For years, the implicit assumption running through South Africa’s cybersecurity compliance conversation was straightforward. If your organisation was breached, you were the victim. You notified the Information Regulator, cooperated with the investigation, implemented remediation measures, and the regulatory process focused on ensuring you fixed what went wrong. That assumption is no longer valid. On 31 […]


