Cybersecurity Law

Cybersecurity or information security is a crucial part of information management. We are experts on the legal aspects regards the security of information (infosec). You can read our advice, or about the products or services we offer related to this focus area below:

Secure data sharing

Navigating the world of data sharing can feel like traversing a minefield. But don't worry. We're here to provide a reliable map for data protection officers that leads to secure data-sharing practices. Understanding data sharing Data sharing involves data providers [...]

By |2023-04-04T21:41:52+02:00April 4th, 2023|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , |

Incident response training through roleplay

Picture this: You're in a dimly lit room, a mysterious figure lies dead on the floor, and you've got a room full of suspects. The culprit? A data breach, insider threat, or even a malicious malware attack. No, this isn't [...]

GDPR enforcement actions – March 2023

As the saying goes, "March comes in like a lion and goes out like a lamb". Regarding GDPR enforcement actions collated in March 2023, the lion has roared. Recent enforcement actions related to the General Data Protection Regulation (GDPR) in [...]

Third party risk management: never do it alone

In today’s interconnected and international business world, third party risk management is vital to your organisation’s risk management strategy. Third-party relationships introduce significant risks to your business, whether with suppliers, vendors, or service providers. These risks include data breaches, intellectual [...]

By |2024-08-25T22:18:15+02:00March 17th, 2023|Categories: Cybersecurity Law|

DKIM: what is it and why does it matter?

Email has long been a primary mode of communication, and we depend on it for both personal and business use. However, email security has become a significant concern with increasing cyber threats. As a result, using DKIM has become increasingly [...]

By |2024-08-25T22:19:42+02:00March 16th, 2023|Categories: Cybersecurity Law, Electronic Communications Law, Email Law|

Membership inference attacks | A new AI security risk

Let’s explore a new AI security risk: membership inference attacks. What is it? It’s an AI attack during which an attacker tries to determine if you have used a particular person’s personal information to train a machine learning model. The [...]

By |2024-08-26T06:21:09+02:00March 8th, 2023|Categories: AI Governance, Cybersecurity Law, POPI and Data Protection|

Model inversion attacks | A new AI security risk

Let’s explore a new AI security risk: model inversion attacks. What is it? It’s a type of AI attack during which an attacker tries to infer personal information about a data subject by exploiting the outputs of a machine learning [...]

By |2024-08-26T06:21:36+02:00March 8th, 2023|Categories: AI Governance, Cybersecurity Law, POPI and Data Protection|

Safi v Gascoigne | BEC

In Safi v Gascoigne, Safi sued Gascoigne Randon and Associates, a conveyancing firm, for a loss of R889,308.50 from a business email compromise (BEC).  Who should care about this judgment and why? The public because they need to be aware [...]

Your duty of care regards information security

Every organisation has a duty of care to establish and maintain appropriate information security. The judgment in Hawarden vs ENS illustrates that no modern business can operate properly and lawfully without establishing and maintaining appropriate information security. The facts of [...]

Hawarden v Edward Nathan Sonnenbergs (ENS) | BEC

In Hawarden v Edward Nathan Sonnenbergs (ENS), Hawarden succeeded in suing ENS for the loss of R5.5 million because of a Business Email Compromise (BEC). Hawarden was ENS' client.  The court said that ENS owed a general duty of care [...]