What is the BIG FUSS with Cyber Security and Data Breaches

Published: 02 August 2018

With the current crisis of cyber-attacks and data breaches or leaks, we are faced with low rates of cyber security vigilance and high cybercrimes. Every enterprise is challenged to constantly back up their cyber security system to protect their database and information systems to avoid these data leaks and cyberattacks.

Menny Barzilay, Head of IT Audit of Bank Hapoalim described Cyber Security as “the sum of efforts invested in addressing cyber risk, much of which was, until recently, considered so improbable that it hardly required our attention,” in an article on ISACA’s Knowledge Centre. When we further define cyber risks, which is the loss or harm of information due to a cyberattack or data breach, we then see the need of efficiently protected information systems.

Data or Personal information is an extremely valuable commodity because when in the wrong hands, it is used for financial benefits by cyber criminals who participate or gain information from data breaches. The cyber criminals take the data and sell it and in return make a lot of money out of the whole data breach.

In a radio interview Mr Sizwe Snail ka Mtuze, Director of Snail Attorneys and Lex-Informatica, said “Your ID number is so Important because it identifies you, your birth date, your race, your citizenship and whole lot of other things which could be used for an unlawful purpose”, when asked why information like a person’s ID number is so important to these cyber criminals. Anyone or any organisation with confidential information in their possession is a target. How would an organisation know whether they are ready? Whether they have the enough information security? the reality is that these cyber criminals are getting smarter and more advanced in the techniques they use.

According to an article on Fin24.com, “Without a fully functional Information Regulator, these breaches will continue to occur without sanctions provided for in the Protection of Personal Information Act (POPIA)”, said Advocate Pansy Tlakula, Chairperson of the information Regulator of South Africa . Which is why organisations and individuals need to be in the business of effectively educating themselves on cyber security vigilance, cybercrime trends, data breaches and cyber law.

What are we doing as organisations to protect ourselves? What measures are we taking? What legal implications are there regarding such incidents? The assumption that cyber vigilance is the primary function of only IT, Legal, Compliance, Risk or Information Management in organisations is where the loophole in our information security is found.

Lex-Informatica SA Cyber Law and ICT workshop is focused on equipping people with necessary skills and education to guard against threats in their workplaces, homes and IoT devices.
Date: 13th and 14th September 2018
Venue: Durban Country Club
Theme: "The advancements of Information and Communication Technology Law - Cyber Law: Techniques, Risks, Legal implications and Emerging trends"
Book your seat here to be enlightened on the reality, cost and possible threats of cyberattacks to your business, personal data and other interconnected devices.

For more info please contact Ms Paballo Mokake on:
Email: This email address is being protected from spambots. You need JavaScript enabled to view it.
Telephone: 0127702312

Is training the solution for Information Security Awareness?

Published: 25 June 2018

Protecting and handling confidential data has come into the limelight with the electronic boom. With multiple copies of the documents being available in electronic format, it becomes difficult to monitor their usage. Companies that misuse or inadvertently leak confidential data face multi-fold consequences ranging from lost reputation to expensive lawsuits and fines worth millions of rands.Information security training prevents security breaches that may be caused inadvertently by employees. Organisations need to consolidate and strengthen their information security strategies by establishing well laid out practices and investing in security awareness programs.Humans are often considered as the weakest connection in the information security chain.

This accusation may be circumstantially right, but it also neglects the fact that humans, if properly motivated and educated, can play an important role in reinforcing the security ecosystem.Security-conscious employees can pick up the slack, where the technology and processes fail, acting as a last resort in the security defence mechanism.According to the Information Regulator Chairperson “South Africa has experienced a disturbingly high number of material data breaches in the past few months. In addition to Liberty Holdings, there have been material data breaches at Master Deeds, Facebook and ViewFine,” Tlakula said. So training your employees on information security is very important. Such trainingReduces organisation’s risk profile: Good information security training gains confidence, trust and loyalty. It reduces the risk of devaluating the organisation’s brand.

Reduces direct and indirect costs: Strict information security training, helps cut down the expenses associated with data loss, data recovery etc., thereby reduces direct and indirect costs.Reduces technology leakage risks: There is always a possibility of making careless mistakes. Thus, in order to protect our technology from being hacked, training is necessary.

The task of safeguarding personal and business data forms the cornerstone of any company’s business. So, it should be ensured that all employees follow privacy policies in a proper manner. The companies must ensure this happens through an effective training approach.Infex Web Solutions have designed an online course in information security awareness training, touching important aspects of information security. The course explains how to identify, handle, and dispose data based on its sensitivity. The course is coupled with scenarios advising employees what they should do on facing certain situations. Effective training on the awareness of information security, could actually make you and your company more secured from the risks of information breaches. 

To find out more about the Information Security Awareness Training visit https://www.infexweb.co.za/ or email This email address is being protected from spambots. You need JavaScript enabled to view it.: 011 036 6570