RESEARCH-BASED ASSIGNMENT
Analysis of Factors Influencing the Data Security
of an Organisation
Case study organisation: Econet Wireless Zimbabwe
Focus: Data security threats, findings, recommendations and conclusion
Prepared as an expanded reference document for a slide presentation.
1. Introduction – Statement of the Problem
Econet Wireless Zimbabwe operates in a highly data-dependent environment. A telecommunications
organisation handles customer information, authentication details, billing records, mobile-money
transactions, employee information, network data and business records. The confidentiality, integrity and
availability of this information are therefore essential to customer trust and continuity of operations.
The main problem is that organisational data can be exposed, altered, lost or made unavailable through
cyberattacks, human error, weak access controls, insecure devices, outdated software, insider threats,
third-party weaknesses and physical incidents. A successful breach can cause financial losses, service
disruption, reputational damage, regulatory consequences and loss of customer confidence.
2. Organisation Background
Econet Wireless Zimbabwe is a major telecommunications operator providing mobile communications
and related digital services. Because telecommunications services depend on interconnected networks,
information systems and large volumes of data, security must be treated as an organisation-wide
responsibility rather than only an IT issue.
For this assignment, the organisation is used as a case study to analyse common and realistic factors
that can influence data security in a telecommunications business. The analysis does not claim that the
organisation has experienced any particular breach unless independently verified.
3. Key Factor: Human Error
Employees can unintentionally expose information by using weak passwords, clicking malicious links,
sending confidential information to the wrong recipient, leaving devices unlocked or mishandling files.
Human behaviour is particularly important because technical security controls can be undermined by
unsafe decisions.
Effect: phishing, credential theft, accidental disclosure and unauthorised access.
Control: continuous security awareness training, simulated phishing exercises, strong password
policies, multi-factor authentication and clear incident-reporting procedures.
4. Key Factor: Cyberattacks and Malware
Attackers may use phishing, ransomware, spyware, credential attacks, malicious attachments or
exploitation of software vulnerabilities. Telecommunications organisations can be attractive targets
because their systems support large numbers of customers and important services.
Control: endpoint protection, email filtering, network monitoring, intrusion detection, secure
configuration, vulnerability management, threat intelligence and tested incident-response procedures.
5. Key Factor: Weak Access Control
If users receive more privileges than necessary, a compromised or misused account can expose a large
amount of information. Shared accounts and poor management of former employees' access also
increase risk.
Control: role-based access control, least privilege, multi-factor authentication, privileged-access
management, periodic access reviews and immediate removal of unnecessary accounts.
6. Key Factor: Software and System Vulnerabilities
Unpatched operating systems, applications, databases, routers and other infrastructure may contain
vulnerabilities that attackers can exploit. Legacy systems can be particularly difficult to secure when they
are essential to operations.
Control: maintain an asset inventory, prioritise critical vulnerabilities, apply security patches, conduct
vulnerability scanning and penetration testing, and use secure software-development practices.
7. Key Factor: Insider Threats
Insiders may intentionally steal information or unintentionally expose it. Risk can arise from excessive
privileges, poor monitoring, disgruntled employees, contractors or compromised employee accounts.
Control: least privilege, separation of duties, logging and monitoring, behavioural alerts, background
screening where appropriate, strong offboarding procedures and disciplinary policies consistent with law
and organisational policy.
8. Key Factor: Third-Party and Supply-Chain Risk
Organisations rely on vendors, software providers, contractors, cloud services and other partners. A
weakness in a supplier's environment can become a weakness in the organisation's own
information-security ecosystem.
Control: supplier due diligence, security requirements in contracts, access restrictions, vendor risk
assessments, audit rights, security incident notification clauses and periodic reassessment of critical
suppliers.
9. Key Factor: Physical and Environmental Risks
Data security is also affected by physical access to offices, server rooms, network equipment and backup
media. Fire, theft, flooding, power failure or equipment damage can interrupt services or expose stored
information.
Control: controlled physical access, CCTV where appropriate, visitor management, environmental
monitoring, fire protection, backup power, secure equipment rooms and protected backup storage.
10. Key Factor: Data Backup and Recovery
Data that is not backed up, or backups that are connected continuously to production systems, may be
lost or encrypted during a serious incident. Recovery also depends on whether backups are complete
and whether restoration procedures have been tested.
Control: maintain multiple backup copies, protect backups from unauthorised access, use offline or
otherwise isolated copies for critical data, encrypt sensitive backups and conduct regular restoration
tests.
11. Key Factor: Network Security
Telecommunications environments contain interconnected networks and systems. Poor segmentation
can allow an attacker who compromises one system to move to other systems. Unsecured remote
access can also increase exposure.
Control: network segmentation, secure remote access, firewalls, encryption, monitoring, strong
authentication and a zero-trust approach where appropriate.
12. Findings
The analysis shows that data security is influenced by a combination of people, processes and
technology. The most significant risks are not limited to sophisticated hacking; ordinary weaknesses such
as stolen credentials, excessive privileges, poor patching, weak supplier controls and inadequate
recovery planning can create major exposure.
A strong security programme should therefore use defence in depth: several complementary controls
should protect important information so that failure of one control does not automatically result in a
serious breach.
13. Recommendations
1. Implement multi-factor authentication for critical systems and remote access.
2. Apply least privilege and conduct regular user-access reviews.
3. Provide compulsory, continuous cybersecurity awareness training.
4. Strengthen vulnerability management and patch critical systems quickly.
5. Segment critical networks and monitor unusual traffic and account activity.
6. Encrypt sensitive information in storage and during transmission.
7. Maintain tested, protected and appropriately isolated backups.
8. Establish and regularly test an incident-response and business-continuity plan.
9. Assess third-party suppliers before granting access to sensitive systems.
10. Conduct periodic security audits, vulnerability assessments and penetration tests.
11. Improve physical security of server rooms, network equipment and backup media.
12. Establish clear data-classification, retention and secure-disposal procedures.
14. Conclusion
Data security is critical to a telecommunications organisation because the business depends on reliable
information systems and customer trust. Human error, cyberattacks, weak access controls,
vulnerabilities, insider threats, third-party risks, physical incidents and inadequate recovery arrangements
can all affect the confidentiality, integrity and availability of data.
Econet Wireless Zimbabwe can reduce these risks by combining technical controls with employee
training, strong governance, monitoring, supplier management, secure backups and regular testing. The
objective should not be to eliminate every possible threat, which is unrealistic, but to reduce the likelihood
and impact of incidents and recover quickly when they occur.
15. Suggested References
For an academic submission, consult authoritative sources such as:
• National Institute of Standards and Technology (NIST), Cybersecurity Framework (CSF) 2.0.
• ISO/IEC 27001, Information security management systems — Requirements.
• ISO/IEC 27002, Information security controls.
• Verizon, Data Breach Investigations Report (latest available edition).
• ENISA, Threat Landscape publications.
• Zimbabwe's applicable data-protection and cybersecurity legislation and regulatory guidance.
Use the latest editions available at the time of submission and format the references according to your
institution's required referencing style.
Quick Slide Structure
Slide Recommended content
1 Title and organisation
2 Introduction / statement of the problem
3 Organisation background
4 Human error
5 Cyberattacks and malware
6 Access control
7 Software vulnerabilities
8 Insider threats
9 Third-party risk
10 Physical/environmental risks
11 Backup and recovery
12 Network security
13 Findings
14 Recommendations
15 Conclusion
16 References