The broad adoption of cloud computing technologies and services in South Africa has gained pace over the past few years. Local businesses of all types and sizes are using cloud services because maintaining their own infrastructure is costly, and they hope to boost efficiency, lower costs and simplify their technology investments.
A substantial number of these local businesses, however, are storing sensitive information relating to clients, employees or the business itself, as well as using it for day to day operations. “This is particularly true of businesses involved in industries such as finance, healthcare and retail, as they house highly confidential customer data, and can face huge penalties should this data be compromised. Public disclosure in the event of a breach is now a legal requirement, which could result in lost revenues as well as customer confidence,” says spokesperson from MWR Infosecurity.
This creates an environment where you could seriously see companies losing business if they are repeatedly compromised. As a result, most businesses will (hopefully) be forced to consider and incorporate security into their business model. “However, lack of awareness of security issues is probably a major contributor to why businesses don’t take security as seriously as they should. From what I’ve seen, security is not necessarily a major concern in South Africa and the few companies that do try to take it into account just don’t have an adequate background to address security properly,” explains spokesperson.
He says this could result in them focusing on the wrong things; the high-profile attacks that litter the headlines, and not the real threats themselves. “You may find that they simply assume that a cloud provider would take care of security without ever checking up on that, or assuming that there is no way a third party would be able to manage security better than they do.”
However, if a South African company ever wants to compete in the international market, they’ll be judged according to the same standards as foreign businesses and that means they need to give the same attention to security, he adds.
Security of cloud infrastructure is also a concern because it is being shared with other users. “I read an article a while ago about ransomware encrypting a company’s entire system which resided mostly on the cloud. If you are sharing infrastructure with someone else, you need to secure your host because you don’t want their problems to become yours. Alternatively, another client for the same cloud provider may be malicious, at which point an insecure cloud service could be something of a gold mine.”
He believes cloud security is almost like mobile security, it’s one of those things that get a lot of media attention in the form of “cloud security is important” but without a real exploration of what cloud security is.
“Much in the same way as mobile security, if you look at the Verizon Data Breach Report or similar, this is just how companies are now getting breached. Companies are still getting compromised through users and their workstations. Until the world at large starts focusing on how organisations are really getting compromised, we will keep throwing money at ‘blinkenboxes’ that solve problems we don’t have.”
In terms of securing the cloud, he advises to consider actual security, not merely regulations, though they may help drive the minimum standard. He also believes that technical issues would probably be a major concern, including:
- Hosting system set up (OS, software, firewall, segregation of different user environments, services running, hard drive encryption, etc.)
- Communication security
- Security policies (updates, patch policies, information access control. This enables encrypted back-ups but companies should look at who in the business can access that and whether the host company has a key too)
- Disposal of equipment (most specifically hard drives that may have sensitive info)
- Security of the actual services offered
Behind the scenes: Established in 2003, MWR InfoSecurity is a research-led information security consultancy, with a client list spanning the major world indices and Government agencies & departments. MWR consults with clients around the globe, providing specialist advice and services on all areas of security, from mobile through to supercomputers.
Central to its philosophy is the desire to deliver high quality cyber security consulting services and unsurpassed levels of support to clients. MWR’s focus is working with clients to develop and deliver a full security programme, tailored to meet the needs of each individual organisation.
www.mwrifodsecurity.com / @mwrinfosecurity/@mwrlabs/@mwrphishd/@countercept
- Motoring News | Diesel and Dust | Tumelo Maketekete | #Motoring | #ebizradio | #Podcast - October 15, 2021
- How is AI going to affect both Business and the Advertising landscapes? | #Marketing | #LunchtimeSeries | Kevin Britz | Craig Page-Lee | #ebizradio | #Podcast - October 15, 2021
- How do youth actually consume content? | #Entrepreneur | #WordOfMouth | Lindi Tshabangu | Khathutshelo Bapela | #Podcast | #ebizradio - October 14, 2021
- Since SA has have moved to level 1 lock-down, what effect is this having on the markets? | #Insights | #Trading | Zihad Israel | CMTrading | #ebizradio - October 14, 2021
- Behind the scenes with a Theater Producer | #BusinessBrunch | #Insight | Björn Salsone | Bernard Jay | #Pantomime | #Podcast #ebizradio - October 12, 2021
- Now is the time to make money in this market | #Insight | #Money | Daniel Kibel | CMTrading | #ebizradio - October 11, 2021
- How Trade Specialisation might make you a rich Forex trader | #Insights | Finance | Tope Ijibadejo | CMTrading | #ebizradio - October 8, 2021
- Who are and why are these South Africa’s brands ranked the most valuable? | #Marketing | #Insight | Kevin Britz | Craig Page-Lee - October 7, 2021
- Ubuntu is the spirit of wealth | Investing in YOUR people | #Insight | Nelisiwe Massabgo | #ebizradio - October 7, 2021
- THE NEW REASON TO GET UP FOR WORK IN THE MORNING – Becoming a future-fit employer in a Pandemic | #Business | #Insight | Sibongile Bobo Mngxali | Roche Diagnostics | #ebizradio - October 6, 2021