Position Paper
A proposal for incentives based governance model for South Africa's Cybersecurity crisis
South Africa faces a cybersecurity crisis. This contribution examines that crisis through the lens of the incentive structures driving it. It proposes an incentive-based governace model which would require suppliers bidding for government tenders to hold minimum cybersecurity certification or controls, depending the size of the enterprise and value of the tender. This would leverage the size of government's own contracting and purchasing power to incentivise suppliers to invest in cybersecurity.
Open article contents
Introduction
South Africa has become the epicentre for cybercriminals. According to Interpol's African Cyberthreat Assessment Report 2026, and drawing on operational data from 36 African countries, South Africa has “transformed from an opportunistic target into a major hub for high-impact, industrialised digital attacks.”1 The numbers are stark. South Africa accounts for 92% of all ransomware detections recorded across Africa, 70% of business email compromise incidents, 43.6% of the continent's identified exploitable vulnerabilities, close to 40% of phishing detections, and 30% of sextortion-related detections.2 In the second half of 2025 alone, the country recorded 213,523 distributed denial-of-service attacks, including a single incident that peaked at 312 gigabits per second.3
This is not a new trend. In fact it is old news. In 2023, the Council for Scientific and Industrial Research (CSIR) ranked South Africa sixth in the world for cybercrime density and eighth globally as a ransomware target, estimating the annual cost to the economy at R2.2 billion.4 By 2025, that same R2.2 billion figure was still being cited, alongside a new data point that the South African government infrastructure alone faces an estimated 3,312 cyberattacks every week.5 As one commentator put it, “[b]eing at the forefront of the continent's digital transformation and having a relatively strong economy puts South Africa in the crosshairs for sophisticated cyber-attacks… Given the economic status of the country, they are also likely to be able to pay ransoms and meet demands.”6
This sets clear incentives on both sides of the field, and they compound rather than offset. On the demand side, attackers select South Africa precisely because its relative economic strength means ransoms get paid, its deep digital integration, and highly connected and banked population, means disruption has real leverage. This sets clear incentives for threat actors. On the enforcement side, the risk of getting caught remains very low. Neither the South African Police Service nor the National Prosecuting Authority are sufficiently resourced and capacitated to catch the threat actors. Reporting to the police is widely acknowledged to be sparse because victims doubt SAPS's technical capacity to act on a complaint.7
Check Point Research separately found South African companies facing 2,113 cyber security threats a week, a volume that dwarfs the incident counts actually making their way to any enforcement authority.8 Put simply, the South African landscape presents a high reward for threat actors, with a low probability of consequence, thereby creating an asymmetric incentive structure that incentivises behaviour and conduct that is not desirable. This same theme of asymmetry, high reward set against low probability of consequence, recurs at every level explored here.
A closer look at the crisis
A. Critical infrastructure becomes a target
Interpol's 2026 assessment notes that ransomware operations against South African organisations have moved “from simple financial extortion toward systemic infrastructure disruption.”9 For example, the South African Weather Service was disrupted by a ransomware-as-a-service attack in January 2025, damaging meteorological data systems and delaying aviation routing and maritime navigation, an incident Interpol places alongside attacks on South African Airways and Namibia's Paratus Telecom as evidence of a regional pattern targeting critical infrastructure specifically.10
This is consistent with the trajectory since the 2021 attack on Transnet, the state-owned rail, port and pipeline operator, which caused significant transport disruption and economic harm.11 A peer-reviewed case study of that incident concluded that “cybersecurity policy needs to be a core dimension of contemporary South African socioeconomic development policy,” and that failing to act against rising cyber-threats “constitutes a substantial risk to the functioning of the South African market.”12
Since then, the list of affected public entities has grown: the National Health Laboratory Service lost 1.2 terabytes of data and had its backups deleted mid-outbreak in 2024;13 the Department of Justice and Constitutional Development had case files, bail services and deceased-estate systems disrupted in 2021;14 the Department of Public Works and Infrastructure disclosed an insider-driven cyber heist totalling an estimated R300 million over roughly a decade;15 and in 2025 the National Treasury discovered malware on its Infrastructure Reporting Model system.16 The State Security Agency, responding to a parliamentary question, has confirmed that threats to the country's critical information infrastructure “will continue to rise,” attributing this partly to South Africa's own advanced communications infrastructure and international standing.17
B. Digital privacy is the second casualty
Cybersecurity failure is also a matter of data rights. The Information Regulator reported that, since April 2025, organisations notified it of 1,947 data compromises, averaging 284 notifications a month and representing a 40% year-on-year increase.18 Keep in mind most incidents go unreported as “only a fraction of incidents gets reported to the regulator,” a gap supported by Check Point Research's finding that South African companies face over 2,000 cybersecurity threats a week, several multiples of what the Regulator's notification figures capture.19 In response, the Regulator “calls on both the public and private sectors to make the requisite investments into developing and maintaining appropriate technical and organisational measures to secure the integrity and confidentiality of personal information in their possession.”20 This call echoes the logic of POPIA: private and public organisations are asked, almost politely, to put basic cybersecurity measures in place, with very little capacity for enforcement.
