CYBER CRIME & CYBER SECURITY
TRENDS IN AFRICA
45
BEST PRACTICE GUIDELINES FOR BUSINESSES
TT Educate
users on safe social media conduct. Offers that
look too good usually are, and hot topics are prime bait for
scams. Not all links lead to real login pages.
TT Encourage
them to adopt two-step authentication on any
website or app that offers it.
TT Ensure
they have different passwords for every email
account, applications and login―especially for work-related
sites and services.
TT Remind
then to use common sense. Having antivirus and
security software doesn’t mean it is ok to visit malicious or
questionable websites.
TT Encourage
employees to raise the alarm if they see anything
suspicious. For example, if Windows users see a warning
indicating that they are “infected” after clicking on a
URL or using a search engine (indicative of fake antivirus
infections), educate users to close or quit the browser using
Alt-F4, CTRL+W or to use the task manager, and then notify
the helpdesk.
Protect Mobile Devices
We recommend that people and employers treat mobile
devices like the small, powerful computers that they are and
protect them accordingly using:
TT Access
TT Data
control, including biometrics where possible.
loss prevention, such as on-device encryption.
TT Automated
TT Remote
device backup.
find and wipe.
TT Regular
updating. For example, the latest version of
Android, codenamed ‘Honeycomb’, includes a number of
features designed specifically to thwart attackers.
TT Common
sense. Don’t jailbreak devices and only use trusted
app markets.
TT Training,
particularly around paying attention to permissions requested by an app.
TT Security
solutions such as Symantec Mobility or Norton
Mobile Security
We have seen the number of mobile vulnerabilities increase
every year over the past three years―although this is perhaps
an indicator of progress rather than a cause for despair. It
is an indication that security researchers, operating system
developers and app writers are, in fact, paying more attention
to mobile security by identifying and fixing more problems.
Although we expect mobile devices to come under growing
attack over the next year, there is also hope that with the right
preventative measures and continuing investment in security,
users can achieve a high level of protection against them.
Building Security into Devices
The diverse nature of ICS and IoT platforms make host-based
intrusion detection systems (IDS) and intrusion prevention
systems (IPS), with customizable rulesets and policies that are
unique to a platform and application, suitable solutions.
However, manufacturers of ICS and IoT devices are largely
responsible for ensuring that security is built into the devices
before shipping.
Building security directly into the software and applications
that run on the ICS and IoT devices should prevent many
attacks that manage to side-step defenses at the upper layers.
Manufacturers should adopt and integrate such principles
into their software development processes.
Business users and consumers need to be assured that
suppliers are fundamentally building security into the IoT
devices that they are buying, rather than it being considered
as a bolt-on option.
It’s a Team Effort
Consumer confidence is built up over multiple interactions
across numerous websites owned by countless different organizations. But it only takes one bad experience of stolen data
or a drive-by download to tarnish the reputation of every
website in the consumer’s mind.
As we said at the start of the report, there is a real opportunity in the coming year to reduce the number of successful
web attacks and limit the risks websites potentially pose to
consumers, but it will take commitment and action from
website owners for it to become a reality.
Adopt Complete Website Security in 2016, and together with
Symantec, make it a good year for cyber security and a very
bad one for cyber criminals.