Ransomware Protection Strategies for South African Businesses

4 Minute read
Seyton Hayes
Technical Director | Digital Forensics & Incident Response Specialist
Ransomware Protection Strategies for South African Businesses
In this article

Share this article

For many organisations, the operational cost of ransomware now extends well beyond system recovery — affecting customer trust, regulatory exposure, insurance claims, procurement relationships, and executive accountability.

Ransomware against South African organisations has shifted from broad opportunistic spray to deliberate, targeted extortion — usually exfiltrate-then-encrypt, with leak-site pressure layered on top. The defences that worked five years ago do not address the disclosure problem posed by leak sites. Effective ransomware protection in 2026 combines prevention controls, rapid detection, tested response, and regulatory readiness — operated as a continuous programme rather than a one-off project.

The short answer

Effective ransomware protection for South African companies rests on five disciplines: identity hardening, network segmentation, immutable and tested backups, 24/7 detection and response, and a rehearsed incident playbook that includes POPIA Section 22 notification readiness. Each layer addresses a different part of the modern exfiltrate-then-encrypt attack chain.

Hardened identity — most ransomware starts with a credential

Stolen, sprayed, or reused credentials are the leading initial-access vector for ransomware operators. Strong identity controls are the cheapest, highest-impact prevention investment available: phishing-resistant multi-factor authentication on every privileged and remote-access account, active monitoring for password compromise, regular review of dormant and over-privileged accounts, and elimination of Kerberoastable service accounts. Most environments fail this audit on first inspection.

Segment the network — make lateral movement expensive

Modern ransomware groups move laterally within minutes of initial access. Flat networks let them reach domain admin, backup infrastructure, and production systems quickly. Segmentation between user, server, backup, and OT zones — with deny-by-default rules and monitored east-west traffic — buys defenders the time they need to detect and contain before encryption begins.

Make backups immutable and test restoration

Backups remain the single highest-value control for recovery, but only when they are immutable (cannot be deleted or encrypted by an attacker who reaches them), offline or air-gapped where possible, and regularly restored. A backup that has never been tested at scale is a theory. Practical targets: monthly restoration tests of tier-1 systems, quarterly full disaster-recovery rehearsals.

Detect early — the dwell-time problem

Most ransomware incidents are visible in telemetry before encryption. Indicators include credential anomalies, reconnaissance tooling (BloodHound, ADRecon), command-and-control beaconing, and unusual archive activity. Managed detection and response, mapped to MITRE ATT&CK techniques relevant to ransomware operators (Initial Access, Discovery, Lateral Movement, Exfiltration, Impact), shortens dwell time from weeks to hours.

Rehearse the response — including POPIA notification

A ransomware response is a multi-team exercise: security, IT operations, legal, communications, executive, and, where applicable, the Information Regulator. Section 22 of POPIA requires notification of the Regulator and affected data subjects “as soon as reasonably possible” after a compromise that is likely to result in unauthorised access. Tabletop exercises that include the disclosure conversation surface coordination gaps before a real incident.

Preserve evidence — for insurance, law enforcement, and root cause

Recovery instincts and forensic preservation often conflict in the first hours of an incident. Forensic readiness — defined evidence-handling protocols, chain-of-custody procedures, and the right tooling to image before remediating — protects insurance claims, supports any law-enforcement engagement, and enables root-cause analysis that prevents recurrence.

Common ransomware weaknesses organisations still miss

  • Shared administrator credentials
  • unsegmented backup infrastructure
  • untested recovery procedures
  • unmanaged service accounts
  • lack of incident coordination rehearsals, and incomplete asset visibility

Key Takeaways

  • Most ransomware starts with a credential — identity hardening is the highest-impact prevention investment.
  • Flat networks let attackers reach backups and production fast — segmentation buys detection time.
  • Backups must be immutable, offline where possible, and regularly restored — untested backups are theoretical.
  • Managed detection and response mapped to MITRE ATT&CK shortens dwell time from weeks to hours.
  • POPIA Section 22 notification is part of the response playbook, not an afterthought.
  • Forensic readiness protects insurance claims, law-enforcement engagement, and root-cause analysis.

How Cyber Resilience Can Help

Cyber Resilience helps organisations assess ransomware readiness across identity security, detection capability, backup resilience, forensic readiness, and POPIA-aligned response planning through structured technical and governance-led engagements.

Speak to our team to arrange a ransomware resilience scoping discussion.

Seyton Hayes

Technical Director | Digital Forensics & Incident Response Specialist

Seyton Hayes is a cybersecurity specialist with more than 25 years of experience across enterprise security, incident response, digital forensics, and operational resilience.

Having previously led breach response and digital forensics capabilities within complex banking environments, Seyton specialises in helping organisations investigate incidents, strengthen security operations, and respond effectively to evolving cyber threats.Seyton’s technical leadership and practical experience in defending large-scale enterprise environments make him a trusted advisor to organisations seeking to strengthen operational resilience and respond effectively to evolving cyber threats.

Expertise

Incident Response • Digital Forensics • Threat Intelligence • Security Operations • Ethical Hacking

Frequently asked questions

Should we pay a ransom?

The position of South African law enforcement and most insurers is to avoid payment where operationally possible. Payment funds further attacks, do not guarantee data recovery, and increase the likelihood of future targeting. The right time to make this decision is before an incident — build the position into governance and document it. During an incident, engage legal counsel and law enforcement before any negotiation.

How quickly must we notify the Information Regulator under POPIA?

POPIA Section 22 requires notification “as soon as reasonably possible” after the responsible party has reasonable grounds to believe that a compromise has occurred. There is no fixed 72-hour clock in POPIA itself — but Regulator guidance has signalled an expectation closer to that range. Refer to the Information Regulator’s published guidance for the current expectation.

Are cyber-insurance underwriters now requiring specific controls?

Yes. Underwriters now routinely require phishing-resistant MFA on all privileged and remote-access accounts, immutable backups with regular restoration testing, endpoint detection and response coverage, and documented incident response plans. Renewals frequently include self-attested questionnaires and increasingly external validation.

What is the difference between ransomware and extortion-only attacks?

Ransomware encrypts data and demands payment for decryption. Extortion-only attacks steal data and threaten publication without encryption. The modern dominant pattern is exfiltrate-then-encrypt — both at once. The disclosure problem is the same in extortion-only attacks; the recovery problem is harder when encryption is also in play.

Related Insights

Cyber resilience insights grounded in operational reality.

Practical guidance, operational perspectives, regulatory insights, and forensic-led thinking across cybersecurity, governance, resilience, and digital risk.

Need Clarity on your CURRENT RESILIENCE POSTURE?

Whether you need a focused assessment, operational support, governance maturity, or incident response guid-ance, we will help you understand your current position and build a practical path forward.