Connect with us

E-Business

How Cybersecurity Readiness Prevents Small and Medium Businesses (SMBs) from Fuelling Supply Chain Attacks

Published

on

Kindly share this post

By Pankaj Bhula

Supply chain attacks aren’t new. If the past couple of years have taught businesses anything, it’s that the impact of supply chain cyber attacks is now universal, from the fallout of the SolarWinds software breach to the exposed Apache Log4j vulnerability and Kaseya last year.

Unfortunately, when such supply chain attacks hit smaller businesses, who are usually the suppliers to larger enterprises, their impact is especially prohibitive.

For SMBs already feeling the prolonged impact of the pandemic, the added pressure of dealing with sophisticated and frequent cyber attacks in real time are a heavy burden, as they try to protect their business against financial, legal and reputational damage, as well as their own suppliers and larger clients’ security.

It is now more important than ever for SMBs to implement strict security hygiene and effective cybersecurity processes to ensure their business is prepared for the event of cyber attacks happening.

Advertisement

SMBs as an indirect avenue of cyber attacks

The ‘new normal’ opened the door to several new vulnerabilities; cyber attacks globally increased by 50% on average in 2021, compared to 2020.

Our Check Point Threat Intelligence report revealed that an organisation in South Africa experienced a cyberattack 1,675 times per week, compared to 1,117 attacks per organisation globally.

While security breaches are on the rise, the top threats impacting SMBs have remained the same. In Check Point’s Small and Medium Business Security Report from 2020/2021, we revealed phishing, malware, credential theft and ransomware to be the top four threats impacting these businesses. So, what does this mean for them?

The reality is threat actors have taken advantage not only of the now-entrenched remote working model to target organisations, but also the usual limits preventing SMBs from bulking up on their cyber security defences – mainly lack of budget and expertise. SMBs often do not have a dedicated IT or security department.

Advertisement

With no in-house security expertise and reduced focus on security patching, these companies are easier to socially engineer and infiltrate.

Adding to this, SMBs usually have employees doing multiple roles, and thus a wider access to valuable areas of the business and information is given to them, and so if breached, they pose a  threat to multiple areas within the business.

In addition, the business IT infrastructure is often shared for personal use communication as well, such as social media and personal emails, allowing easier access to hackers as the data is often not secured.

Threat actors often target SMBs as low hanging fruit for their vital role in supply chains. This is especially so as such attacks wreak havoc on not only one organisation but entire businesses within the supply networks.

By leveraging tactics such as phishing, cybercriminals gain access to an organisation to launch a malware attack, steal data and credentials or instigate a ransomware.

Advertisement

Take for example, the attack against Target USA where hackers used stolen credentials from an SMB vendor that serviced the HVAC systems in Target stores, to gain access to the retailer’s network and then laterally move to the systems that kept customer payment information. As a result, the global retailer was breached and 40 million credit and debit cards details stolen.

The key factor to preventing cyberattacks is threat prevention. With minimal time and lack of cyber expertise or manpower, SMBs must adopt a prevention mindset to minimise potential cyber attacks and threats.

Why cybersecurity readiness is paramount for SMBs

Beyond the immediate financial impact and reputational blow as a trustworthy, reliable partner, SMBs can also face legal or regulatory repercussions, operational disruption, flow-on costs for system remediation and cyberattack response, customer churn, and the loss of competitive advantage that can make or break a smaller business.

In fact, a tarnished reputation as an avenue of attack can be even more detrimental to an SMB organisation, as the loss of trust with a larger organisation could mean a loss of potential business and revenue down the line with them or other new, potential customers.

Advertisement

With this in mind, budgetary constraints to keep computers and corporate networks protected should never be an excuse, as keeping sensitive data and information protected will bring many advantages and benefits to companies.

This can range from overall cost savings, compliance with data protection laws, gaining the trust of customers and suppliers, to protecting your documents and information to the maximum by preventing any type of data breach.

How SMBs can prevent supply chain attacks

By applying stronger cyber defences, SMBs are in a position to provide larger organisations with assurance that larger companies they supply to will not be compromised via the SMB partner or third-party vendor.

Whilst there are multiple means to prevent such supply chain attacks, the first step is to have good software capable of covering the entire company, protecting the company’s endpoints and devices, and supported by regular backups so that, in the event of a cyber attack, they have the possibility of restoring all the data.

Advertisement

Any device that connects to the network can become a security breach, so it is important to secure all endpoints. It is especially critical for remote or hybrid workforces to avoid security breaches and data compromise.

Also, all employees should be trained in cybersecurity so that they themselves become the first barrier to any attempted attack, such as phishing via email or SMS. Keep in mind that prevention is one of the best protection measures available.

A viable option for SMBs is to also consider engaging an experienced Managed Security Service Provider (MSSP), who will have the skilled resources, updated security software and experienced expertise to monitor for and analyse threats on behalf of the SMB player. This is especially useful for SMBs who have neither the time nor resources to adequately enforce threat detection and response.

Partnering with a cybersecurity expert equipped with best-in-class security and scalable solution such as Check Point Software can put SMBs in good stead to protect against the most sophisticated attacks and generate trust among larger potential players.

