South Africa Is Not a Soft Target. It Is a Perfect One. There Is a Difference.

The dominant narrative around South Africa’s cybersecurity crisis frames the country as vulnerable. Underprepared. Behind the curve. A passive recipient of attacks it cannot defend against.

Yugan Reddy, CEO of iGuardSA and an SS-Consulting partner, offered a different, more precise frame at GovTech 2026 last week. iGuardSA was the first company SITA called when the GPAA breach was discovered in 2024, and Reddy has since become one of the most credible practitioner voices on the state of South Africa’s public sector cyber defences.

“We actually have some pretty good infrastructure. Our comms infrastructure is decent. We’ve developed a lot of our systems, and the data is readily available through them. So, what happens is we become a nice sort of testing ground for the cybercriminals.”

He corrected himself immediately. Because over the past five years, attackers stopped treating South Africa as a testing ground and started treating it as a primary target. The distinction matters.

“We’ve got established infrastructure, everything’s connected, but it’s not protected. In a first-world country, everything’s connected but protected. We are just nicely in between for them. So we make things a lot easier for them.”

That observation reframes the entire conversation. South Africa is not being attacked because it is weak. It is being attacked because it is valuable, connected and inadequately defended. That combination is not the profile of a country that hackers overlook. It is precisely the profile they look for.

What the GPAA saga teaches us.

The GPAA breach in February 2024 remains the most instructive case study in South African public sector cybersecurity. LockBit 3.0 breached the Windows environment of the agency that administers the Government Employees’ Pension Fund, the largest pension fund on the continent, managing R2.38 trillion in assets for 1.7 million active members, through unpatched perimeter vulnerabilities or compromised credentials.

The GEPF initially denied the breach, publicly stating an attempted intrusion had occurred and assuring the public no data was compromised. Then LockBit published a 668-gigabyte archive containing records of 168,000 data subjects on its dark web leak site. The GEPF finally admitted the breach, confirming the GPAA had misinformed it. The complete infrastructure shutdown persisted until 21 June 2024, a total system rebuild that took months. New retirements, resignations and death benefits had to be processed manually during that period.

This happened two months before the two-pot withdrawal system went live on 1 September 2024, when 361,000 members withdrew R4.1 billion in rapid liquidity, placing further pressure on an administration already rebuilding from the ground up.

Finance Minister Enoch Godongwana dismissed GPAA CEO Kedibone Madiehe after a disciplinary hearing this month. That consequence is significant. It establishes that a cyber incident at a government entity can and will result in executive accountability at the highest level. Even President Ramaphosa’s personal details were counted among the credentials stolen in the breach.

But the dismissal, while appropriate, addresses the consequence of the failure rather than the conditions that made it possible. And those conditions, Reddy made clear at GovTech 2026, remain largely unchanged across South Africa’s public sector.

The budget gap that no governance framework closes.

Corporate entities in South Africa allocate approximately 15% of IT budgets to cybersecurity. Government bodies allocate less than 5%.

That gap is not simply a funding problem. It is a prioritisation signal. It reflects a structural assumption, embedded in how public sector IT budgets are built and approved, that cybersecurity is a cost rather than an investment, a compliance obligation rather than an operational imperative.

The consequences of that assumption are visible in the GPAA incident, in the Stats SA breach, in the Gauteng Provincial Government’s network where 70% of devices had passed end-of-service, in the Lengau supercomputer breach where a decade-old system with no disaster recovery plan was running South Africa’s most sensitive scientific research infrastructure.

Reddy also flagged something that sits beneath the budget conversation. Government agencies rely on systems and applications built 20 to 30 years ago, and inexperienced young engineers are tasked with maintaining legacy environments they have never encountered before. The knowledge gap compounds the budget gap. You cannot patch what you do not understand, and you cannot defend an architecture that was designed before the current threat landscape existed.

The sovereignty conversation is happening in the wrong order.

