CYBER CRIME & CYBER SECURITY TRENDS IN AFRICA 45 BEST PRACTICE GUIDELINES FOR BUSINESSES TT  Educate users on safe social media conduct. Offers that look too good usually are, and hot topics are prime bait for scams. Not all links lead to real login pages. TT  Encourage them to adopt two-step authentication on any website or app that offers it. TT  Ensure they have different passwords for every email account, applications and login―especially for work-related sites and services. TT  Remind then to use common sense. Having antivirus and security software doesn’t mean it is ok to visit malicious or questionable websites. TT  Encourage employees to raise the alarm if they see anything suspicious. For example, if Windows users see a warning indicating that they are “infected” after clicking on a URL or using a search engine (indicative of fake antivirus infections), educate users to close or quit the browser using Alt-F4, CTRL+W or to use the task manager, and then notify the helpdesk. Protect Mobile Devices We recommend that people and employers treat mobile devices like the small, powerful computers that they are and protect them accordingly using: TT  Access TT  Data control, including biometrics where possible. loss prevention, such as on-device encryption. TT  Automated TT  Remote device backup. find and wipe. TT  Regular updating. For example, the latest version of Android, codenamed ‘Honeycomb’, includes a number of features designed specifically to thwart attackers. TT  Common sense. Don’t jailbreak devices and only use trusted app markets. TT  Training, particularly around paying attention to permissions requested by an app. TT  Security solutions such as Symantec Mobility or Norton Mobile Security We have seen the number of mobile vulnerabilities increase every year over the past three years―although this is perhaps an indicator of progress rather than a cause for despair. It is an indication that security researchers, operating system developers and app writers are, in fact, paying more attention to mobile security by identifying and fixing more problems. Although we expect mobile devices to come under growing attack over the next year, there is also hope that with the right preventative measures and continuing investment in security, users can achieve a high level of protection against them. Building Security into Devices The diverse nature of ICS and IoT platforms make host-based intrusion detection systems (IDS) and intrusion prevention systems (IPS), with customizable rulesets and policies that are unique to a platform and application, suitable solutions. However, manufacturers of ICS and IoT devices are largely responsible for ensuring that security is built into the devices before shipping. Building security directly into the software and applications that run on the ICS and IoT devices should prevent many attacks that manage to side-step defenses at the upper layers. Manufacturers should adopt and integrate such principles into their software development processes. Business users and consumers need to be assured that suppliers are fundamentally building security into the IoT devices that they are buying, rather than it being considered as a bolt-on option. It’s a Team Effort Consumer confidence is built up over multiple interactions across numerous websites owned by countless different organizations. But it only takes one bad experience of stolen data or a drive-by download to tarnish the reputation of every website in the consumer’s mind. As we said at the start of the report, there is a real opportunity in the coming year to reduce the number of successful web attacks and limit the risks websites potentially pose to consumers, but it will take commitment and action from website owners for it to become a reality. Adopt Complete Website Security in 2016, and together with Symantec, make it a good year for cyber security and a very bad one for cyber criminals. 

Select target paragraph3