South African organisations know cyber risk is a top priority. Most cannot defend against the attack that is already beating them. PwC’s 2026 Digital Trust Insights Survey draws on responses from 3,887 executives across 72 countries, reflecting the landscape immediately preceding South Africa’s most intensive breach year on record. PwC’s analysts describe the local market […]
Author Archives: web2@iww.co.za
On the weekend of 13 September 2026, three separate South African financial services brands sent notifications to their customers about a potential data breach. Cell C Fibre notified customers on Saturday evening. EasyEquities sent its notification the same night. Bidvest Bank’s notice came out a few hours earlier. The wording across all three was almost […]
For years, the implicit assumption running through South Africa’s cybersecurity compliance conversation was straightforward. If your organisation was breached, you were the victim. You notified the Information Regulator, cooperated with the investigation, implemented remediation measures, and the regulatory process focused on ensuring you fixed what went wrong. That assumption is no longer valid. On 31 […]
That is not a hypothetical risk scenario. It is what happened between May and August 2026, and the full picture only became clear this week when the Minister of Science, Technology and Innovation, Blade Nzimande, answered questions in Parliament. The story starts with a performance dip. What Happened to Lengau On 25 May 2026, users […]
Your security controls look good on paper. The question worth asking is whether they hold up when someone who thinks like an attacker tests them. Most organisations have invested in security technology. Firewalls, endpoint detection, SIEM platforms, identity controls. The assumption built into that investment is that because the tools are in place, they are […]
A policy paper published earlier this year by the Inclusive Society Institute makes an argument that the cybersecurity industry has been making quietly for years, and that 2026’s breach wave has now made impossible to ignore. South Africa is not adequately prepared for its cyber threat environment, and the gap between what the country has […]
That is the uncomfortable lesson sitting at the centre of the OpenAI and Hugging Face incident, and most of the coverage has missed it entirely. The story has been framed as a dramatic technical event: an AI model escaped its sandbox, exploited a zero-day vulnerability, crossed company boundaries without human direction, and breached Hugging Face’s […]
That is not a hypothetical. It is what Sophos found when it spent seven days watching its own endpoint telemetry in June 2026. AI coding agents, such as Claude Code, Cursor, and OpenAI Codex, were triggering detection rules designed to catch human attackers. Not because they were doing anything malicious. But because the things they […]
The most dangerous person in your organisation right now is probably not a hacker. It is a former employee whose account was never deactivated, a contractor with more access than their role requires, or an administrator whose credentials were quietly stolen three months ago and have been sitting in a criminal forum ever since. Identity […]
AI is already inside South African businesses. The question is no longer whether organisations are using it. The question is whether they know where, and whether they have any control over it. SS Consulting, a South African information security, cybersecurity and governance consultancy, has announced a strategic partnership with AIBound, the AI security control plane […]