Poor enforcement undermines the penalty approach
Of course, some enforcement has followed, though limited and uneven. The Regulator has issued administrative fines of R5 million against the Department of Basic Education, R5 million against the Department of Justice and Constitutional Development, R500,000 against Blouberg Municipality, and R100,000 each against Lancet Laboratories and FT Rams Consulting.21 This enforcement record must be read against the Regulator's own institutional resourcing. On paper, it is legally positioned for a very large role. It bears the sole enforcement authority for POPIA and PAIA, across every public and private body in the country, with powers to investigate, issue enforcement notices and impose administrative fines.
This is a rather extensive mandate; however, its budget for that mandate was R110.86 million in the 2024/25 financial year, up marginally from R107.95 million the year before, rising to roughly R135 to R136 million for 2025/26.22 Around 70% of that is consumed by staff compensation, leaving a comparatively small residual for investigations, technical capacity and ICT infrastructure. Moreover, the Regulator has openly conceded it cannot compete with private-sector salaries for the data privacy and cybersecurity skills its own mandate require, describing itself as effectively “a training ground” whose best staff are routinely recruited away.23 Seen through the lens of incentive structures, the Regulator is effectively in the position of having to ask organisations to self-report data breaches and invest in cybersecurity measures, while itself lacking the capacity to investigate more than a fraction of what is reported.
At the same time, the fines imposed (R100,000 to R5 million) actually remain small enough that for many organisations, they can simply be absorbed as another cost of doing business. In such a scenario, the poor enforcement actually incentivises corporate underinvestment in cybersecurity, which, in the circumstances, remains the economically rational choice. For the organisation deciding whether to spend on prevention, this is the identical asymmetry described at the outset of this article, relocated from the criminal law to the data protection regime, and it is precisely what the recommendation below is designed to correct.
The same enforcement gap that weakens POPIA also runs through the Cybercrimes Act on its criminal justice side. Section 55 of the Act requires the Minister of Police to establish and maintain sufficient human and operational capacity within SAPS to detect, prevent and investigate cybercrime, yet more than five years after the Act came into force, capacity levels are still lagging, to put it mildly. Cybercrime capacity within Detective Services numbered 86 members against a shortfall of 152.24 A Department of Justice official has separately acknowledged that, notwithstanding the Act’s quality as legislation, “the problem comes with the enforcement,” attributing this to “the absolute shortage of skills in South Africa to enforce this legislation.”25
The consequence shows up at the prosecution stage, where the picture is stark. Reporting in December 2024 found that of 2,679 cybercrimes recorded by SAPS over a two-year period, only 83 cases were referred on to the NPA for prosecution.26 That funnel, from tens of thousands of estimated weekly threats, to a few thousand recorded cases, to a low double-digit referral rate, means the deterrent effect the Cybercrimes Act is meant to provide is largely ineffective without enforcement. If the prosecuting authority cannot convert investigation into conviction at any meaningful rate, the offender weighing whether to strike faces no credible probability of consequence, reproducing the same calculus already described for the private sector and the data protection regime: attractive reward, negligible risk of being caught.27
Current approach: Strong on cybercrimes & penalties, limited on cybersecurity & incentives
South Africa's Cybercrimes Act is widely regarded internationally as strong legislation.28 Yet, as cybersecurity practitioner Jacqueline Fick has argued, legislation alone does not constitute governance: a strong statute book does not by itself supply the national strategy, resourcing and institutional coordination needed to act on it.29 Distinguishing cybercrime from cybersecurity clarifies why. The former is a criminal law matter of penalties; conduct defined and prosecuted as a criminal offence after the fact. This is what South Africa's Cybercrimes Act is built to address: unlawful access, interception and so on, with mechanisms for investigation and prosecution.
