The 6% Blind Spot: Why South Africa’s Cybersecurity Strategy Is Looking Backward

South African organisations know cyber risk is a top priority. Most cannot defend against the attack that is already beating them.

PwC’s 2026 Digital Trust Insights Survey draws on responses from 3,887 executives across 72 countries, reflecting the landscape immediately preceding South Africa’s most intensive breach year on record. PwC’s analysts describe the local market as ambitious yet uneven in maturity.

That description is generous. The data tells a more uncomfortable story.

1. The Priority-Capability Paradox

  • 63% of South African leaders rank cyber risk investment in their top three strategic priorities (above the 60% global and 62% Africa averages).
  • Only 6% feel very capable against supply chain vulnerabilities (compared to 43% globally and 48% across Africa).

That gap between a top strategic priority and catastrophic vulnerability is the survey’s most important number. And 2026’s major incidents have made it painfully public.

What 6% Means in Practice

Supply chain attacks bypass direct perimeters to target the vendors, managed service providers, and third-party integrations trusted with your data. When attackers exploit those relationships, internal defences become irrelevant.

South Africa lived this reality in 2026:

  • January: The Land Bank was breached.
  • March: Liberty compromised via third-party access.
  • August: Cartrack hit by Dire Wolf ransomware.
  • September: A single breach at compliance platform RelyComply triggered simultaneous notifications at Cell C, EasyEquities, Satrix, Bidvest Bank, and Peregrine Capital.

Five organisations notifying customers in one week because of a single shared vendor is not an isolated incident. It is the pattern PwC’s data flagged months in advance. The 94% of organisations that feel unequipped are operating directly in the crosshairs of this exact threat vector.

The Budget Misalignment Trap

The survey reveals that only 28% of South African organisations spend significantly more on proactive security than reactive measures (recovery, fines, and incident response). Globally, that figure is 70%.

You cannot respond your way out of a third-party breach. By the time a vendor notifies you of a compromise, the reactive phase has already begun. South Africa is heavily funding the wrong side of the ledger. As Craig Rosewarne, MD of Wolfpack Information Risk, noted regarding RelyComply: an organisation’s security perimeter is only as resilient as its least secure integrated vendor.

Overlooking the Geopolitical Shift

While 63% of local leaders cite geopolitical uncertainty as an investment driver, few understand how it translates into exposure.

We saw this in May 2026 when Nigerian hacktivist group #OpSouthAfrica targeted government entities (including the Civil Aviation Authority, SANSA, and SASSA) in retaliation for xenophobic violence. This was politically motivated, completely missing from risk registers built around financial criminals. Vendor relationships established in a stable context years ago may now carry entirely different risk profiles.

The AI Accelerant

AI is a double-edged sword. Attackers use it to automate reconnaissance and scale phishing, while defenders use it for behavioral anomaly detection and threat automation. Local organisations moving fast on AI-driven defense are pulling away from peers still treating AI as a future roadmap item.

While South Africa’s cybersecurity market is projected to grow from USD 0.33 billion in 2026 to USD 0.59 billion by 2031 (reflecting a 12.71% CAGR), money alone won’t close the gap.

The Work Ahead

PwC South Africa’s Cybersecurity and Forensics Technology Solutions Leader, Junaid Amra, notes that aligning cybersecurity with business objectives is now critical.

The organisations escaping 2026 without headline breaches won’t necessarily be those with the biggest budgets. Several companies that leaked data this year had heavy security investments in place. What they lacked was governance and verification discipline.

Securing the supply chain is not a technology problem. It is a governance problem. It demands:

  • Continuous vendor control verification, not just onboarding questionnaires.
  • Contracts enforcing strict breach notification timelines and minimum control standards.
  • Board-level risk visibility that maps third-party exposure alongside internal posture.

Six percent of South African organisations feel capable against the attack vector defining 2026. Closing that gap is the definitive test for leadership teams for the rest of the year.

What Is Your Organisation Doing Today?

Are your third-party vendor assessments robust enough to keep you out of next week’s breach notifications, or are you relying on outdated onboarding questionnaires? Audit your supply chain risk posture now, or schedule a consultation with our risk advisory team to close your 6% capability gap before the next incident hits.