A policy paper published earlier this year by the Inclusive Society Institute makes an argument that the cybersecurity industry has been making quietly for years, and that 2026’s breach wave has now made impossible to ignore. South Africa is not adequately prepared for its cyber threat environment, and the gap between what the country has and what it needs is significant enough to constitute a national crisis.
The paper, authored by Lars Gumede and titled “Securing the Future: Blueprint for Solving South Africa’s Cybersecurity Crisis in the Age of AI,” is worth reading in full. Its diagnosis is accurate. South Africa ranks as the third-highest country globally in terms of cybercrime victims, with nearly 600 cyberattacks launched every hour at South African businesses, government and civic organisations. The country loses roughly R2.2 billion annually due to cyberattacks, and over half of all South African companies are victims of ransomware each year.
Its prescription is also broadly correct. A dedicated, politically independent national cybersecurity organisation. A national public awareness campaign addressing the human layer. A structured programme for developing the next generation of cyber talent.
These are the right recommendations. They are also, realistically, years away from implementation in any meaningful form.
That gap is what this blog is about.
The paper is right about the structural problem. It is less useful about the immediate one.
The paper notes that South Africa’s Cybersecurity Hub, which serves as the country’s Computer Security Incident Response Team, has recorded just 544 police cases against a backdrop of over 100,000 banking-related cyberattacks annually, an 86% increase year on year.
That statistic captures the enforcement gap precisely. But it does not help the financial institution, the healthcare provider, the government department or the manufacturing company that is facing an active threat environment today, before any of the paper’s structural recommendations can be implemented.
The paper acknowledges that 88% of South African organisations face between one and five cyber incidents each year and that the average cost of a single large data breach is R53.1 million. These are not future projections. They are the current operational reality of doing business in South Africa.
Waiting for a national cybersecurity strategy to materialise is not a risk management position. It is an exposure.
What the paper gets exactly right, and why it matters for the private sector.
The paper’s most important insight is one that the private sector consistently underestimates.
The weakest link in any cyber system is the human element. Most cyber incidents rely on an unsuspecting individual to click on a link or compromise themselves in some way. Cybersecurity has a PICNIC problem: Problem In Chair, Not In Computer.
This is not a new observation. It is, however, a consistently underacted-upon one. Every major breach we have analysed from South Africa’s 2026 incident record involved a human decision, a trusted relationship, a dormant account that nobody deprovisioned, or a process that existed on paper but was never tested in practice.
The paper cites a survey finding that 80% of IT executives interviewed said they were most confident they could not fall for any kind of phishing attack. However, when tested, 64% of them clicked on a malicious phishing link disguised as a friendly one.
That 64-percentage-point gap between confidence and behaviour is the attack surface that most South African organisations are not measuring, not testing and not closing. A staff awareness programme that runs once a year and produces a completion certificate is not a defence against that gap. It is documentation of it.
What the paper does not address, and what organisations need to do now.
The paper makes a compelling case for systemic national intervention. What it does not provide is a framework for what organisations do while they wait for that intervention to materialise. That is understandable for a policy paper. It is not acceptable as an organisational posture.
South Africa’s breach record in 2026 has demonstrated, repeatedly and expensively, that the organisations suffering the most significant consequences share common characteristics. They are not the ones facing the most sophisticated attackers. They are the ones with the largest gap between their assumed security posture and their actual one.
The Gauteng Provincial Government was not breached through an advanced persistent threat operation. It was accessed because attackers exploited poor infrastructure and outdated systems, the same pattern Interpol identifies as the primary enabler of cybercrime across the African continent. Seventy percent of the provincial government’s network devices had passed their end-of-service date. The entry point was an internet-facing server that had not been secured.
Stats SA had an HR portal connected to infrastructure that should have been isolated. Polmed’s breach entered through a dormant account that had not been used since 2019 but still held domain-admin rights. Standard Bank’s attacker spent three weeks moving laterally through internal systems before anyone noticed.
None of these required a nation-state threat actor or a zero-day exploit. They required patience and the reasonable expectation that the basics would be neglected.
The three things the paper recommends at a national level are the same three things every organisation needs to implement internally right now.
The paper recommends a dedicated national cybersecurity organisation. At an organisational level, the equivalent is a clearly defined security governance structure with board-level accountability, not a security team that reports to IT and whose concerns are filtered before they reach leadership. The organisations that have navigated 2026’s threat environment most effectively are the ones where the security function has direct access to leadership and where cyber risk is discussed at the same level as financial and operational risk.
The paper recommends a national public awareness campaign. At an organisational level, the equivalent is a security awareness programme that is current, tested and ongoing, not a compliance exercise that runs in February and is not revisited until the following year. The 64% click rate among IT executives who believed they were immune to phishing is a number every South African board should see before approving next year’s security budget.
The paper recommends a national talent pipeline. At an organisational level, the equivalent is investing in the development of your existing security team rather than waiting for the talent market to improve. South Africa faces a documented shortage of cybersecurity professionals, and 71% of cyber leaders believe that small organisations have reached a critical tipping point in being unable to secure themselves against growing cyber threats. Organisations that cannot recruit their way out of the skills gap need to build, train and retain the talent they already have, or partner with specialists who provide the capability they cannot build internally.
The national strategy matters. It is not sufficient.
The Inclusive Society Institute’s paper is a valuable contribution to a conversation South Africa needs to have urgently at a policy level. The recommendations are grounded, internationally benchmarked and practically achievable if there is political will to pursue them.
But organisational cybersecurity cannot wait for political will to translate into institutional capacity. The breaches of 2026 have made clear that the organisations paying the heaviest price are not the ones facing the most advanced threats. They are the ones that treated systemic national vulnerability as someone else’s problem to solve.
A single cyberattack could descend the country into total anarchy in less than a week. That is the paper’s most striking claim, and it is made not for dramatic effect but as a genuine assessment of what South Africa’s dependency on cyber systems means in the context of its current defensive posture.
The urgency the paper applies to the national conversation belongs equally in every boardroom, every security review and every budget cycle across South Africa’s public and private sector.
The national strategy is coming. It needs to come faster. And in the meantime, the organisations that will emerge from 2026 intact are the ones that did not wait for it.
SS-Consulting provides cybersecurity, governance, risk and compliance advisory services to South African organisations across the public and private sector. We help organisations close the gap between their assumed security posture and their actual one, before the gap is found by someone else. www.ss-consulting.co.za

