Digital economy needs an agile approach to cybersecurity

Issue 3 2025 Information Security, News & Events

As South Africa’s digital economy matures, cybercriminals are taking notice and targeting businesses across the country, with major financial consequences. Earlier this year, South African Airways (SAA) faced a significant cyber incident that disrupted access to its online platforms. In 2024, the National Health Laboratory Service (NHLS) was hit by a ransomware attack, which resulted in the loss of 1,2 terabytes of data. These are not isolated incidents, they represent a growing pattern of attacks against businesses that are unprepared when it comes to modern cybersecurity challenges.

“Cybersecurity frameworks offer a blueprint for digital safety and data regulation compliance, but as these develop and proliferate in response to emerging cyberthreats, choosing the right one is increasingly difficult. Particularly in high-risk sectors like fintech, retail, and healthcare, understanding specific requirements must be a top priority,” says Anscombe.


Tony Anscombe.

In 2020, South Africa implemented the Protection of Personal Information Act (POPIA), a legal framework aimed at protecting individuals’ rights to privacy. While these regulations establish what must be protected, cybersecurity frameworks offer a detailed roadmap for achieving compliance.

“Organisations that view cybersecurity frameworks as enablers of trust and innovation, not merely regulatory hurdles to overcome, will likely see more success. With strategic implementation, these frameworks provide the foundation for secure, sustainable digital transformation across the continent – provided they are interpreted and implemented in a way that makes sense for each business,” says Anscombe.

Cybersecurity frameworks

These frameworks generally fall into two categories: mandatory compliance frameworks that organisations must follow to comply with laws or industry regulations, and voluntary frameworks designed to improve their overall security posture. Many businesses struggle to determine which cybersecurity frameworks best address their specific needs, while satisfying regulatory requirements.

“For regulatory frameworks, there is no decision, they are a requirement that must be followed, with significant financial penalties for non-compliance. However, businesses still have important choices to make around voluntary frameworks. Business objectives, risk approach, available resources, and vendor support all influence which framework will be most beneficial,” says Anscombe.

The consequences of inadequate security measures extend beyond immediate financial losses, making compliance failure an urgent business concern across all industries. “Thanks to the disaster management protocol it already had in place, SAA was able to respond to the breach and get back online relatively quickly. However, in the case of the NHLS, the ransomware attack put sensitive medical data of millions of patients at risk and disrupted systems in the middle of dealing with an mpox outbreak,” says Anscombe.

The goal is not perfect compliance with every aspect of a framework, but rather effective protection that enables business growth. “If you take the approach of merely ticking boxes for minimum requirements, you may end up compliant, but not adequately protected. If you stick too strictly to all requirements, your team might become overwhelmed. Careful consideration of what is right for your business and industry, supported by an effective cybersecurity provider, is the best way to ensure protection,” says Anscombe.

For more information go to www.eset.com/za.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
POPIA non-compliance puts municipalities at risk
Information Security Government and Parastatal (Industry)
Digital responsibility must go beyond POPIA compliance to recognising that privacy and service delivery are fundamentally linked. Despite this, only 51 out of 257 municipalities submitted their mandatory data protection and access to information reports in 2024.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Most wanted malware
News & Events Information Security
Check Point Software Technologies unveiled its Global Threat Index for June 2025, highlighting a surge in new and evolving threats. Eight African countries are among the most targeted as malware leaders AsyncRAT and FakeUpdates expand.

Read more...
Firexpo 2025 ignites interest in fire safety
Fire & Safety News & Events
Firexpo 2025 showcased fire detection, suppression, and safety tech, drawing professionals eager to explore innovations, gain insights, and connect with suppliers.

Read more...
Welcome to the new cyber battleground
Information Security
The Iran-Israel conflict is rapidly redefining modern warfare, pushing the boundaries of cyber capabilities and creating a new, borderless digital battlefield. Fortinet’s CISO, Dr Carl Windsor, offers a critical, in-depth analysis of the escalating tactics and global implications in his latest report.

Read more...
African industries may overestimate cyber defences
Information Security
] A significant perception gap exists in security awareness training: 68% of leaders believe training is tailored to roles, yet only a third of employees feel adequately trained. Many organisations only conduct annual or biannual generic training that may not effectively change behaviour.

Read more...
SMARTpod talks to Sophos and Phishield
SMART Security Solutions Technews Publishing Sophos Videos Information Security News & Events
SMARTpod recently spoke with Pieter Nel, Sales Director for SADC at Sophos, and Sarel Lamprecht, MD at Phishield, about ransomware and their new cyber insurance partnership.

Read more...
Cybersecurity and insurance partnership for sub-Saharan Africa
Sophos News & Events Information Security Security Services & Risk Management
Sophos and Phishield Announce first-of-its-kind cybersecurity and insurance partnership for sub-Saharan Africa. The SMARTpod podcast, discussing the deal and the state of ransomware in South Africa and globally, is now also available.

Read more...
Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.