In this video
- The three ways most attacks start: stolen credentials, unpatched systems and malicious email
- Why attackers select targets by ease rather than by size
- Why backups are now the first thing attacked rather than the last line of defence
- The seven protection layers: identity, patching, endpoints, email, network, backups and monitoring
The three doors
Sophos' State of Ransomware research for South Africa found that most attacks begin in one of three ways: stolen or compromised credentials (34%), unpatched vulnerabilities (28%), and malicious email (22%). Note what is absent from that list — exotic zero-day exploits barely feature.
For scale: INTERPOL's Africa Cyberthreat Assessment recorded 17,849 ransomware detections in South Africa in a single year, the highest on the continent and more than Egypt and Nigeria combined.
Backups are the first target
Attackers know a business with working backups will not pay, so the backups are attacked first. Copies sitting on the same network, or in a cloud account reachable with the same admin credentials, get encrypted or deleted alongside everything else. Immutable and off-network is the requirement — verified with actual restore drills rather than green ticks on a dashboard.
Frequently asked questions
Are smaller South African businesses actually targeted?
Attack tooling scans indiscriminately for the same three weaknesses everywhere. Smaller environments are statistically more likely to have all three open at the same time, which makes them easier rather than less interesting.
What is the single highest-value change?
Enforcing MFA across email, VPN, remote access and administrator accounts, and blocking legacy authentication alongside it. That closes the largest of the three entry routes.
Why immutable backups specifically?
Because an immutable copy cannot be altered or deleted, even by an account holding full administrative rights. That is what survives the stage of the attack where the backups are targeted.
Keep reading
Find out which door is open
Book a ransomware-readiness assessment — 30 minutes, no obligation, and you will leave with a prioritised list either way.
Contact Us