Ultimately, SMBs seek a simple plug-and-play solution with best-in-class threat protection, given their lack of financial funding and skills.

Advertisement

With an effective cybersecurity strategy, SMBs are better placed to demonstrate their credibility as secure partners to larger organisations, opening up more business opportunities.

Pankaj Bhula is Regional Director for Africa at Check Point Software

 

Kindly share this post

Dear Reader, Your support matters. But we believe that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. That is why, we have devoted our energy to independent reportage of technology and finance and how they affect lives. Our incisive and analytical view of how technology news affects the daily life help individuals and organizations make up their minds. Quality journalism costs money. Today, we're asking that you support us to do more. Kindly support our effort to deliver technology and finance journalism to everyone in the world. Donate as little as N1,000. Bank transfers can be made to: UBA Plc 1017156876 Communication Week Media Ltd

E-Business

X Replaces Revenue Sharing wit New Creator Rewards Programme

Published

on

Kindly share this post

X has announced plans to discontinue its Revenue Sharing programme and introduce a new Original Content Rewards programme to reward creators for producing original content on the platform.

X Replaces Revenue Sharing wit New Creator Rewards Programme

The social media company announced the changes at the weekend in a post on its X Creators handle, saying the new programme would reward creators who contribute original content.

“Today, we’re introducing the Original Content Rewards Program, a new way to reward creators who bring original ideas, expertise, reporting, creativity, and commentary to X,” the company said.

X said it would stop accepting new enrolments into the Revenue Sharing programme from Friday, while existing participants would continue earning until September 7, 2026.

“Starting today, we’re no longer accepting new enrollments into Revenue Sharing,” it said.

Advertisement

According to the company, existing Revenue Sharing participants will receive three final payouts, with two scheduled for August 14 and August 28, while the final payment for earnings accrued through September 7 is expected around September 11.

X said existing Revenue Sharing participants would begin getting access to apply for the new programme from September 8, subject to meeting its eligibility requirements.

The first payout under the Original Content Rewards programme will be made on August 28, 2026, while existing Revenue Sharing creators who enrol in the new programme from September 8 will receive their first payment on September 25.

Under the new programme, eligible creators will earn from qualified impressions generated by their original content, with payments made every two weeks.

X defined qualified impressions as unique impressions from Premium users on the Home Timeline feed, where at least 50 per cent of a post is visible.

Advertisement

On the other hand, “The following are excluded from qualified impressions: impressions from the same account counted more than once per post; paid, promoted, or artificially generated impressions; and fraudulent impressions,” it said.

To qualify, creators must be at least 18 years old, live in a country where the programme is available, maintain an account in good standing and have either a personal or vusiness account.

They must also subscribe to X Premium, Premium+ or Premium Business, have at least 500 verified followers and record at least 500,000 Home Timeline impressions from verified users within the previous 90 days.

X said creators must also regularly post original content to remain eligible.

“We want to recognize creators who break news, share expertise, tell stories, create entertainment, and contribute meaningful perspectives to the conversation,” the company said.

Advertisement

The platform said original content could include threads, videos, memes, graphics, illustrations, reporting, analysis, commentary and reactions that add meaningful value to existing conversations.

It said creators who use content produced by others would need to add meaningful commentary, context, analysis, humour or creative transformation for such posts to qualify.

“Building on existing conversations is a core part of X, but simply reposting someone else’s content is not enough,” it said.

X said minor edits such as cropping, filters, borders, watermarks, speed adjustments or simple text overlays would generally not qualify as meaningful transformation on their own.

It also warned that content copied or substantially reproduced from another creator, content downloaded and re-uploaded from X or another platform without being the original author’s, automated content, disinformation and misleading content would be ineligible.

Advertisement

The company said accounts that violate the programme’s requirements could be temporarily or permanently removed from it, depending on the severity of the violation.

It added that creators would be responsible for ensuring they had the necessary rights, permissions or licences to use content created by others.

“Original content is content you personally create that reflects your own voice, perspective, expertise, or creativity,” X said.

The company said the new programme was intended to reward creators who make the platform more valuable by bringing original ideas and perspectives to its conversations.

“The Original Content Rewards Program is designed to reward the creators who start them, shape them, and move them forward,” it said.

Advertisement

Kindly share this post
Continue Reading

E-Business

NITDA Introduces Cloud Certification Boost Data Localisation Compliance

Published

on

Kindly share this post

National Information Technology Development Agency (NITDA) has introduced so-called Nigeria’s Certified Cloud Register, regulatory framework developed under the agency’s National Sovereign Cloud Initiative to determine which cloud providers are authorized to handle sensitive data, such as banking records.

NITDA Introduces Cloud Certification Boost Data Localisation Compliance

In effect, from October, NITDA requires banks, fintech companies and other regulated organisations to source cloud infrastructure providers from a national register of certified firms approved to host sensitive financial and government data.

The Certified Cloud Register, is expected to strengthen data sovereignty, improve regulatory oversight and support the implementation of the Central Bank of Nigeria’s (CBN) data localisation policy, which takes effect on January 1, 2027.

