
Johannesburg High Court: Companies Must Mitigate Cloud Security Risks
Summary
- South African businesses assume that moving to the cloud ensures security, but this is a misconception.
- Identity-based attacks now account for the majority of breaches globally and locally.
- The Protection of Personal Information Act places direct obligations on companies to safeguard personal data and report breaches.
- Continuous visibility into identity and cloud configuration is essential for mitigating the risk of identity-based attacks.
Cloud Security Misconceptions in South Africa
Cloud providers secure their infrastructure, but customers are responsible for what happens inside that infrastructure, including who has access and which services are exposed.
South African businesses often assume that moving to the cloud automatically ensures security. However, this assumption is misplaced. Cloud providers secure their infrastructure, but customers are responsible for what happens inside that infrastructure, including who has access and which services are exposed. This shared responsibility model is poorly understood by many local companies.
The consequences of this approach are stark. Globally and locally, identity-based attacks now account for the majority of breaches. These attacks often involve stolen credentials or compromised accounts, rather than sophisticated hacking. The fact that many organisations only discover they have been breached weeks after the initial attack is particularly concerning.
The Protection of Personal Information Act: A Compliance Challenge
The Protection of Personal Information Act places direct obligations on companies to safeguard personal data and report breaches. However, the discovery gap created by identity-based attacks poses a significant compliance challenge. Companies must ensure they have continuous visibility into their cloud configuration and identity management systems to meet these obligations.
In addition, the act's breach reporting requirements highlight the need for businesses to be able to understand and respond to security incidents in a timely manner. This requires more than just technical expertise; it demands that executive management can grasp the business risk implications of cyber exposure.
The Importance of Continuous Visibility and Expert Judgement
Continuous visibility into identity and cloud configuration is essential for mitigating the risk of identity-based attacks. This requires more than just relying on security tools; it demands expert judgement to interpret the data generated by these tools.
Under King IV, directors carry a governance responsibility for technology and information risk. However, many are asked to discharge this responsibility based on reports they cannot properly interrogate. To govern the business responsibly, executive management must be able to understand its own cyber exposure in the same terms it understands credit risk or currency exposure.
Practical Implications
South African businesses must ensure continuous visibility into identity and cloud configuration to mitigate the risk of identity-based attacks, which are now behind most cloud breaches, and comply with the Protection of Personal Information Act's breach reporting obligations.
Source
Source: Original reporting via Briefly
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Wansom is AI and can make mistakes.
