What should a cybersecurity risk assessment include?

A cybersecurity risk assessment helps an organisation answer three important questions: What are we protecting? What could go wrong? What should we fix first? Without these answers, cybersecurity spending can easily become product-driven rather than risk-driven. A good cybersecurity risk assessment provides management with a structured view of the organisation’s technology, threats, vulnerabilities and potential […]

Read More

How can businesses prevent SSL certificate expiry across multiple domains?

An expired SSL/TLS certificate can cause websites, APIs and applications to become inaccessible or display security warnings. SSL certificate expiry is an important issue every site owner should monitor to ensure uninterrupted and secure access. Managing one certificate manually may be straightforward. However, managing dozens or hundreds across multiple domains, servers, applications and business units […]

Read More

Penetration testing vs vulnerability assessment: what is the difference?

Many businesses use the terms penetration testing and vulnerability assessment interchangeably. Understanding the differences between penetration testing vs vulnerability assessment is key to choosing the right cybersecurity approach. While both are important cybersecurity activities, they serve different purposes. A vulnerability assessment helps identify potential weaknesses. A penetration test goes further by determining whether those weaknesses […]

Read More

SOC as a Service vs an in-house SOC: which is right for your business?

Cybersecurity monitoring has become increasingly important as organisations operate across endpoints, cloud platforms, networks, email and remote-working environments. Many businesses are now considering the differences between SOC as a Service vs in-house SOC to determine the best approach for their security needs. That raises an important question: Should you build your own Security Operations Centre […]

Read More

How often should a business perform penetration testing?

A common cybersecurity question is whether penetration testing should happen monthly, quarterly or annually. For many organisations, annual pen testing is a useful baseline – but it should not automatically be the only time testing occurs. The appropriate frequency depends on how quickly your technology environment changes and the level of cybersecurity risk your organisation […]

Read More
vulnerability scanning

8 Vulnerability Scanning Questions CISOs Should Ask

Vulnerability scanning is one of the few security controls that organisations can measure, repeat, and link directly to remediation. For CISOs, the real question is not whether to scan, but whether the vulnerability detection and scanning programme is frequent enough, deep enough and operationally useful. Prima Secure, a South African cybersecurity provider, is relevant here […]

Read More