Tony Anscombe | Chief Security Evangelist | ESET Southern Africa | mail me |
South African businesses have evolved alongside the reality of the country’s physical infrastructure challenges. Organisations instinctively build redundancies for power. These include solar installations, battery backup solutions, UPS systems and generators. When the grid fails, the failover system kicks in.
Similarly, most businesses have multiple connectivity failovers because they understand operational disruption intimately. Yet, when it comes to digital infrastructure, many businesses treat security as a separate, IT-delegated silo. They do not treat it as a core pillar of operational performance and, in the worst-case scenario, survival. This is a mistake.
Unmitigated financial risks
The era of viewing cybersecurity merely as a defensive IT function is over. Cyber risk is fundamentally a business risk. Therefore, true resilience demands a commercial rather than a purely technical approach. In fact, organisations need to see cybersecurity as an exercise, not an IT problem.
What does this mean? Security is often viewed as a grudge purchase. Imagine a boardroom where a Chief Information Security Officer requests a budget of R10 million based on detailed threat modelling. The board reviews the request and approves only R6 million. That R4 million difference is not a saving for the business. Instead, it is an unmitigated financial risk that the business chooses to absorb.
This is an important insight because the C-suite needs to translate technical vulnerabilities into bottom-line exposure. To do that effectively, leaders must view cybersecurity as an exercise, not an IT problem.
Defining acceptable risk
Cybersecurity is not binary. In other words, organisations are not simply “safe” or “breached”. Cybersecurity revolves around an organisation’s specific appetite for risk. By way of analogy, imagine two people walking into a Las Vegas casino with $200. They make their way to the roulette tables.
The first person puts the entire $200 on a single, high-risk number. That person has a high tolerance for risk. The second person spreads the bet across multiple, defensive layers.
Businesses, especially enterprise-level financial services institutions, carry the burden of complex legacy systems that still work. Because of this, they cannot eliminate risk entirely. Therefore, they need to define what acceptable risk looks like. They must then strategically map out which of their systems are uniquely vulnerable. Furthermore, risk is not just about hackers. It is also about accessibility.
For example, a bank or insurer’s risk profile becomes more complicated when it seeks to broaden its client base and strengthen social and financial inclusion. If a bank tightens security by forcing app-only biometrics in all customer interactions, it risks alienating its least tech-savvy customers. In many cases, this forces organisations to rely on legacy SMS technology. However, SMS comes with vulnerabilities and creates a permanent risk window that the board must acknowledge.
The hidden cost of friction
The whole point of cybersecurity is to keep digital infrastructure safe. Yet, as we all know, hyper-aggressive security can also damage the bottom line if it disrupts operations. Therefore, organisations need to work with platforms and partners that reduce false positives.
False positives occur when security software blocks legitimate business activities. In high-volume environments, such as trading floors or busy periods, a system disruption of only a few minutes creates a meaningful and quantifiable financial cost.
With this understanding, organisations have the blueprint for good security. Effective security works almost invisibly and applies a light touch. By contrast, disruptive security eats into profits every day. Good security, however, boosts commercial ROI through quality threat intelligence.
Good, or quality, security is not only about building an impenetrable wall. It is also about telemetry and context. High-quality security platforms understand user behaviour.
For example, if a system detects a login from Cape Town and then another from New York almost immediately, it recognises that no one can travel halfway around the world in three minutes. Consequently, it flags the anomaly. This intelligence-driven approach represents a light touch because it interrupts the user only when context and behaviour are genuinely suspicious. This reinforces the idea of cybersecurity as an exercise in risk tolerance, not an IT problem.
Are you asking the right questions?
When organisations reframe cyber risk as business risk, the next step is to understand that risk extends beyond their own walls.
Many people reading this will remember when Heathrow Airport suffered a major power outage. A major global hub went offline for a day. However, a direct attack on its core systems did not cause the outage. Instead, a utility provider ignored an earlier alert about moisture in a nearby power substation.
C-suites would do well to challenge their organisations to ask the right questions. Are they simply checking whether their primary systems are safe? Or are they interrogating the “substations” connected to their operations, such as legacy applications, third-party vendors, and integrated supply chains?
In conclusion
The sobering truth is that risk is not merely the absence of a firewall. It is also technical debt. Financial organisations currently run systems that cannot be patched. Consequently, the cybersecurity discussion shifts away from patches. Instead, organisations must ask how they can best segment and protect a vulnerable old heart with a modern shield. This is a strategic architectural decision rather than a simple software installation.
Cybersecurity should be a continuous, boardroom-led exercise in commercial resilience. It requires organisations to work with partners who understand that there is no finish line in cybersecurity. You cannot arrive at complete security.
All organisations can do, and should do, is strategically and tactically plan their race according to the level of risk they are willing to accept. Ultimately, this requires leaders to embrace cybersecurity as an exercise in risk tolerance, not an IT problem.
