Newsletter Subscribe
Enter your email address below and subscribe to our newsletter


Although most companies have invested in IT security solutions to protect their networks and data, these tend to focus on mitigating the most common threats like viruses and malware and fall short of addressing more sinister risks such as fraud, identity theft and espionage.
These are damaging threats that can put a company’s reputation and business continuity at risk and can have serious financial implications. It is only when IT security-related risks are considered as business risks that the relevance of addressing them with proactive, strategic and appropriate solutions really becomes apparent – and this has to come from the top.
“Cyber risks should be treated as business risks and should form part of a company’s overall risk management strategy. This has to be a top-down drive; from C-level employees, for whom the cost of a breach or leak is highest, to everyone else in the organisation that has access to information systems,” says Charl Ueckermann, CEO at AVeS Cyber Security.
Cybercrime is burgeoning rapidly, not only in volume but sophistication as well; while 70% of threats faced by enterprises are known, 30% are unknown, advanced threats that traditional signature-based security technologies alone cannot tackle.
Cybercriminals are also becoming far more discerning and are targeting their attacks. Though more targeted, they often employ basic methods to implement their attacks. These methods can include social engineering, stealing of employee credentials, imitating legitimate software or even using malware covered by a stolen certificate to infiltrate systems. Ransomware, a type of malware that encrypts data and either prevents or limits users from accessing their systems, is typically targeted at C-level employees as well as departments dealing with sensitive information, such as accounts and human resource departments. These types of advanced, targeted cyber incidents are becoming more prevalent – even in South Africa.
“With this in mind, it becomes quite clear that organisations need a multi-disciplinary approach that is aligned with their specific risk management requirements and includes the implementation of appropriate IT security solutions, ongoing monitoring, analysis of IT security intelligence, and employee education. Regardless of how expensive or robust the IT security technologies are, they will not be fully effective unless everybody throughout the enterprise, starting at the top, understands the risks and supports the IT security strategy,” says Ueckermann.
He offers this advice to C-level employees for managing IT security risks to their organisations:
“To put organisations at ease, there are various computer-based training products available that leverage modern learning techniques and address all levels of the organisational structure”, says Ueckermann.
“Every individual in the organisation using a computer is responsible for IT security, not just the IT department. Cybersecurity awareness and education are, therefore, fundamental to the effectiveness of your risk management strategy,” he concludes.
Edited By: Darryl Linington
Follow @DarrylLinington on Twitter
Follow @ITNewsAfrica.com on Twitter