At the 2025 Microsoft Digital Defence Report press briefing on 3 November, Kerissa Varma, chief security advisor at Microsoft Africa, outlined the key cyber threats facing South African organisations and the urgent need to shift from reactive to proactive security strategies.
Kerissa Varma, Microsoft Africa’s chief security advisor, began by warning of an increasingly fragile digital ecosystem. “Our ecosystem that we operate in is increasingly fragile and we need to do more to protect it,” she said. She noted that while threat actors remain motivated by financial gain, data has become the new prize, with adversaries targeting sensitive information across multiple sectors.
One of the top emerging attack methods is click fix, a simple but effective form of social engineering. “It’s exactly what the name suggests,” she explained. “A threat actor will ask you to click on something, and then it will either execute code or ask you to put a command into the command line. It preys on the need of users to want to fix something quickly.”
While phishing continues to dominate, Kerissa pointed out that old vulnerabilities remain a reliable path for attackers. “Athough vulnerabilities are a small percentage of the overall threat activity, they are still the most reliable way to get into an organisation. It doesn’t require a user to click on anything,” she added.
Although business email compromise (BEC) represented only two percent of global threat activity, it accounted for 21 percent of all successful attacks. Kerissa noted that South Africa has become a launchpad for BEC groups, including the Nigerian-operated Storm 2126, which conducts attacks globally from local bases.
Kerissa emphasised that simple security measures can prevent most identity attacks. “If you have modern multi-factor authentication, it can prevent 99 percent of attacks that we’re seeing against identities,” she said. Despite this, she warned that credential-based theft is still the biggest mechanism for attackers to get into organisations.
Access brokers, who sell network entry to other threat actors, continue to expand cybercriminal capabilities, with the public sector and industrial organisations most affected due to legacy systems and weak controls.
The report found that attackers are operating faster and with greater precision. “The average length of threat activity has been 58 days over the last year. They’re getting in, staying in for shorter periods of time and getting out,” she explained.
However, she cautioned that government systems often remain infiltrated for years due to espionage motivations. “They try to stay there for as long as possible because they want to have continued access regardless of what happens geopolitically.”
The AI threat and opportunity
Kerissa warned that AI is transforming the cyber threat landscape. AI-generated phishing emails have a 54 percent success rate, compared to 12 percent for traditional attempts. Attackers are using AI to analyse stolen data and craft highly targeted messages, making social engineering significantly more effective.
She also revealed how some organisations are unknowingly hiring their attackers. “Some organisations are hiring their own threat actors. Once they’re inside the organisation, all those defences on the perimeter don’t matter anymore,” she explained.
Her advice was simple: “Make sure you have a camera-on interview. If something sounds strange, pick up the phone and phone a South African number. It’s harder to fake that.”
Cybersecurity, she said, must now be viewed as a business imperative rather than a technical concern. Reactive responses following major incidents are insufficient. Proactive investment in prevention and resilience is essential to business continuity and investor confidence.
Microsoft’s approach focuses on embedding AI into every element of its security stack to enable defenders to counter AI-driven attacks. The company is also expanding its digital crimes unit to identify and disrupt individual threat actors, moving beyond infrastructure takedowns.
Recommendations for IT leaders
Africa remains a key target region, with 21 percent of tracked nation-state cyber activities taking place in South Africa. Microsoft’s collaboration with law enforcement has led to the identification of key developers and tools used in major global attacks, with this intelligence shared to support ecosystem-wide disruption.
The 2025 report provides several recommendations for leaders. These include investing in resilience by design, fostering public-private collaboration, supporting innovation and workforce development, incentivising resilience through policy and regulation and measuring and monitoring resilience.
“We have to manage cyber risk at the boardroom,” Kerissa emphasised. “Boards are good at managing operational and financial risk, but maybe not as great at managing technology risk.”
She also cautioned that organisations must prepare for the impact of quantum computing. “As quantum computers become better, faster, stronger, the traditional encryption mechanisms we’ve all used are going to become easier to break. We have to be crypto agile,” she said.
Kerissa concluded by reinforcing the call for proactive and AI-enabled defence. “If we don’t use AI, we’re fighting a losing battle. We have to get to a point where we’re using AI against AI attacks. Cybersecurity is not a technical issue anymore. It is a business imperative.”
















