There have been at least 21 notable cyberattacks against South African organisations since the start of 2025

mylesillidge

Journalist
Joined
Jul 29, 2021
Messages
4,157
Reaction score
4,432
On the one side it's mind blowing interesting how and why SA companies and organizations are so easily targeted....
 
On the one side it's mind blowing interesting how and why SA companies and organizations are so easily targeted....
Cause as many consumers some companies dont believe the need to put some money down on security.

Fun and games until it hits you. and even if you get some good security there is always a way to get attacked.

its never full proof sadly. There is only so much you can do especially if your business is public. if its closed its a lot easier to lock it down. But there is also people that opens links in emails and let things in cause you know untrained staff etc lack of policies.
 
gov.za was pwned entirely around 10 years ago and continues to be a prolific source of campaign mails, password spray attacks, etc.

SITA, et al, have never actually dealt with it. The threat actors remain resident and active in their estate.

Cloudflare loves to brag about how they're the primary vendor "defending" gov.za. Then they get upset when I laugh. They've built an internet inside the internet and imagine that's fixed everything. It's a laughable position to take.

To make matters worse, auditors don't look at *actual* defense posture. They focus instead on policy and standards, which is utterly divorced from reality. Policy and standards are lagging reality by 10+ years.

This is why I laugh when a vendor claims ISO or similar certification. They do so in the earnest belief it means something. It does not.

Harsh realities: -
================

Paranoia is only paranoia if they aren't out to get you. They are.

They're better funded. They're multi-national and they're focused on one thing and one thing only, all the time. Our SOC/engineering teams are split-focused, over-worked, out-gunned and out-funded.

Defenders are always one step behind. Always. We do not dictate the rules of engagement.

Defense in depth is a must have. As much depth as you can get away with. It will make you no friends.

Zero trust is a must have. Everywhere. In every instance. Always. It will make you no friends.

A major problem being that security sucks and makes life just a little harder. For many this is unnacceptable so they choose being hacked over a little discomfort. Until it costs real world money which is when they decide that *maybe* a little investment and buy-in is worth it.
 
gov.za was pwned entirely around 10 years ago and continues to be a prolific source of campaign mails, password spray attacks, etc.

SITA, et al, have never actually dealt with it. The threat actors remain resident and active in their estate.

Cloudflare loves to brag about how they're the primary vendor "defending" gov.za. Then they get upset when I laugh. They've built an internet inside the internet and imagine that's fixed everything. It's a laughable position to take.

To make matters worse, auditors don't look at *actual* defense posture. They focus instead on policy and standards, which is utterly divorced from reality. Policy and standards are lagging reality by 10+ years.

This is why I laugh when a vendor claims ISO or similar certification. They do so in the earnest belief it means something. It does not.

Harsh realities: -
================

Paranoia is only paranoia if they aren't out to get you. They are.

They're better funded. They're multi-national and they're focused on one thing and one thing only, all the time. Our SOC/engineering teams are split-focused, over-worked, out-gunned and out-funded.

Defenders are always one step behind. Always. We do not dictate the rules of engagement.

Defense in depth is a must have. As much depth as you can get away with. It will make you no friends.

Zero trust is a must have. Everywhere. In every instance. Always. It will make you no friends.

A major problem being that security sucks and makes life just a little harder. For many this is unnacceptable so they choose being hacked over a little discomfort. Until it costs real world money which is when they decide that *maybe* a little investment and buy-in is worth it.
cloudflare just a filter to be honest had it up and running once and caused more issues than anything it actually allowed 2million hits from china on my end within an hour but marked none of those IPs as bad bots.
 
Top
Sign up to the MyBroadband newsletter
X