Sunday, 6 October 2024
22.7 C
Durban

Cybersecurity is more than a tech issue – it’s a business problem too

Home Engineering ICT Cybersecurity is more than a tech issue – it’s a business problem...

A concerning number of South African companies are not prepared for the inevitability of a cyberattack despite the significant financial and reputational risks, according to Ryan Mer, Managing Director, eftsure Africa, a Know Your Payee (KYP) platform provider.

“Too few senior managers view cybersecurity as a business problem and not just a technology problem,” he said.

“The reality is cybersecurity is very much a business consideration. CEOs and CFOs will eventually face critical questions such as: How much money do we spend on cybersecurity? Do we change key processes? How do we create awareness and change company culture? Do we put security ahead of operational functionality? What is the role of internal processes and staff on data security and integrity?”

Mer added that because cybersecurity is a business-wide risk it requires more than isolated activities to be addressed. “This is where the role of a Chief Information Security Officer (CISO) is important. The CISO therefore needs to have technical and security skills and competencies, but equally as important, should understand the finance function, operations of the business, and have the business as well as communication skills to effectively create this span.”

While large corporates are more likely to have the resources to fill the CISO role, businesses below the corporate level may not. In such instances, said Mer, an outsourced or CISO-as-a-service offering could add immense value.

“Ultimately, and especially in relation to the Protection of Personal Information (POPI) Act, there needs to be a coherent strategy and allocated responsibility in place with respect to cybersecurity, data management, compliance and fraud prevention.”

He added that in the absence of commonplace and well-developed CISO roles, it is the CFO who should lead the way in addressing cybersecurity concerns, particularly in smaller organisations.

“It is potentially disastrous for the finance team to be ignorant of cyber risk. Attackers can target many areas of an organisation, but the dangers are usually measured in financial terms: CFOs cannot ignore cybersecurity simply because it is a complex issue outside their area of expertise.”

In addition to having the skills and oversight necessary to take a broad and long-term view of the potential financial impact of an attack, Mer said the CFO is one of the most natural custodians of data, from collection to its ongoing management.

“Attacks will very often target the finance department and its team members directly, and in many instances may even be perpetrated by or assisted by internal team members, in attempts to steal and defraud the business. CFOs need to ensure their own vulnerabilities are both understood, and urgently addressed.”

Most Popular

UKZN institute’s new high-tech rocket launch gantry a first for SA

ENGINEERS at the University of KwaZulu-Natal’s Aerospace Systems Research Institute (ASRI) have commissioned a new suborbital sounding rocket launch facility at the Denel Overberg...

State-owned energy company formed by merged subsidiaries

A POLICY statement by President Cyril Ramaphosa has resulted in the formation of a new state-owned petroleum company, the South African National Petroleum Company...

Time is running out on the 125% solar tax incentive

BUSINESSES that act quickly can still take advantage of the substantial 125% income tax incentive available for solar energy projects completed and operational by...

Diversified packaging group disposes of assets, refinances

NAMPAK Limited, the largest diversified packaging company in Africa, issued an update on Monday on key company developments including the asset disposal program and...