As a small to medium-sized business owner or IT Manager, you are vulnerable to all kinds of cybersecurity risks. Preparation significantly reduces risk, but cyber risk can never be fully eliminated. With proper preparation, you can put your mind at ease. In my view, many small businesses underestimate cybersecurity until something actually goes wrong, and by then, it’s usually too late.
Here are some common threats you may find:
Business Email Compromise (BEC)
In a BEC, attackers impersonate someone (usually an executive or supplier) to gain access to sensitive information or siphon funds with fraudulent banking information. To prevent such an attack, you are advised to implement strict verification processes for all high-risk information. Never use contact information found in suspicious emails. Educate all employees on these risks, as a single slip-up can drag everyone with it.
For example, an attacker might send an email pretending to be your CEO asking the finance team to urgently pay a supplier. Under pressure, the payment gets made, only for the business to realise later that the bank details were fake
Ransomware
Imagine arriving at work one morning and finding that none of your files can be opened, with a message demanding payment to unlock them. Without backups, your business could come to a complete standstill. This is Ransomware. Ransomware is a type of malicious software that encrypts a user’s files and demand payment (usually in the form of cryptocurrency) in exchange for decrypt the files. To prepare for such a scenario, make sure to keep backups for all your data on different devices. Ransomware is honestly considered one of the most disruptive threats.
Phishing
Phishing (similar to BEC) has an attacker impersonate someone (usually a company). Unlike a BEC attack, a phishing attack is non-targeted, meaning hundreds of thousands of emails are sent out to different people. Common types of phishing emails will claim that your account has been suspended or that something is off with your banking details. To identify a false/spoofed email, you have to pay close attention to spelling. Imagine receiving an email from GoogleSupport.com and Goog1eSupport.com, they may initially look the same, but upon closer inspection, they lead completely different places.
Supply chain compromise
Instead of attacking a secure company, malicious individuals sometimes target a weaker supplier to gain access to a company’s customer base. To avoid this, you should limit the permissions and access scopes granted to vendors and external services. While at the same time demanding strict security procedures for all third-party providers.
Why South African businesses?
South African infrastructure and markets pose extra challenges such as:
Limited cybersecurity knowledge
Research by MiDO Academy reveals that 56% of South African organisations find it difficult to recruit cybersecurity specialists. Meaning we are going through a major shortage of qualified personnel.
Cloud adoption without appropriate security
South African businesses often rush to adopt cloud-based models with the hope of escaping the South African infrastructure constraints. Cloud security depends on correct configuration and identity control.
Loadshedding
The power instability in South Africa leads to periods of time when you could be left wide open and vulnerable to attacks. The abrupt shutdown can also result in corrupt data or backup processes being ruined.
Cybersecurity is seen as optional
Some businesses don’t understand the importance of cybersecurity until it’s too late. Cybersecurity is treated like a compliance cost instead of something that your business needs in order to run.
Cyber attacks often lead to more than just disrupting the workflow.
Some impacts include:
Financial loss
Ransomware attacks can become very expensive once you factor in both the ransom itself and the disruption to your services.
Reputation damage
Weak cybersecurity can damage your reputation, causing clients to lose trust and potentially walk away.
Non-compliance with the POPIA Act
Under the POPIA Act, organisations must protect the privacy and confidentiality of personal data. Failing to do so puts both the business and its clients at risk
We can breakup the stages of Cybersecurity readiness into 5 stages.
1. Initial – Informal and unorganised. This level is focused on reacting rather than preventing.
2. Developing – Basic practises are standardised and documented.
3. Standardised -Policies are standardised and stretch over the entire organisation.
4. Proactive – Security is continuously monitored and measured with specific metrics.
5. Optimised – Security is continually improved and adapted to current and relevant threats.
How can I reduce cybersecurity Risks
While the risks above may seem overwhelming, most cyber threats can be significantly reduced by implementing a few core controls. Businesses do not need highly advanced systems to improve their security—discipline and basic measures go a long way.
Improve Local Infrastructure
• Use UPS or backup power for critical IT systems during loadshedding
• Ensure backup processes are not interrupted by power outages
• Plan for secure system shutdowns and restarts
Strengthen Access Control
• Use multi-factor authentication (MFA) on all email, banking, and cloud systems where possible.
• Limit user access to only what is required (least privilege principle)
• Regularly review and remove unused accounts
Secure Your Financial Processes
• Always verify banking detail changes using independent communication (e.g., phone call)
• Create clear internal procedures for handling invoices and payments
Back Up Data Properly
• Maintain regular backups (daily or weekly depending on business needs)
• Keep backups in separate locations (cloud + offline/external storage)
• Test backups periodically to ensure they can be restored
Continuous Cybersecurity awareness Training
• Educate staff on Identifying phishing emails, Handling suspicious links and attachments and reporting unusual activity immediately.
• Run simple internal awareness sessions or simulated phishing tests
Protect Devices and Systems
• Install reputable antivirus/endpoint protection on all devices
• Keep systems, software, and apps regularly updated (patching)
• Use firewalls and basic network security controls
Manage Third-Party Risk
• Only work with trusted vendors
• Limit their access to systems and data
• Ensure key service providers follow basic security practices.
In conclusion, we can see that cybersecurity is essential to protect the personal information of clients and ensure a competitive advantage while at the same time complying with regulations. Businesses need to constantly adapt and stay on top of developments in the cybersecurity sector. By implementing basic, practical controls, most SMEs can move from a reactive position to a far more resilient and proactive security posture, significantly reducing the likelihood and impact of cyber incidents
Leave a Reply