Under the framework, banks, fintechs, government institutions and other regulated entities will be able to verify whether cloud service providers, data centre operators, managed service providers and Artificial Intelligence (AI) infrastructure companies have met NITDA’s certification requirements before entrusting them with critical digital workloads.

The initiative is expected to provide regulated institutions with a standardised process for selecting cloud infrastructure providers that satisfy Nigeria’s technical, security and regulatory requirements.

Advertisement

According to NITDA, the framework establishes “a common national standard, an independent assessment process and a public register of approved providers that banks, fintechs and government institutions can rely on when selecting cloud infrastructure partners.”

The register is expected to become a key compliance tool ahead of the CBN’s directive, which requires all payment transaction data generated within Nigeria to be stored and processed locally, effective from January 1, 2027.

The policy applies to deposit money banks, microfinance banks, mobile money operators, payment service providers, switching companies and other financial institutions.

The certification regime is also expected to reshape Nigeria’s cloud computing ecosystem, making regulatory approval a major requirement for cloud providers seeking to handle sensitive data for regulated industries.

Figures cited by NITDA showed that Nigeria’s 10 largest banks spent about N177.91 billion on information technology in the first quarter of 2026, representing a 31 per cent increase over the corresponding period last year.

Advertisement

A sizeable portion of the investment currently supports cloud infrastructure hosted outside Nigeria, a trend the new certification framework is expected to address by encouraging greater utilisation of compliant local infrastructure.

NITDA said the certification programme will apply the same technical and regulatory standards to indigenous cloud providers and international hyperscale operators, creating a level playing field for all companies seeking to provide cloud services to regulated sectors.

The agency also disclosed that more than 85 per cent of Nigerian businesses currently rely on cloud services, with the majority using infrastructure hosted outside the country.

It said the new framework is aimed at improving confidence in Nigeria’s digital infrastructure while promoting local capacity and enhancing oversight of critical national data.

Speaking on the objective of the initiative, Kashifu Inuwa Abdullahi, director-general of NITDA, said the programme is designed to strengthen Nigeria’s position in the global digital economy rather than exclude foreign technology companies.

Advertisement

According to him, the initiative is intended “to redefine the terms under which Nigeria participates in the global digital economy rather than isolate the country from international technology providers.”

The Certified Cloud Register forms part of broader efforts by the Federal Government to deepen digital trust, strengthen cybersecurity and ensure that critical financial and public sector data are managed in line with Nigeria’s evolving data governance and sovereignty objectives.

Kindly share this post
Continue Reading

E-Business

Firm Advocates Healthy IT Habits to Strengthen Cyber Resilience

Published

on

Kindly share this post

At the recent Cyber Security Weekend 2026 conference, Kaspersky shared the findings from its survey titled “Cybersecurity in the workplace: Employee knowledge and behaviour” which was conducted among employees from the Middle East, Turkiye and Africa (META) region.

The study highlights that everyday IT habits, including decluttering computers and reducing digital fatigue, can have a direct and often underestimated impact on an organisation’s cyber resilience.

The Kaspersky survey points to a growing challenge of digital fatigue in the workplace. 13.5% of employees surveyed in the META region confirmed that they made IT-related mistakes due to a lack of cybersecurity knowledge – a figure that shows the critical importance of continuous cybersecurity training and awareness programmes.

Among other reasons behind IT mistakes, respondents cited being in a hurry (30%), oversight (14%), being tired or stressed (12.9%) and having too many notifications (10%). The constant barrage of alerts, messages, and on-screen clutter is becoming an acute problem that can lead to costly IT errors, overlooked social engineering attacks, and even to cyber breaches.

The survey also examined employees’ digital workspace habits. An overwhelming 44.5% of respondents in the META region reported having between 10 and 20 icons on their desktop, while 30% admitted to having even more – with half to a full screen covered in them.

Advertisement

Meanwhile, 33% of respondents also keep more than 10 tabs open in their browser at any given time. Excessive icons and open tabs do more than distract attention and fuel procrastination – they can slow device performance and, in the case of unused applications, quietly collect data.

Interestingly, most employees regularly disinfect their keyboards and phone surfaces (21.5% have adopted this habit since the COVID pandemic). However, digital cleanliness has not kept pace: 55% of respondents remove needless files once a month or more often; the rest perform digital clean-ups far less frequently – once a quarter, or even once a year.

Managing digital noise is key to staying alert: only essential notifications should remain active, especially during periods of deep focus on critical project deliverables. Regular breaks are just as vital for maintaining both well-being and cyber vigilance.

According to the survey, 78% of respondents spend their work breaks eating or drinking, while 58% chat with friends and colleagues. However, stretching and physical exercise is a more effective way to relieve stress and recharge focus – a habit adopted by only 14% of employees.

“It is important to recognise that digital fatigue is a real and growing stress factor: the constant stream of notifications, cluttered screens, and information overload gradually erode focus and make employees far more susceptible to mistakes and social engineering attacks. Simplifying your digital environment is not just a productivity tip, it is a cybersecurity measure”, says Brandon Muller, senior security consultant for the META region at Kaspersky.

Advertisement

Kindly share this post
Continue Reading

Trending