Direct Transact’s (DT) head of cybersecurity, Dirk Labuschagne, unpacks the vulnerabilities facing South Africa's financial sector and shares practical strategies for organisational resilience.
With ransomware attacks spiking by 11 percent globally from 2023 to 2024, according to Check Point's Annual Ransomware Report 2024, the financial services industry remains in the crosshairs of cybercriminals. The report, along with Check Point’s State of Cyber Security 2025 Report, highlights concerning trends with financial services ranking among the top ten most targeted sectors by cybercrime gangs worldwide.
Alongside his role at DT, Dirk Labuschagne also serves on the SA Reserve Bank task force to prevent and mitigate financial blackout, giving him a unique perspective on threats to the country’s payment systems.
For Dirk, who has spent over two decades in financial cybersecurity, the most significant vulnerability is “how employees behave in the digital environment”. He explains that: “Banks and non-banks have been through dramatic digital transformations over the past few years, and employees’ knowledge and vigilance have not kept up with the pace and sophistication of the criminal networks.”
This human element often creates pathways for ransomware attacks, which have grown increasingly sophisticated.
When looking at why ransomware attacks have increased by 11 percent globally, Dirk points to two major concerns identified in the Check Point reports: The proliferation and fragmentation of criminal gangs, and the risks posed by popular digital platforms such as social media, AI and messaging services, where unsuspecting victims are prompted to click on various links that may not always be safe.
“The criminal enterprises are professionalising and corporatising, and are very well-organised, so you can never let your guard down,” Dirk notes. “In the old days, you could follow the money, but today that is harder, because of how easy it is for criminals to transfer money across borders with cryptocurrencies.”
Rehearsing for the inevitable
When asked about practical defensive strategies, Dirk strongly advocates for “tabletop ransomware exercises” – structured simulations that allow organisations to rehearse their response to attacks. These exercises help organisations test and refine incident response plans, identify shortcomings and develop more coordinated responses between departments.
“Simulations could begin with phishing emails that lead to a network breach, or direct attacks on the organisation’s customer data or operational systems,” he shares.
They should not be limited to IT teams, however. “It’s important not to relegate cybersecurity exercises to the IT team – attacks affect every department,” Dirk emphasises. He explains that, during an actual attack, different departments play vital roles:
- IT must handle the technical aspects of containment and recovery
- Legal needs to ensure compliance with notification laws and regulations
- Compliance should focus on notifying law enforcement, compliance authorities and monitoring service level agreements (SLAs)
- Operations should focus on maintaining business continuity
- Back office must secure transactional data
- Marketing and PR should manage external communication and reputational crisis management
- The executive team should work with highly skilled ransomware negotiators while managing high level stakeholder engagements
As such, Dirk makes his entire company participate in these simulations annually. “Given the interconnectedness of financial ecosystems and economies, all businesses that offer financial solutions to their clients have a duty to protect the ecosystem in which they operate,” he says.
System vulnerabilities and protection strategies
The Check Point report highlights that ransomware groups increasingly target Linux and VMWare ESXI systems. “Open-source servers and virtual machines can make companies vulnerable to attack, and can expose critical applications and data to danger,” Dirk says.
While they are quite secure by design, they can suffer from bugs and vulnerabilities like any other software. “For instance, its various components and libraries from third-party sources could include additional vulnerabilities and bugs, and hypervisor technology is normally hosted on multiple virtual machines, which means a single compromised VMware ESXi hypervisor could potentially provide access to numerous virtual servers,” he explains.
To counter these threats, he recommends regular patching and backup practices regardless of the system used. “Adopt a ‘zero trust’ model, because threats can come from anywhere,” he says. This means assuming no user or system is trustworthy by default, requiring verification from everyone attempting to access resources.
His other recommendations include:
- Testing recovery procedures to ensure quick data restoration
- Segmenting systems to contain potential breaches
- Installing endpoint protection on all devices
- Implementing strong access controls
- Regular security scans to detect anomalies
- South Africa’s mobile threat
The Check Point Threat Intelligence Report for South Africa 2025 revealed that mobile and botnet attacks are higher in South Africa than elsewhere in the world. Dirk attributes this to the country’s high smartphone penetration rate. “About one-third of the population – about 22 million people – use smartphones, and in many cases, people have more than one phone or SIM card,” he explains. “Although SA has a population of about 65 million people, there are about 90 million mobile connections in the country.”
This widespread use of mobile phones for banking, shopping and other online activities creates abundant opportunities for cybercriminals. Dirk stresses the importance of public education on cybersecurity basics, such as using strong passwords, keeping software updated, employing security apps, avoiding public Wi-Fi for sensitive transactions and utilising two-factor or biometric authentication.
“Many organisations, including our banks, institutions and organisations such as the National Consumer Commission (NCC), are trying to educate the public, but we need to step it up to reach more people with the message,” says Dirk.
The report also identifies four prominent threat types in South Africa:
- Information disclosure (accidental exposure of sensitive data)
- Remote code execution (hackers running malicious code on remote systems),
- Authentication bypass (circumventing login security), and
- Denial of service attacks (overwhelming systems to disrupt operations).
South African banks leading in cyber defence
Despite these challenges, Dirk sees positive developments in the South African banking sector, stating that South African banks are “global leaders when it comes to cybercrime preparedness”. Check Point found that banking attacks have been lower in South Africa than in the rest of the world in the second half of 2024.
He attributes this success to several factors:
- Heavy investment in advanced security technologies
- Multi-layered security approaches (including AI and machine learning)
- Regular security audits
- Strong encryption practices
- Industry-wide information sharing
- Effective collaboration with regulators like SABRIC and the South African Reserve Bank
“South African banks have invested heavily in advanced security technologies and practices,” Dirk notes. “They use multi-layered security approaches, which include advanced threat detection through AI and machine learning, regular security audits to identify and fix vulnerabilities, and encryption of sensitive data, both in transit and at rest."
The South African Reserve Bank has also published a joint standard and directives on cybersecurity.
The ecosystem approach to security
Dirk believes that companies fall victim to attacks more frequently if they have vulnerabilities such as sensitive or financial data that could be enticing to criminals, complex systems with weak spots that give hackers a way to get in undetected and old legacy technology that has inadequate cybersecurity defences.
His advice is that organisations need to keep up with the pace of technology change, such as AI, which can be deployed to detect and respond to threats immediately.
Dirk emphasises that cybersecurity in the financial sector must be understood as an ecosystem responsibility. He explains that, when criminals gain access to sensitive financial and customer data, it puts the entire network and data system at risk. “Any breach can wreak havoc in the lives of customers, and for local and global ecosystems, including the various types of payment rails,” he notes.
This interconnected nature of financial systems means organisations must look beyond their own perimeters and think about how their security posture affects the broader ecosystem.
















