Ransomware Protection for South African Businesses

A short summary of how ransomware attacks on South African businesses actually begin, and the seven layers that stop them.

In this video

  • The three ways most attacks start: stolen credentials, unpatched systems and malicious email
  • Why attackers select targets by ease rather than by size
  • Why backups are now the first thing attacked rather than the last line of defence
  • The seven protection layers: identity, patching, endpoints, email, network, backups and monitoring

The three doors

Sophos' State of Ransomware research for South Africa found that most attacks begin in one of three ways: stolen or compromised credentials (34%), unpatched vulnerabilities (28%), and malicious email (22%). Note what is absent from that list — exotic zero-day exploits barely feature.

For scale: INTERPOL's Africa Cyberthreat Assessment recorded 17,849 ransomware detections in South Africa in a single year, the highest on the continent and more than Egypt and Nigeria combined.

Backups are the first target

Attackers know a business with working backups will not pay, so the backups are attacked first. Copies sitting on the same network, or in a cloud account reachable with the same admin credentials, get encrypted or deleted alongside everything else. Immutable and off-network is the requirement — verified with actual restore drills rather than green ticks on a dashboard.

Frequently asked questions

Are smaller South African businesses actually targeted?

Attack tooling scans indiscriminately for the same three weaknesses everywhere. Smaller environments are statistically more likely to have all three open at the same time, which makes them easier rather than less interesting.

What is the single highest-value change?

Enforcing MFA across email, VPN, remote access and administrator accounts, and blocking legacy authentication alongside it. That closes the largest of the three entry routes.

Why immutable backups specifically?

Because an immutable copy cannot be altered or deleted, even by an account holding full administrative rights. That is what survives the stage of the attack where the backups are targeted.

Find out which door is open

Book a ransomware-readiness assessment — 30 minutes, no obligation, and you will leave with a prioritised list either way.

Contact Us

More videos