With phishing, smishing, and vishing attacks on the rise across South African enterprises, the proactive management of cybersecurity risks is no longer optional and is fast becoming an industry standard. Richard Cassidy, CISO for the EMEA region at Rubrik, offers his expert perspective on what CIOs need to prioritise to counter the growing threat of identity-based attacks.
Richard Cassidy, CISO for the EMEA region at Rubrik, outlines key considerations for South African CIOs looking to strengthen cyber resilience and implement more effective identity protection strategies.
Is there a rising urgency for cyber resilience in SA, and why?
The urgency for cyber resilience in South Africa is growing rapidly. Recent breaches at the South African Weather Service, MTN, and SAA highlight a clear trend: large, high-profile organisations are increasingly becoming targets of sophisticated cyberattacks.
It’s no longer a matter of if an organisation will be targeted, but when. This reality demands a shift in mindset, from purely focusing on prevention to building resilience. That means combining protection with preparedness, and placing equal emphasis on recovery, response and transparency.
Cyber resilience is now a business imperative. As threats become more complex and persistent, South African – and global – organisations must evolve from defensive postures to adaptive strategies that can withstand, respond to, and recover from disruption, without losing trust or operational continuity.
What can you tell us about this increase in identity-based attacks? Why are they happening more?
Rubrik Zero Lab’s latest research found that identity-based attacks account for nearly 80 percent of all cyberattacks. This shift reflects a major evolution in attacker tactics, one that’s closely tied to how modern businesses now operate. As organisations increasingly adopt hybrid and multi-cloud environments, implement identity-driven access models, and manage distributed workforces, the perimeter has shifted from physical infrastructure to individual identities as a gateway for criminals.
Instead of “breaking in” using malware, attackers are “logging in” using valid credentials, a method that's significantly harder to detect and block with traditional tools. As indicated in the latest research from Rubrik Zero Labs, which includes data from CrowdStrike and Microsoft, Microsoft alone reported blocking over 600 million identity-based attacks daily.
Why are we seeing an increase in this type of attack? Simply put, businesses are ill-prepared, and human error happens. Identity compromise offers a route into enterprise environments, and cyber criminals will exploit the weakest link in the chain where they can. Rubrik’s research shows that the time between initial access and full command over sensitive systems is dropping, with some intrusions reaching “breakout” in as little as 51 seconds. Additionally, over 86 percent of organisations that suffered a ransomware attack ended up paying a ransom, underscoring the effectiveness and damage potential of these attacks.
Cloud complexity, decentralised data, and reliance on SaaS platforms create ideal conditions for threat actors to thrive. Organisations must come to grips with the reality that their most critical vulnerabilities are no longer at the firewall, they’re embedded in user credentials and permissions.
This is why building strong identity and access management practices, layered with automated monitoring and Zero Trust architecture, is no longer optional. It’s the only way forward.
What easy-to-implement steps should CIOs start with to lock down both user and system accounts?
CIOs must lead with a mindset shift, from passive defence to proactive identity security. That strategic pivot should translate into practical, high-impact actions across the organisation. From my perspective, the easiest and most effective starting points are:
- Ground AI initiatives in real-time data awareness: Security tools, especially AI-powered ones, are only as good as the data they’re trained on. CIOs should prioritise solutions that deliver dynamic, contextual insights across structured and unstructured environments, enabling smarter and faster threat detection.
- Implement least privilege access: Limit every user and system account to only what’s absolutely necessary. Excessive permissions are a common vulnerability. Regular audits should be built into the security routine to identify and remove unnecessary access.
These aren’t heavy-lift changes; they’re foundational, and they help. Identity is the new perimeter, and securing it starts with getting the basics right.
As attackers employ smarter social-engineering tricks, what practical training and automated checks can help employees recognise and avoid convincing phishing or voice-based scams?
As scams grow more sophisticated, a combined approach of human training and automated detection is essential to address evolving vulnerabilities. One of the most effective steps is upgrading scenario-based testing to include current, high-impact phishing and vishing (voice phishing) techniques. These simulations help employees build intuition and stay alert.
But training shouldn’t stop at scenarios. It’s just as important to teach the psychology behind the scam; how attackers create false urgency, impersonate authority, or manipulate just enough personal information to make their message seem legitimate.
On the automation side, AI-enabled tools can proactively flag suspicious behaviour, such as unusual login patterns or unexpected data transfers, before they escalate into serious breaches. In addition, implementing email security filters with anomaly detection and real-time link and attachment scanning helps block threats at the source, preventing malicious content from ever reaching users.
When companies use dozens of cloud apps and tools, how can CIOs ensure identity rules and access policies stay consistent everywhere, without overwhelming IT teams?
CIOs need to start by scaling security thinking across the entire organisation, not just within the IT department. This mindset shift is foundational to enforcing consistent identity rules and access policies without overwhelming already stretched IT teams.
The reality is, the attack surface today isn’t limited to IT infrastructure; it includes every team, tool and workflow. CIOs and security leaders can’t be in every room, but their influence can. Embedding secure-by-design thinking into how each business unit operates, from product and finance to HR and marketing, extends the reach of identity governance and reduces risk across the board.
In practice, this means aligning on shared principles (like least privilege access), leveraging identity management platforms with automated policy enforcement, and giving non-technical teams the tools and awareness they need to act securely by default. It’s not just about central control, it’s about decentralised responsibility, powered by smart systems and a security-first culture.
How can CIOs strike the right balance between tighter identity controls and keeping user workflows smooth, so security measures don’t turn into daily frustrations?
It starts with creating visibility across the business, not in a way that slows people down, but in a way that supports smarter, more adaptive risk mitigation. Identity controls shouldn’t be blockers; they should be frictionless guardrails. That’s why automation is key. Automating detection and response, backed by real-time threat intelligence, allows security to happen in the background, enabling rapid decision-making and containment without constant user disruption.
CIOs should also empower IT teams to use AI to pressure-test assumptions, simulate attack scenarios, and automate triage, even rewriting post-incident reports to reflect evolving tactics and lessons learned. This turns identity controls from static policies into adaptive, learning systems.
Just as importantly, security must be mapped to real business priorities. Work closely with business stakeholders to define resilience goals: what must never go down, what must recover fast, and what a "smooth recovery" looks like. That clarity helps shape identity policies that protect what matters most, without turning everyday workflows into obstacles.
Fundamentally, it’s about alignment: between IT, security, and the people who use the systems every day. That’s where real resilience and usability are built.
















