X

The “Permission Economy”, Why Cybersecurity Is Mostly About Who Can Say Yes

Most organisations still talk about cybersecurity as if it is a war of machines. Firewalls, malware, endpoints, patches. That language is comforting because it implies a technical solution. Yet the last few years have been teaching a more awkward lesson, most modern breaches are not breakthroughs in computing, they are breakthroughs in persuasion. And the next stage of that persuasion is being industrialised by AI.

The mental shift that matters is to stop thinking of cybersecurity as protecting systems, and start thinking of it as governing permissions. A modern organisation is a permission economy. Every useful thing that happens in a business is some form of authorised access, to money, to data, to systems, to approval chains, to suppliers, to customers. Attackers do not need to defeat your best technology if they can borrow your permissions, or trick someone into granting them.

The new threat model is a world where “convincing” is cheap

AI is not simply adding more attacks, it is changing the cost structure of deception. When an executive voice can be mimicked, when emails can be tailored to the recipient’s role and writing style, when social engineering can be run like a marketing campaign, the human layer becomes the primary attack surface. That is why executive outlooks in 2026 are framing AI as the biggest driver of change in cybersecurity right now.

If you are a decision owner, you should hear that as a governance statement, not a technical one. Persuasion at scale attacks processes, approvals, and culture. It targets the places where people say, “yes, that seems reasonable”.

Ransomware is no longer just theft, it is coerced downtime

Ransomware remains a top organisational cyber risk, and the trend line is becoming nastier. The story is shifting from “we stole your files” to “we broke your operations”, because disruption is leverage. When attackers aim at airports, logistics, healthcare, or the systems that keep customers moving and goods flowing, the reputational blast radius dwarfs the technical one. The organisation is forced to negotiate, not because it has lost data, but because it has lost time.

In a permission economy, ransomware often succeeds because permissions were too broad, too permanent, and too poorly monitored. A compromised identity becomes a master key, and the business effectively assists the attacker by executing legitimate commands at the wrong time.

The perimeter is dead, identity is the new map of reality

Hybrid work and cloud services have turned the old security perimeter into a myth. You can no longer rely on “inside the network” as a proxy for “trusted”. That is why identity first security and Zero Trust ideas are gaining traction, not because they are fashionable, but because they describe the environment accurately.

This is also where many programmes stumble, because they focus on employee identities and forget machine identities. Service accounts, APIs, automation scripts, and software components often carry high privileges and low visibility. When they are compromised, they do not trigger the same suspicion as a human user, and they can move very fast.

Supply chains turn cyber risk into an ecosystem problem

Interdependence is now a default state. Gartner explicitly highlights supply chain interdependencies as a defining trend, and any leader who has handled an incident knows why. Your organisation is not only as secure as your own controls, it is as secure as the least mature partner you trust with access, data, or workflow integration.

This is where cyber inequality becomes dangerous, large organisations harden, smaller ones lag, attackers pivot through smaller targets and arrive at larger ones through shared trust. WEF flags this widening resilience gap as a major issue, and it is not abstract, it is supply chain maths.

South Africa is seeing the governance era arrive, finance is the leading indicator

Regulation always tells you where a market is going to price trust. In South Africa, the financial sector has a clear milestone, with cybersecurity and cyber resilience requirements for financial institutions, with implementation dates being communicated publicly. This matters beyond finance, because banks and insurers pull their supply chains upwards. If you sell into a regulated industry, you inherit their security expectations.

What decision owners should do, govern permissions as if they are money

Treat permissions like financial controls. Be explicit, measured, auditable, and reversible. Five principles make the difference.

First, design approvals so that high risk actions require strong verification, not just a polite email. Second, reduce privilege creep, make access temporary by default, and review it continuously. Third, get serious about machine identities, inventory them, rotate secrets, and remove broad privileges. Fourth, treat suppliers as part of your security programme, set minimum controls, verify them, and segment access. Fifth, build resilience for disruption, tested backups, rehearsed recovery, and crisis playbooks that include executives, not only IT.

The point is not to become paranoid. The point is to become deliberate. In the permission economy, cybersecurity is the craft of designing how the organisation says yes, and how quickly it can say no when something feels off.

Jul 31, 2026

Trust Is Not a Soft Asset. It’s the Infrastructure African Commerce Keeps Neglecting.

Read Full Article

Jun 30, 2026

Why the Next African Unicorn Will Come From a Township, and Why Nobody Is There to Listen

Read Full Article