EDITOR'S NOTE

Last issue we looked at how R71 million left the Compensation Fund through a single uncontrolled process - a banking detail change with no oversight and no audit trail. The common thread running through that story, and through the wave of South African breaches reported this month, is the same: someone had access they should not have had, and nobody noticed.

This issue is about a question every South African business should be able to answer, and most cannot. Who, right now, has access to your systems?

WHO HAS ACCESS TO YOUR SYSTEMS RIGHT NOW?

The Numbers Are Uncomfortable

A new report from Zoho found that 79% of South African organisations lack complete visibility into user identities and access permissions. Separately, Accenture research found that 54% of data breaches in South Africa involved compromised user identities. And 36% of South African organisations experienced a cyberattack in the past year - the highest rate recorded globally.

These three statistics point to the same underlying problem. The most common entry point for a breach in South Africa is not a sophisticated technical exploit. It is an identity - an account, a credential, a login - that should not exist or should not have the access it does. Strengthening perimeter defences while leaving user access ungoverned is, as one security researcher put it, building stronger walls while leaving the front door unlocked.

The Four Access Gaps Most Businesses Have

The access problem in most South African SMEs is not one thing. It is four things, usually all present at the same time.

The first is former employees. When someone leaves a business, their accounts should be disabled immediately - email, cloud tools, accounting software, shared drives, every platform they touched. In practice, this rarely happens systematically. An IT provider gets the laptop back but nobody thinks to check the Google Workspace account, the Xero login, the Dropbox folder, or the project management tool. Former employees with active credentials are one of the most consistent sources of insider incidents, whether intentional or accidental. Disgruntled departures make this significantly worse.

The second is third-party access. Fifty-eight percent of South African organisations identified unmanaged third-party access as a major risk. IT providers, consultants, software vendors, and contractors are routinely given access to systems during a project or engagement - and that access is almost never formally reviewed or revoked when the relationship ends. Your previous IT provider may still have remote access to your server. A software vendor whose contract lapsed eighteen months ago may still have login credentials to your client database. Nobody has checked.

The third is excessive permissions. Access tends to accumulate over time. An employee starts in one role, moves to another, and picks up permissions along the way without the old ones being removed. Junior staff end up with access to financial records because they needed it once for a specific task. A manager has administrative rights on systems they have not used in two years. The principle of least privilege - giving people only the access they need to do their current job - is almost universally understood and almost universally ignored in practice.

The fourth is forgotten integrations. Most businesses use a growing number of cloud tools, and those tools are connected to each other through integrations, API keys, and service accounts. When a tool is retired or replaced, the integrations that gave it access to other systems are rarely cleaned up. The Pick n Pay breach confirmed this month involved customer data from a retired delivery app - a system nobody was monitoring because it was no longer in active use. Retired systems are not inherently safe. They are just unmonitored.

What POPIA Requires

Access control is not optional under POPIA. Section 19 requires organisations to take appropriate technical and organisational measures to prevent unauthorised access to personal information. The Information Regulator's enforcement focus is maturing, and access governance is explicitly within scope. If your organisation suffers a breach and cannot demonstrate that user access was actively managed and regularly reviewed, the ability to show reasonable measures were in place is significantly weakened.

The practical requirement is not complex. It is an Access Review - a regular, documented process of checking who has access to what, whether that access is still appropriate, and removing anything that is not. Done quarterly, this process takes a few hours. Done never, the accumulation of stale credentials, former employees, and forgotten integrations becomes a liability that grows silently until something goes wrong.

Five Questions to Ask This Week

Run through these questions with whoever manages your systems:

Can you pull a list of every active user account across all your business tools right now - not just your main system, but every cloud platform, shared drive, and communication tool? If that list does not exist or would take days to compile, that is the gap.

When did you last review that list against your current employee and contractor roster? If the answer is never, there are almost certainly accounts in your environment that belong to people no longer associated with your business.

Do any former employees, ex-IT providers, or past contractors still have active credentials? Most businesses that check this for the first time find at least one.

Does every user have only the access they need for their current role? Or has access accumulated over time without review?

Are there any retired or unused systems that still have active integrations or API connections to your live environment?

If any of these questions produce uncertain answers, the access audit is overdue.

The Bottom Line

Identity is now the primary security perimeter in South African business. The most common path into an organisation is not through a firewall - it is through a credential that should not exist. Former employees, unmanaged third parties, excessive permissions, and forgotten integrations are not exotic attack vectors. They are routine gaps that accumulate quietly in every organisation that does not actively manage them. The fix is not technology. It is a process - regular, documented, and enforced. The question is not whether your organisation has these gaps. It is whether you know where they are before someone else finds them first.

Aigeus Cyber Briefing