Author Archives: web2@iww.co.za

Your Penetration Test Passed. You’re Still Vulnerable. Here’s Why.

Passing a penetration test does not mean you are secure. It means you were secure enough, on that day, against that scope, tested by those methods. That distinction matters more than most security reports will tell you. Penetration testing remains one of the most valuable tools in a cybersecurity programme. But in South Africa, where […]

The Pick n Pay Breach: Old Data, Real Risk

South Africa’s largest supermarket retailer is the latest major brand to face the uncomfortable reality that old data does not simply go away. Pick n Pay this week confirmed a data breach involving customer records from its former on-demand delivery platform, originally known as Bottles and later rebranded as Pick n Pay asap!. The affected […]

Raising the Bar: SS-Consulting Announces Strategic Partnership with OffSec

SS-Consulting has always held a firm belief: that true cybersecurity competence is not built in a classroom or earned through a multiple-choice exam. It is forged through practice, pressure and the willingness to think the way an attacker thinks. It is with great pride that SS-Consulting announces its strategic partnership with OffSec, the global leader […]

Your Password Is Not the Problem Anymore

For years, the cybersecurity conversation has centred on passwords. Use a strong one. Don’t reuse it. Add multi-factor authentication. It became the standard advice, repeated in boardrooms and IT policies across the world. It is still good advice. But attackers have largely moved past it. A shift has been quietly accelerating; rather than stealing your […]

When Hackers Get Hacked: What the PCPJack Campaign Tells Us About the Threat Landscape

There is a certain dark irony in watching cybercriminals become the victims. But the story of PCPJack is less a morality tale and more a warning about how chaotic and layered the modern threat environment has become. Here is what happened. An unknown group of attackers identified systems already compromised by TeamPCP, a prolific cybercrime […]

When the AI Giants Play Gatekeeper, African Defenders Get Left Outside

There is something almost theatrical about Sam Altman publicly mocking Anthropic for restricting access to its cybersecurity tool Mythos, only to turn around days later and announce that OpenAI’s competing tool, Cyber, would be rolled out in exactly the same way. The irony would be funny if the stakes were not so high. But beyond […]

South Africa’s Breach Season Is Not a Coincidence. It Is a Warning.

April 2026 has been a defining month for cybersecurity in South Africa. Within a two-week window, the country witnessed a sequence of high-profile incidents that, taken together, reveal something far more significant than a series of isolated attacks. They reveal a systemic vulnerability that runs through both the public and private sector. Standard Bank, Africa’s […]

Liberty’s Breach Is a Warning. The Real Risk Comes After the Headline.

Liberty’s recent disclosure of a data breach did what most incidents do in the first 24 hours: it triggered concern, prompted customer notifications, and raised the familiar questions about what data was accessed and whether systems remain secure. Liberty told clients that unauthorised access to personal information had been detected, while policies, investments and services […]

The Real Cost of a Cyber Attack: Why Speed of Response Matters More Than Ever

For many organisations, a cyber-attack is viewed as a technical problem, something for IT to manage. The reality is far more serious. A cyber incident can quickly become a financial, operational and reputational crisis. Research suggests JSE-listed companies could lose as much as 30% of their share value following a major breach. And the threat […]

When War Moves to the Network: The Rising Role of Cyber Operations in Modern Conflict

For decades, warfare has been defined by physical force. Jets, tanks, and missiles determined the outcome of conflicts. That battlefield has fundamentally changed. Wars are no longer fought only in the skies and on the ground. They are increasingly fought across networks, data systems, and digital infrastructure, often before a single shot is fired. Reports […]