Cyber and Information Security is a complicated and often very technical topic that can be quite daunting for those who don't come from technical backgrounds. We wanted to have a place where questions can be asked and answered in a non-techy way to help you understand why certain policies are in place, what some of the risks of doing something may be or any other cyber-security related question you care to ask.
We do want this site to cater to more than just work-related topics. Cyber-security extends to our personal lives and those of our children and families. Please feel free to ask other questions related to personal or family safety too.
Why do we need to use Multi-Factor Authentication?
Multi-Factor Authentication (MFA or sometimes called 2FA) is the system we have in place to ensure that we validate that you are you via at least 2 methods. In the past, passwords were the main way we authenticated people to our systems and services, but the bad guys have developed many ways of getting your password over the past few years. To protect against the fact that your password could be known by others, we require you to type in a number that is delivered to you via an app or SMS. This is not perfect and doesn't cover everything, but it does achieve the goal of making it harder for a bad guy to gain access to your account. Everything we do is around making it harder for the bad guys while hopefully not too much harder for you.
Why do our passwords need to be so long?
Password uniqueness (not using the same password on multiple sites) is the most important part of password security followed by length. The longer the password is, the more difficult it is to crack. The traditional “cracking” of passwords is becoming less common as social engineering (tricking people into giving their passwords away) is far less work and much more effective for the bad guys. There is an article detailing passwords and some of the ways to choose good passwords here. How to survive the password madness!
Doesn't Pepkor use expensive technology to keep us safe so it doesn't matter what I do?
Pepkor has spent a lot of money and effort on security technologies and tries to keep them in tip-top shape to ensure they provide as much protection as possible, but we are still very reliant on our people to ensure that our critical data and systems are kept safe. The technology and policies we have in place are there to act as guardrails, traffic lights and the rules of the road. We still need you to know the rules of the road, drive safely, be alert and report anything you see that seems suspicious or out of place. You are usually the prime target of an attack. You are also our best defence.