In a globalised world, where economies are increasingly interconnected and technology is advancing at an unprecedented rate, cybercrime is big business. In recent years, the range and complexity of attacks have grown exponentially, as criminals exploit new methods of infiltration to gain access to confidential data and sensitive information, writes Ashley Singh, CIO at Sanlam Corporate.
Across the globe, cybercrime is costing businesses hundreds of millions of dollars in the form of financial losses, legal liabilities, reputational damages, and regulatory fines. In Africa the cost of cybercrime has grown in volume, impact, and complexity, with Nigeria, Kenya, and South Africa recording the largest losses.
As we close the digital divide and more Africans adopt technology, malicious actors find increased opportunities to exploit vulnerabilities. The SA Banking Risk Information Centre (SABRIC) estimates South Africa loses around R2,2 billion annually to cyberattacks, affecting credit bureaus, healthcare, retail groups, government departments, and financial institutions, such as banks and insurers.
According to cybersecurity specialists Orange Cyberdefense, the finance and insurance industries accounted for slightly more than 22 percent of all cybercrime victims in Africa over the past two years, with a 60 percent increase in reported incidents within this sector.
A primary reason for the increase was the shift towards home and remote working initiated during the Covid-19 pandemic, which has continued in many organisations. The proliferation of the Internet of Things (IoT) across all sectors of business and society has further amplified opportunities for security vulnerabilities, leading to increased costs and challenges.
One such example is the threat of business email compromise (BEC), which according to Interpol’s 2023 African Cyber Threat Assessment, has intensified notably in the region. Despite African countries accounting for only 0.75 percent of global BEC attempts from 2021 to May 2022, data indicates South Africa reported more than half of the BEC cases during the same period.
Additionally, organisational attack surfaces have expanded significantly in recent years due to the accelerated adoption of Software as a Service (SaaS), expanded digital supply chains, increased corporate engagement on social media, custom application development, and internet-based customer interactions.
Cyber risk in the insurance sector
Cybercrime today is very different from what it used to be, with perpetrators ranging from powerful intelligence agencies to teenage hackers. They profit from employing sophisticated attack vectors such as distributed denial-of-service (DDoS) attacks, phishing attempts, malware campaigns, ransomware attacks and other malicious activities. These actions can inflict substantial harm and have a profound impact on organisations and communities alike.
The insurance industry, like any other sector, faces significant cyberthreats. Its nature as a repository of vast amounts of sensitive customer data – including personal information, financial records, and medical histories – makes it a prime target for cybercriminals. These attackers seek financial gain, competitive advantage, or disruption of operations by exploiting this treasure trove of valuable data.
A benchmark exercise commissioned by Sanlam involving 184 employer and umbrella funds revealed alarming statistics: 70 percent expressed cybersecurity concerns, yet only 40 percent took measures to assess their service providers for cyber-risks. These findings raise crucial questions about the security measures that are in place to protect client data.
In light of these findings, cybersecurity is top of everyone’s agenda. We face common cyber-risks such as phishing and social engineering, ransomware attacks, and insider threats, where employees, whether intentionally or unintentionally, can present significant cybersecurity risks. Additionally, third-party risks are an ongoing concern, particularly as insurance companies frequently partner with various vendors, introducing additional cybersecurity risks. Weak security measures among these vendors can serve as potential entry points for cyber-attackers.
The main consequences suffered by insurers following cyber-incidents include business interruption and material costs for the business, policyholders, and third parties. Besides the direct financial consequences, cyber-incidents can also result in severe and long-lasting operational issues for the targeted insurance groups. The reputational damage may also be substantial or even irreversible.
Compliance with the Joint Standard
Over the last two years, some African countries have engaged in the process of adopting new cybercrime-related legislation. This marks a proactive stride towards strengthening legal frameworks to combat cybercrime on the continent.
The Joint Standard 2 of 2024 for IT Governance and Risk Management, issued by the Financial Sector Conduct Authority and the Prudential Authority indicates that the South African financial sector is keeping pace with the global resilience movement..
It has significant implications for the insurance industry and emphasises sound, proactive measures and cyber-resilience, and aligns insurers with societal needs and technological advancements. Reacting to risks may not be sufficient and insurers need to undertake the required transformation efforts to prevent losses from occurring in the first place.
















