Advertisements

NAM-CSIRT said that media practitioners, digital publishers and members of the public must exercise “due care when handling information” obtained through cyber attacks.

The Namibia Cyber Security Incident Response Team (NAM-CSIRT) said it has noted with concern an emerging trend in which individuals access, study, analyse and unpack data stolen or leaked following cyber incidents, either for subsequent publication or to improperly target, intimidate, cause distress to or otherwise adversely affect individuals whose information has been exposed.

“While reporting on cyber incidents and matters of legitimate public interest remains important, the active analysis, exploitation or further dissemination of stolen or leaked personal information may raise significant ethical, privacy and legal concerns, particularly where such conduct causes or compounds harm to affected individuals,” said CRAN’s manager for communication and consumer relations, Mr Mufaro Nesongano.

Nesonagno said: “NAM-CSIRT urges members of the public and other stakeholders to refrain from accessing, analysing, sharing, redistributing or otherwise using stolen or leaked personal information in ways that could cause distress, intimidation, reputational harm or other adverse consequences for affected individuals.

“Victims of cyber incidents should not be subjected to further harm or secondary victimisation through the misuse or circulation of information that has been unlawfully obtained and exposed by cybercriminals.

“The fact that personal information has been leaked or placed in the public domain following a cyber-attack does not remove the need to handle it responsibly.

“Further examination, reproduction or dissemination of compromised personal information may amplify the damage caused by the original incident, worsen its impact and contribute to the continued victimisation of affected persons.

“Cyber incidents should not create a second wave of victimization.”

When handling leaked, allegedly leaked or unlawfully obtained information, care should be taken to verify its authenticity, minimise further disclosure, retract personal or sensitive information, and avoid publishing personal identifiers, credentials, contact details or internal documents.

Where appropriate, such information should be referred to the relevant authorities or affected institutions.

He added: “These responsible information-handling practices are particularly important in the absence of a finalised and comprehensive data protection law.”

Institutions are encouraged to exercise heightened caution and to be guided by recognised principles of responsible information handling.

Clearer statutory requirements would further promote consistency, strengthen accountability and provide greater certainty regarding the protection of personal information across sectors.

“NAM-CSIRT therefore encourages institutions to familiarise themselves with applicable data protection principles and to adopt proactive measures that support the lawful, secure and responsible processing of information.

“Finalising Namibia’s data protection framework remains an important step towards strengthening public confidence, institutional accountability and the protection of personal information.”

In the photo: Mr. Mufaro Nesongano.