Securing business systems goes beyond the technology

Issue 8 2021 Information Security

While companies invest a great deal of time and effort in securing their systems, remote and hybrid working has forced businesses and their staff to acknowledge that security goes beyond technology. For all the best technology, a human lapse could result in a catastrophic breach.


Tim Wood.

Let’s use an analogy that many South Africans will be accustomed to. Security-conscious estates or complexes have varying levels of access control. These complexes have high walls, electric fences, security guards manning key entry points and many – if not all – have security monitoring and patrolling the premises 24/7.

It’s possible that this environment could lull someone into a false sense of security and they’d let their guard down. However, we know that this would be a mistake. Just because the complex or estate boasts these security measures, there are still several ways someone could be at risk.

When they enter and leave the complex, they could become targets of criminals. When they are inside their own unit, they may not be aware of an undetected breach at the estate’s entrance. It is possible criminals are operating from within the secured estate. What if they have adult children going in and out late at night?

Obviously, this is not an exhaustive list of possibilities, but the point is obvious – it would be a mistake to be lulled into taking anything for granted because we understand that security extends beyond the physical measures in place. And so, in the South African context, one invests in physical security and then continually remains aware of risks and behaves in a way to minimise them.

Similarly, securing a company requires a conscious effort and it involves an interplay of people, processes and technology. In a traditional workplace setup, a company can – and will – do all that it can to control its environment. As the pandemic has shown so vividly, this environment no longer exists only in a physical form, yet the requirement to secure it remains.

A company can no longer lock the doors and rely on the fact that access is restricted. Systems need to be accessed remotely and in providing for this you lose control of the environment. As sobering as it is, you must start with the premise that your staff will, at some point, leave their laptop unattended in a public space.

Securing company systems requires protecting your software, protecting your hardware, protecting and backing up your data and the ongoing education of your system’s users. To get this right, it is important to ask - and answer - who is accessing your systems, from where, using what, how and why they are accessing them?

Who is trying to access your systems?

In an ideal scenario, it is your employee attempting to access company systems. However, someone may have stolen login credentials, which would be a targeted and planned attack. Alternatively, it is also possible someone encountered an unlocked device and is opportunistically attempting to gain access. There are various ways to mitigate this risk. User access management is paramount. A company needs strong password policies such as complexity rules and password resetting timetables. Multi-factor authentication adds a layer that could be the difference between being breached or not.

One cannot always rely on an employee to remember to lock their devices every time they are not using them and so auto-lock is crucial. Encrypting external devices such as hard drives and USB sticks is vital – what if an employee leaves a USB stick on a coffee shop table or airport lounge chair?

Where is the employee working from?

Remote working means that an employee must access systems from various locations. In many instances, it will be their home, but they could also be accessing systems from an airport or café. As a priority, organisations should implement virtual private network (VPN) technology to ensure encrypted and private access to the corporate network.

As part of the ongoing education, employees should learn to become aware of their surroundings and the potential for eavesdropping. They should make the care and security of physical assets like laptops a priority. This extends to clean desk policies – nothing should be left lying around, while each employee should understand how to appropriately dispose of printed documents.

What devices are they using to access systems?

As far as reasonably possible, it would be wise to restrict access to company systems from devices other than company-managed assets. It is not ideal for staff to use personal or shared devices. With company-managed assets, a business can invest in central device management software, including the ability to wipe devices remotely. It enables companies to encrypt hard drives, ensure appropriate back-ups are in place and update devices with the latest operating systems and malware and antivirus software.

How is the employee accessing your systems?

While employees may access company systems through their dedicated home fibre, it is also possible they are connecting via public Wi-Fi access points. Again, it can never be overstated – education is paramount. Take the time to teach staff about the dangers of unsecured Wi-Fi and honeypots, as well as being aware and alert to their surroundings. Then reinforce this message consistently.

Why are they accessing the company system?

They may need to access emails and collaboration tools, but it may also be that they work in critical areas such as payments. There are various things a company can do here, including limiting access levels depending on the employee’s job function, monitoring the device activity of staff working in critical areas and running vulnerability scans and penetration tests, which are simulated cyber-attacks against your own system to isolate vulnerabilities that need to be addressed.

Securing a business’s systems is an ongoing task. It is about cultivating a company-wide security mindset as much as it is about investing in the best available technology. Very much like living in South Africa today.


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...
Cyber resilience is the real defence
Security Services & Risk Management Information Security Infrastructure
Cyber resilience has evolved into a form of strategic agility, ensuring that when an interruption occurs, the business does not just survive; it snaps back into place before the market even notices a pause.

Read more...
You will not get your files back with VECT
Information Security
If the newbie to the ransomware scene, VECT, comes knocking at your organisation’s door, do not pay the ransom! The decryption keys simply do not exist. They were discarded at the moment of encryption by the malware itself.

Read more...
Industrial sector is a primary cyber target
Information Security
Threats in industrial environments are distributed with striking uniformity: APT-driven incidents constitute 17,8%, malware 14,9% and social engineering 13,9%. This pattern suggests that industrial organisations attract a broad range of adversaries with different capabilities and objectives.

Read more...
Key attributes of an effective cybersecurity leader
BlueVision Information Security
In an evolving technology landscape, an effective cyber leader must combine technical acumen, foresight, and adaptive leadership to mitigate risks, and risks can only be mitigated once accurately identified and remedial processes are in place.

Read more...
Employees are SA’s biggest cyber threat
Security Services & Risk Management Information Security
South Africa experienced a 46% increase in insider cyber risk in 2026, surpassing the global average of 44%. What is more, 63% of South African companies surveyed expect insider-driven data losses to increase.

Read more...
Surge in AI-enabled cybercrime and a 389% increase in ransomware
News & Events Information Security
Cybercrime no longer functions as a series of isolated campaigns; it operates as a system, with malicious hackers operating across an end-to-end life cycle and compressing the attack life cycle with shadow agents.

Read more...
Tackling enterprise security ‘tool sprawl’
NEC XON Information Security
South African ICT solutions provider NEC XON is advocating a shift away from fragmented cybersecurity toolsets towards unified platforms, arguing that ‘tool sprawl’ is undermining the effectiveness of enterprise security operations.

Read more...
SilverFox campaign targeting companies in South Africa
Information Security News & Events
The APT campaign involved disguising malicious files as documents related to tax violations. Upon infection, attackers could gain remote access to affected devices and exfiltrate sensitive organisational data.

Read more...
Q-Day is closer than you think
Information Security
The accelerated 2029 quantum computing deadline turns current encryption into a looming crisis as Google brings its internal post-quantum cryptography migration deadline forward to 2029.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.