The loudest conversation at GovTech 2026 was about digital sovereignty. Communications Minister Solly Malatsi delivered a speech on the National Digital Sovereignty Agenda. The government preaches data localisation, reduced dependency on foreign technology providers and the cultivation of local capability.

Reddy’s assessment of that conversation was direct. While the state preaches digital sovereignty on the GovTech stage, it routinely outsources security to foreign OEMs and cloud vendors rather than investing in and cultivating local cybersecurity talent.

He described the gap plainly. The government lacks basic policies, including AI usage policies, the enforcement tools, the capacity, and the skilled personnel within security organs like the State Security Agency to enforce controls.

This is the cart-before-the-horse problem that no amount of sovereignty rhetoric resolves. Digital sovereignty without cybersecurity is not sovereignty. It is exposure with a different name. You cannot claim ownership of your digital infrastructure if you cannot defend it, and you cannot defend it if the people responsible for it are working with tools, policies and budgets that were inadequate before the current threat environment arrived.

Communications Minister Malatsi has confirmed a new AI policy will be ready by March 2027. What he and SITA have been less forthcoming about is any statutory mandate requiring state agencies to allocate at least 10 to 15% of IT budgets specifically to cybersecurity. The policy is coming. The funding discipline that would make it actionable is not yet on the table.

What AI has done to the calculus.

Reddy did not mince his words when Daily Maverick asked about AI’s impact on the cybersecurity industry.

“It’s a nightmare for us. And if we’re having sleepless nights about it, everybody else out there should be shaking in their boots right now.”

Threat actors are using automated AI discovery tools to scan for zero-day vulnerabilities and build functional exploits within seconds. The defender advantage that patching once provided, closing a known vulnerability before an attacker could exploit it, is narrowing to the point of disappearing. Defenders have near-zero lead time against never-before-seen vectors built and deployed at machine speed.

There is also the growing concern of unregulated employees feeding sensitive corporate and state data into public large language models because no operating policy exists to prevent it. This is not a hypothetical. It is happening daily across both private and public sector organisations that have deployed AI tools without establishing governance frameworks for how those tools interact with sensitive information.

The Sophos State of Ransomware South Africa 2026 report, published this month, provides the operational context for Reddy’s assessment. 47% of South African victims cited a complete lack of protection as their operational root cause, the highest proportion recorded across all 17 countries surveyed. 85% confirmed their ransomware breach was directly linked to their most significant identity compromise. Only 40% recovered within a week, the lowest rate of any country surveyed.

These are the numbers of an environment where fundamental baseline security controls and policies were never instituted. Not where they were in place and failed. Where they were never there to begin with. That is the environment AI-powered attackers are now operating in.

What the private sector cannot afford to take from this conversation.

The GovTech 2026 conversation and Reddy’s assessment are framed around the public sector. That framing is accurate but incomplete.

The conditions he describes, legacy infrastructure, inadequate budgets, skills gaps, absent policies, uncontrolled AI usage, are present across South Africa’s private sector too, in varying degrees and in different combinations. The September 2026 incidents, Cartrack, RelyComply triggering notifications at five financial services organisations, Serengeti Estates, Toyota South Africa, do not all trace back to government inadequacy.

They trace back to the same structural pattern Reddy identified. Connected. Developed. Not protected.

South Africa’s private sector organisations that have not formally audited their own version of the conditions Reddy describes are carrying risk that the current threat environment will eventually find. The infrastructure is valuable. The data is accessible. And the combination of AI-powered attackers with automated discovery tools and a target environment where baseline controls are inconsistently applied is precisely the dynamic that produced 2026’s breach record.

The government’s cybersecurity crisis is the most visible manifestation of a national condition. It is not the only one.

SS-Consulting, in partnership with iGuardSA, works with South African organisations across the public and private sector to build the security foundations, governance frameworks and operational disciplines that the current threat environment demands.