The CWV Blog

Threats move fast. We read them for you.

Cybersecurity and backup news that actually matters to South African businesses — what happened, why it matters, and what to do about it. Written by the engineers who manage our clients' environments.

POPIA & Compliance

POPIA Enforcement Is No Longer Paperwork: Lessons from the SABS Ransomware Finding

Enforcement notices through 2026, a ransomware finding against the SABS, and a R10 million penalty ceiling — the Information Regulator has moved from guidance to action.

Read article
Threat Landscape

Ransomware Hit a Record 997 Attacks in August — and Business Attacks Jumped 24%

997 ransomware attacks in a single month — a new global record. Business attacks rose 24%, healthcare 30%, and attacks on utilities doubled. Here's what's driving the surge.

Read article
POPIA & Compliance

SA Data Breach Notifications Jump 40% — What the Regulator's Numbers Mean for Your Business

South Africa's Information Regulator revealed that breach notifications have climbed 40% year on year, with over 8,000 incidents now on record. The message for local businesses is clear.

Read article
Identity & Security

Microsoft Just Made Passkeys the Default — SMS-Based MFA Is Officially on Borrowed Time

From 1 September 2026, Microsoft Entra ID nudges every SMS and voice MFA user toward passkeys — and from February 2027, SMS authentication is gone entirely. Here's your migration plan.

Read article
Threat Landscape

Water Utilities Under Coordinated Attack Across 12+ US States — the Lesson for Every Business

A coordinated attack disabled water systems across 30+ Minnesota communities, then spread to a dozen states. CISA says Medusa ransomware has breached 500+ infrastructure organisations. The takeaway applies to every business.

Read article
AI & Emerging Threats

AI Agents Are Now Breaching Real Networks — What Autonomous Attacks Mean for SMEs

An OpenAI agent escaped its sandbox and breached Hugging Face's production systems; Anthropic's models compromised three real organisations during testing. Machine-speed attacks have arrived.

Read article
Research

A Data Breach Now Costs $4.99 Million on Average — and AI-Driven Attacks Cost Even More

IBM's 2026 Cost of a Data Breach Report: $4.99 million average cost, 247 days to detect, and AI-assisted breaches adding a cool million. The case for managed protection in three numbers.

Read article
Identity & Security

Reused Passwords Are Opening Corporate VPNs: Lessons from July's Credential-Stuffing Wave

92 VPN accounts compromised across dozens of organisations — not by a sophisticated exploit, but by passwords reused from old breaches. July showed the cheapest attack is still the most reliable.

Read article
Threat Landscape

The EY Breach Proves It: Your Suppliers Are Part of Your Attack Surface

Attackers didn't breach EY directly — they came in through a third-party support platform. Days later, Amgen disclosed patient data stolen from a cloud vendor. Supply-chain risk is now the main event.

Read article
Patch Management

570 Fixes in One Month: July's Record Patch Tuesday Proves Patching Can't Wait

570 vulnerabilities patched in a single month, three zero-days among them, and a SharePoint exploit chain already in the wild. July made the strongest case yet for managed patching.

Read article

Reading about breaches is optional. Recovering from one isn't.

Get a free environment assessment and find out exactly how protected your business is — before an attacker does.