‘Life and death issue’ — SA health lab service shuts down test results communication system after cyberattack



A recent survey conducted by the multinational technology company Cisco has revealed that South African businesses lack adequate preparation for cyberattacks. According to the index, only 5% of South African companies have attained a mature level of readiness against cybersecurity threats.

In today’s digital age, cybersecurity ranks among the top concerns for nations worldwide. South Africa, like many others, faces a significant challenge: a growing disparity between the demand for skilled cybersecurity professionals and the availability of qualified individuals to fill these vital roles. This gap not only puts businesses at risk but also weakens the nation’s overall cybersecurity resilience.
Despite the critical nature of the issue, it seems that government, business, and educational institutions in South Africa lack sufficient awareness and are slow to address the problem. There’s a noticeable absence of proactive measures to effectively bridge the cybersecurity skills gap.

The Companies and Intellectual Property Commission (CIPC) has officially reported an "attempted security breach" resulting in the unauthorized exposure of personal information belonging to both employees and clients.

The Information Regulator of South Africa has recently issued its inaugural enforcement notice as a consequence of a direct marketing complaint. This notice was directed towards FT Rams Consulting, an educational institution, following the Information Regulator's determination that the organization had violated various provisions of the Protection of Personal Information Act (POPIA).
The biggest shift the IBM X-Force® team observed in 2023 was a pronounced surge in cyber threats targeting identities.

Based on the input from 170 countries worldwide, the IBM X-Force Threat Intelligence Index report for 2024, has identified the main cyber-attack trends of 2023 that revolved around four key areas: identity and access management, data security, applications, and generative AI. While these trends pose significant challenges, the report also offers recommendations on how to prevent and mitigate these threats.
In 2023, valid accounts stood out as the primary target for attackers, comprising 62% of incidents. Notably, the abuse of these valid accounts, along with phishing attacks, constituted the top threat. Each of these attack types contributed to 30% of identity theft cases, marking a significant 71% increase from 2022.
Credential theft primarily occurred through two methods: phishing and info stealers, accounting for 30% and 28% of incidents, respectively. Phishing was further categorised into two groups – bogus links and malware-containing attachments – both aimed at collecting user credentials, thus facilitating access credential theft.
Recommendations related to Identity and Access Management (IAM) emphasize the inefficiency of relying solely on single-login systems with usernames and passwords. Thus, it is crucial to implement multi-factor authentication (MFA) and utilize passkeys to bolster identity protection. A passkey is a unique code or token used for authentication purposes to provide an additional layer of security beyond traditional passwords.
StormWarning! is a Cybersecurity consultancy. Our experienced team of cybersecurity experts provide cybersecurity assessments, cybersecurity training and cybersecurity solutions to organisations that have a high risk public profile. StormWarning! is your organisation's best defense against the ever growing cascade of innovative security threats raining down on all organisations with a public digital footprint.
Cybersecurity is the practice of protecting critical systems and sensitive information from digital attacks. Also known as information technology (IT) security, cybersecurity measures are designed to combat threats against networked systems and applications, whether those threats originate from inside or outside of an organization. StormWarning! is constantly researching the latest cybersecurity threats and building innovative measures to prevent them.
StormWarning! offers comprehensive Cybersecurity Consulting, with a focus on its Automated Online Auditing Solutions, primarily the NIST CSF Readiness Audit. This audit is prioritized as its results directly inform the organization's needs for targeted cybersecurity training. By identifying specific gaps in risk management knowledge, they deliver precise education via Short Courses—like Cybersecurity Risk Management or Understanding Cybersecurity GRC—to ensure staff and leadership close deficiencies and maintain compliance.
Their full suite of services also includes robust Risk Management planning, development of essential Policies, impactful Cybersecurity Awareness Campaigns, and a security monitoring/incident response platform, StormFront. Additionally, we offer a resource library of Cybersecurity Books authored by our esteemed associate Dr. Zoran Mitrovic.