InfoReg says Data breaches rising at alarming rate!

cybersecuritybreaches
In the midst of a security crisis in South Africa, the Information Regulator chairperson, Advocate Pansy Tlakula, reveals a staggering increase in data breach notifications, surpassing 150 a month. This alarming revelation came to light during a fireside discussion with ITWeb editor-in-chief Adrian Hinchcliffe at the ITWeb Governance, Risk, and Compliance 2024 conference. Tlakula expressed concern over the lack of seriousness regarding cybersecurity among South Africans, emphasizing the escalating numbers and the fertile ground hackers have found in the country.

Last year, Tlakula disclosed around 56 monthly data breaches based on notifications, attributing the surge to the over-processing of personal information of data subjects. However, the situation has worsened, with the current rate exceeding 150 data breach notifications each month. Tlakula stressed the gravity of the situation, labeling data breaches in the country as "very serious" and "scary."

In response to this escalating threat landscape, StormWarning! emerges as a beacon of cybersecurity resilience, offering online NIST cybersecurity audits. StormWarning! stands committed to helping organizations comprehensively understand their cybersecurity risk status. With a dedicated team of experienced professionals, StormWarning! an all South African tailors customized cybersecurity solutions to meet the unique needs and requirements of South African organizations.  Enhancing their cybersecurity profile across the entire organizational spectrum to meet the unique SA Cyber environment.

Despite the increasing challenges, the TransUnion security compromise remains a significant concern in South Africa, involving millions of people. The 2022 TransUnion hack, where N4ughtySecTU demanded a $15 million ransom for four terabytes of compromised data, marked a critical moment in the country's cybersecurity landscape. The group claimed access to 54 million personal records, including details of President Cyril Ramaphosa.

South Africa has witnessed a surge in high-profile cyber attacks, affecting credit bureaus, government departments, and banks facing highly organized distributed denial-of-service attacks. The Council for Scientific and Industrial Research estimates annual financial losses of up to R2.2 billion due to cybercrime in the South African economy.

Data from Kaspersky further underscores the prevalence of cyber incidents, with 82% of surveyed South African companies reporting various forms of cyber threats, including 11% caused by deliberate malicious behavior by employees. In this precarious environment, the Information Regulator, led by Advocate Pansy Tlakula, plays a crucial role in enforcing data privacy measures under the Protection of Personal Information Act (PoPiA), striving to safeguard the privacy of South Africans.

As cybersecurity challenges continue to evolve, StormWarning! also stands ready to assist organizations in staying ahead of the threats and fortifying their cybersecurity defenses.


Offences, Penalties and Administrative Fines

Sections 100 – 106 of the POPI Act deal with instances where parties would find themselves “guilty of an offense”. The most relevant of these are:
  1. Any person who hinders, obstructs or unlawfully influences the Regulator;
  2. A responsible party which fails to comply with an enforcement notice;
  3. Offences by witnesses, for example, lying under oath or failing to attend hearings;
  4. Unlawful Acts by responsible party in connection with account numbers;
  5. Unlawful Acts by third parties in connection with account number.
  6. Section 107 of the Act details which penalties apply to respective offenses.

For the more serious offences the maximum penalties are a R10 million fine or imprisonment for a period not exceeding 10 years or to both a fine and such imprisonment.

For the less serious offences, for example, hindering an official in the execution of a search and seizure warrant the maximum penalty would be a fine or imprisonment for a period not exceeding 12 months, or to both a fine and such imprisonment.

Failure to comply with the requirements of the POPI Act could have dire consequences.

This article must be read in conjunction with the POPI Act which can be downloaded from Act No. 4 of 2013 : Protection of Personal Information Act, 2013 

StormWarning! CyberSecurity Consultants

Is your organisation ready for the coming CyberSecurity Storm?..

                           ...Best you contact StormWarning! today  for a NIST CyberSecurity Audit and we will do our very best to answer that question for you and your organisation, rest assured, we will diligently endeavor to support your organization while adhering to the constraints of your budget.

CONTACT US NOW!

 

 SOME CYBER SECURITY STATISTICS TO CONSIDER

How many cyberattacks per day?
According to Security Magazine, there are over 2,200 attacks each day which breaks down to nearly 1 cyberattack every 39 seconds.

How many people get hacked each year?
With around 2,220 cyberattacks each day, that equates to over 800,000 attacks each year.

What percentage of cyberattacks include a social engineering aspect versus a technical problem?
According to Cybint, nearly 95% of all digital breaches come from human error.

Related Articles

What is StormWarning! ?

 StormWarning! is a Cybersecurity consultancy. Our experienced team of cybersecurity experts provide cybersecurity assessments, cybersecurity training and cybersecurity solutions to organisations that have a high risk public profile. StormWarning! is your organisation's best defense against the ever growing cascade of innovative security threats raining down on all organisations with a public digital footprint.

What is Cybersecurity?

Cybersecurity is the practice of protecting critical systems and sensitive information from digital attacks. Also known as information technology (IT) security, cybersecurity measures are designed to combat threats against networked systems and applications, whether those threats originate from inside or outside of an organization. StormWarning! is constantly researching the latest cybersecurity threats and building innovative measures to prevent them.

 

NIST Audit & Targeted Cyber-Risk Training

StormWarning! offers comprehensive Cybersecurity Consulting, with a focus on its Automated Online Auditing Solutions, primarily the NIST CSF Readiness Audit. This audit is prioritized as its results directly inform the organization's needs for targeted cybersecurity training. By identifying specific gaps in risk management knowledge, they deliver precise education via Short Courses—like Cybersecurity Risk Management or Understanding Cybersecurity GRC—to ensure staff and leadership close deficiencies and maintain compliance.

Their full suite of services also includes robust Risk Management planning, development of essential Policies, impactful Cybersecurity Awareness Campaigns, and a security monitoring/incident response platform, StormFront. Additionally, we offer a resource library of Cybersecurity Books authored by our esteemed associate Dr. Zoran Mitrovic.