Why your cloud journey must start with a “gearlock” mindset to remain safe and compliant
By Industry Contributor 7 September 2026 | Categories: feature articles
By Allan Juma, Lead Cyber Security Engineer at ESET
Recently, I was involved in a discussion with an acquaintance about a home-security upgrade. The additional investment was not necessarily on the radar, except that the person told me that he had suspected someone may have breached his perimeter fence without stealing anything. This investment, he said, was his “second wave” of home security, having completed what he considered the basics a year prior.
It reminded me of the current state of cybersecurity in South Africa, where we are clearly seeing a similar “second wave” investment in security in the digital realm. As our data moves from on-prem servers to the cloud, many organisations are realising that while the neighbourhood may have changed, the threat has not. This is in no way alarmist, it is just an acknowledgement of the status quo.
Africa, as we know, is no longer just a participant in the digital revolution. If we look at Southern Africa, we are its rising star. Recent research from McKinsey suggests that Africa’s cloud growth potential exceeds that of more mature markets such as Europe. With 40% of infrastructure already migrated as of 2024, it is safe to say this continent is bypassing legacy limitations and surging into the digital future.
The continent has clearly seen the advantages of being in the cloud: reduced total cost of ownership and an ability to level the playing field with international competitors of any size, among other benefits. However, as this reality accelerates, we are facing a critical consideration: data sovereignty.
The data sovereignty challenge
South Africa has released pivotal national policies on data and the cloud. These aren't just suggestions; they are policy mandates. Under POPIA, there are strict conditional cross-border transfer regimes that act as de facto data localisation for certain types of data.
Large hyperscalers have already planted flags in the ground with local data centres. The data sovereignty imperative exists alongside the need to keep the data safe. This all creates a complex challenge for an organisation’s C-suite. And so, as organisations navigate this evolving landscape, how do they protect their data while leveraging the power and advantages of the cloud?
The cloud security fallacy
The biggest misconception in the market is the belief that security in the cloud is someone else’s problem. Many business leaders fall into a false sense of security, assuming that because they are using a world-class provider, their data security is automatically bulletproof. This is a dangerous misconception.
Cloud security operates on a shared responsibility matrix. Perhaps it is best to think of this in terms of an analogy. The provider secures the building, the cables and the physical “box”, so to speak. The end user, you, is responsible for securing the doors, the windows and the locks. You are in charge of your encryption, configuration and your organisation’s digital hygiene.
Modern security does not override old-school discipline
How often have you heard: How much security is too much? Or worse: “Cyber security is just another cost centre”? The original conversation among acquaintances about the second wave of home security evolved into a discussion about purchasing a new vehicle. Another commented that she had just bought a new car and that smash-and-grab tint and a tracker device were part of the basic essentials, the former a necessity out of lived reality, and the latter a requirement for insurance. What may have been considered optional or advanced extras in the past are today considered a non-negotiable fundamental of new car ownership.
Now, consider that a few decades ago, gealocks and steering locks were the standard security layer. Indeed, many people still use gearlocks and steering locks today, in addition to whatever new technologies have been brought to the table. The gearlock physically prevents the vehicle from being operated.
Related to this, we must understand that data sovereignty isn't just a legal hurdle. It is a security architect’s blueprint. In other words, when the law says data must stay within a country’s borders, a gearlock mindset ensures that even when data is hosted locally or in hybrid environments, it remains as protected as if it were in a physical vault on-prem. That understanding is critical to understanding modern cybersecurity.
What do we learn from this? The world has evolved, and so we need to evolve too. For the modern organisation, in addition to supporting a gearlock mindset, the second wave of security essentials for our digital world includes:
- Endpoint security: Protecting the organisation’s devices that access the cloud.
- Identity access management: Ensuring that only the right people have the keys to the organisation.
- Vulnerability and patch management: Keeping the software updated to avoid breakdowns and known vulnerabilities.
The bottom line
To return to the vehicle analogy: Whether you are driving a high-end, modern push-to-start, software-driven electric vehicle that requires a fob or NFC mobile phone to be present to start, or an old-school petrol-driven manual car with a mechanical gearlock installed, the goal remains the same: you want to prevent somebody else from driving off with your asset.
Securing your data needs the same pragmatic approach. As we navigate the gray areas of data regulations and the vastness of the African cloud market, security cannot be an afterthought. It must be “baked in” to the organisation’s infrastructure investments, and not “bolted on”, after the fact. Organisations are innovating and building incredible infrastructure of a continent. The onus is on all of us to make sure we aren’t leaving the keys in the ignition.
Most Read Articles

Have Your Say
What new tech or developments are you most anticipating this year?

