A concerning number of South African companies are not prepared for the inevitability of a cyberattack despite the significant financial and reputational risks. Too few senior managers view cybersecurity as a business problem and not just a technology problem. The reality is cybersecurity is very much a business consideration.
CEOs and CFOs will eventually face critical questions such as: How much money do we spend on cybersecurity?
Do we change key processes?
How do we create awareness and change company culture?
Do we put security ahead of operational functionality?
What is the role of internal processes and staff on data security and integrity?
Cybersecurity is a business-wide risk
Cybersecurity is a business-wide risk it requires more than isolated activities to be addressed. This is where the role of a Chief Information Security Officer (CISO) is important.
The CISO therefore needs to have technical and security skills and competencies, but equally as important, should understand the finance function, operations of the business, and have the business as well as communication skills to effectively create this span.
"A concerning number of South African companies are not prepared for the inevitability of a cyberattack despite the significant financial and reputational risks." - Ryan Mer, Managing Director, eftsure Africa (Tweet this | Share this via WhatsApp)
While large corporations are more likely to have the resources to fill the CISO role, businesses below the corporate level may not. In such instances, an outsourced or CISO-as-a-service offering could add immense value.
Ultimately, and especially in relation to the Protection of Personal Information (POPI) Act, there needs to be a coherent strategy and allocated responsibility in place with respect to cybersecurity, data management, compliance and fraud prevention.
Cybersecurity in smaller organizations
The absence of commonplace and well-developed CISO roles, it is the CFO who should lead the way in addressing cybersecurity concerns, particularly in smaller organizations. It is potentially disastrous for the finance team to be ignorant of cyber risk.
Attackers can target many areas of an organization, but the dangers are usually measured in financial terms: CFOs cannot ignore cybersecurity simply because it is a complex issue outside their area of expertise.
In addition to having the skills and oversight necessary to take a broad and long-term view of the potential financial impact of an attack. The CFO is one of the most natural custodians of data, from collection to its ongoing management.
Attacks will very often target the finance department and its team members directly, and in many instances may even be perpetrated by or assisted by internal team members, in attempts to steal and defraud the business. CFOs need to ensure their own vulnerabilities are both understood, and urgently addressed.
Subscribe to our Daily Brief newsletterShare this via:
Insights and analysis into how business and technology impact Africa. We promise to leave you smarter and asking the right questions every time after you read it. Sent out every Monday to Friday.