South African home loans giant affected by data breach, customer records potentially exposed

Cybersecurity is a Joke in SA,
so many breaches and leaks from companies that really shouldn't let these things happen so easily.
The problem is that it is an entire field by itself being handled as "IT General".

And when the **** hits the fan everyone has their 2 cents on it.

Like I ****ing hate BYOD device policies. That is bull ****.
Or please make me a local admin. NO.
Please unlock my USB... NO.

It is not IT being painful. It is IT preventing incidents cause johnny cnut in marketing did not know brad pitt is not in space.
 
I'm giving training today on supply-chain cyber security - it seems a major gap we're seeing over and over again is a lack of proper management and measurement of suppliers that hold and process critical PII data. Its not a South African problem, its a global problem.
 
The problem is that it is an entire field by itself being handled as "IT General".


It is not IT being painful. It is IT preventing incidents cause johnny cnut in marketing did not know brad pitt is not in space.
this its far easier to compromise jhonny idiot than it is to figure out passcodes or brute force your way in,
problem is many people not in IT are uneducated and dont understand security and permissions levels are set up for security

problem is many of those people are also managers and dont understand the delicate balance between doing your job and more access than is necessary.

I guess this is how these gigantic and massive leaks happen throwing everybody including said managers under the bus from their lack of understanding.
 
this its far easier to compromise jhonny idiot than it is to figure out passcodes or brute force your way in,
problem is many people not in IT are uneducated and dont understand security and permissions levels are set up for security

problem is many of those people are also managers and dont understand the delicate balance between doing your job and more access than is necessary.

I guess this is how these gigantic and massive leaks happen throwing everybody including said managers under the bus from their lack of understanding.
The proverbial "Please protect me from myself" type ****.

Like @neoprema said, he is giving training today. 95% will already zone out after the first few minutes.

But how do you know??? Cause I give the training myself.
1 week later, johnny can't change his password.
Ask him to write out his new password : johnny1985!

Said I will log it with Microsoft. Their system is kak for not accepting his name and the year he was born as password.
Like c'mon. Gave the ticket to my junior to help him reset it further.
 
The proverbial "Please protect me from myself" type ****.

Like @neoprema said, he is giving training today. 95% will already zone out after the first few minutes.

But how do you know??? Cause I give the training myself.
1 week later, johnny can't change his password.
Ask him to write out his new password : johnny1985!

Said I will log it with Microsoft. Their system is kak for not accepting his name and the year he was born as password.
Like c'mon. Gave the ticket to my junior to help him reset it further.
Don't forget... that same password is written on a sticky note and stuck to the monitor. And I've seen people put their actual password into the "hint" too. HAHAHA.
 
Hmm the breach is not on SA Homeloans side but on the 3rd party provider. That like takealot referring to payfast.

Sucks but that's why information regulation companies are supposed to be held to a much higher standard and audit check and why companies hand that function over to them.
 
and audit check
Audits test policy adherence. They do nothing for securing the digital estate.

Auditors are useless, brain-dead, farkwhits who couldn't defend against a determined gerbil.

Audits are busy work that make managers/board members feel warm and fuzzy, billed for at stupendous rates.

<edit>
Should probably add - the only "audit" that means *anything* is indepedent pen testing. Everything else is - as Ridcully would say - playing silly buggers.
 
Last edited:
Audits test policy adherence. They do nothing for securing the digital estate.

Auditors are useless, brain-dead, farkwhits who couldn't defend against a determined gerbil.

Audits are busy work that make managers/board members feel warm and fuzzy, billed for at stupendous rates.
That last line, I haven't heard that one in a few years. Well done for saying it like it is.
 
Audits test policy adherence. They do nothing for securing the digital estate.

Auditors are useless, brain-dead, farkwhits who couldn't defend against a determined gerbil.

Audits are busy work that make managers/board members feel warm and fuzzy, billed for at stupendous rates.

<edit>
Should probably add - the only "audit" that means *anything* is indepedent pen testing. Everything else is - as Ridcully would say - playing silly buggers.
Nah by audit I was referring to external auditing risk not financial, same as PCIDSS compliance.
 
Nah by audit I was referring to external auditing risk not financial, same as PCIDSS compliance.
Auditing and complaince are empty noise.

Threat actors care not one jot for compliance or certification because all of it is irrelevant 2 years before it is even released. Simply does not move fast enough.

Risk assessments suffer from the exact same issues.

Compliant != secure.
Risk awareness/acceptance != secure.

Secure is zero trust, defence in depth, least privelege, conditional access and a slew of other controls, working in concert... and even then you are not "secure"... You are just more hassle than the next available target so we're effectively playing the "I don't need to be faster than the lion, just faster than you" game.
 
The problem is that it is an entire field by itself being handled as "IT General".

And when the **** hits the fan everyone has their 2 cents on it.

Like I ****ing hate BYOD device policies. That is bull ****.
Or please make me a local admin. NO.
Please unlock my USB... NO.

It is not IT being painful. It is IT preventing incidents cause johnny cnut in marketing did not know brad pitt is not in space.

nah i think the problem is too many cybersecurity "Experts" dont have solid IT skills .They go straight into Cyber security without being IT administrators / Systems engineers / network engineers .
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X