takes centre stage.

Read more...
Back-up securely and restore in seconds
Betatrac Telematic Solutions Editor's Choice Information Security Infrastructure
Betatrac has a solution that enables companies to back-up up to 8 TB of data onto a device and restore it in 30 seconds in an emergency, called Rapid Access Data Recovery (RADR).

Read more...
How intrusion protection helps secure O&G operations
Surveillance Perimeter Security, Alarms & Intruder Detection Industrial (Industry)
For O&G operators in Africa, physical security remains one of the biggest considerations, particularly when it comes to perimeter protection and the ability to mitigate intruder-related incidents.

Read more...