
IT forensics can not only help mop up the aftermath of a successful hack, it can reveal the motives and plans of the culprit, and can help reduce the damage of a security incident. But while criminals have realised a target's data is its most valuable asset, most organisations do not realise the value of their intellectual property (IP), do not protect it, and do not understand the risk of exposure, said Janine Hollesen, a director at Werksmans specialising in IP.
"You're facing the erosion of competitive advantage, loss of sales, reputation damage, and the loss of potential investment," Hollesen said. "Every type of intellectual property is of value to your competitor and to a hacker."
Criminal activity, particularly industrial espionage, is on the rise, and getting easier. "Cybercrime costs SA over a billion rand a year," said David Loxton, partner at Werksmans Attorneys. "According to the FBI, SA is number six on the list of attractive destinations for cybercrime, but unofficially it's believed we're closer to third place.
"Motivations include stealing trade secrets, damaging profits, revenge, or just fame for the hacker." Regardless the motive, Loxton said, the impact on a company can be devastating. "We even had a revenge incident at this firm - a dismissed employee deleted their boss's archive of precedents."
"The reality is most hacks are quite straightforward," said Simon Placks, director of Ernst & Young's fraud investigation and dispute services division. "It's easier to hack humans than computer networks. Most people have an enthusiasm for technology without really understanding security implications, and that leaves us susceptible. That is particularly relevant in SA, with the rapid adoption of mobile technology.
"You are going to get hacked," he added. "You can't prevent it, but you can minimise the damage and monitor your network to identify and block malicious activity quickly."
IT forensics is typically used to analyse incidents to tighten security after a breach, but Placks advocates a more active role in day to day security.
Identifying and tracking suspicious behaviour can help identify employees who are jumping ship to a competitor, and may be taking trade secrets with them, Placks said. It could also identify high-profile executives who could be at risk of targeted attacks like spear-phishing or blackmail, he noted, describing an incident with a top exec at a financial institution whose sexual activities, revealed through his Google history, suggested he may be a high risk.
In SA, employers must also understand the extent to which they are allowed to investigate private data on employees' machines, as permitted by the ECT Act, RICA, the impending Protection of Personal Information Act, and others, said Loxton.
Although employers have the right to investigate systems on their networks and to monitor communications, the growing BYOD (bring your own device) trend not only increases the surface area for attackers, it makes things more complicated for internal security efforts, Loxton said. Users may well install encryption tools to legitimately prevent an employer accessing personal data, but the same tools could be used to hide IP theft, he said.