Cybersecurity, on the other hand, is a governance category which entails the proactive, systemic, forward-looking capacity of institutions, public and private, to prevent, withstand and recover from attacks (See POPIA's 7th Condition on security measures). South Africa has comparatively strong (although dated) cybercrime law, and yet it applies the same penalties-based approach to motivate organisations to invest in cybersecurity as well, on the assumption that the threat of an administrative penalty can be sufficient motivation for the proactive, forward-looking capacity of institutions to prevent, withstand and recover from attacks.
The National Cybersecurity Policy Framework, approved by Cabinet in December 2013, predates the Cybercrimes Act and the advent of Ai tools by close to a decade, with significant gaps in scope, costing and implementation timeframes relative to the national critical information infrastructure it is meant to protect.30 The result is a national approach that effectively criminalises cyber-harm (although with structurally deficient enforcement capacity), while lacking an effective strategy to incentivise organisations to proactively invest in minimum cybersecurity controls.
This diagnosis is echoed at the policy-analysis level. Carnegie Endowment researchers Russell Buchan and Joe Devanny, in a dedicated 2024 assessment of South Africa's cyber strategy, concluded that cybersecurity has remained a comparatively low government priority despite public commitments to address it, with implementation lagging well behind the country's exposure.31 Interpol's own 2026 findings reinforce the point at a regional level, noting that Southern Africa has “the most mature regulatory frameworks” on the continent, yet “the region's institutions remain vulnerable to the speed and scale of AI-enabled attacks.”32
The uncertain prospect of administrative fines or criminal santions without an accompanying enforecement capacity, is proving ineffective as a governance strategy capable to meeting the current cybercrisis. Pending review of the present approach, the governant has an oppotunity for an additional lever to encourage or incentivise the intended behaviour, which ultimately is for organisations in the South African market to make cybersecurity investments.
Where penalties & their enforcement are ineffective, try an incentive-based strategy
Rewards-driven frameworks have already demonstrated incentive-based governance strategies,not command alone, can sustain institutional cooperation and behaviour.35 South African private-sector practice already provides evidence for this proposition. Consider, for example, the ISO/IEC 27001 certification, which is increasingly becoming a baseline requirement for doing business for South African companies seeking to supply large corporate clients, multinationals and international partners.
These partners increasingly make ISO/IEC 27001 certification a precondition of onboarding and continued contracting with a supplier.36 Becasue the incentive is getting to do business with a large contracting party, South African companies pursuing that certification frequently commit to a security environment considerably more onerous than POPIA itself, because a commercial counterpart with purchasing power made it the price or condition of the contract.37 We think the logic generalises. A reward tied to something an organisation actually wants, access to a customer's business, appears capable of motivating security investment that an exclusively penalty-based framework has not.
The structural lack of enforement and the economic cost of making cybersecurity investment both give organisations incentive to delay or avoid implementing security controls. In any event, the cost of a breach or an enforcement penalty from the Information Regulator is uncertain and somewhere in the future, may never materialise for any given organisation and if it does, it can be absorbed in the busines model and insurance. A more effective governance framework, we think, would reverse that calculation, employing an additional compliance incentive to balance the regulatory penalty design.38
One approach is leveraging the size of government's own market in procurement to incentivise the desired behaviour. Government could require a demonstrable minimum standard of cybersecurity investment or certification as a condition of eligibility for public contracts and tenders, graduated according to the size of the enterprise and the value of the contract. The logic is that one cannot benefit from a government contract while simultaneously disregarding compliance on such a safety-critical matter of priority to that same government. The government already employs this logic elsewhere, for example requiring proof of tax compliance (formerly a tax clearance certificate, now a SARS Tax Compliance Status PIN) as a condition for a state contract, precisely to incentivise companies to pay their taxes.39
At present, a supplier bidding for a state tender has little incentive to prioritise cybersecurity spending, since the two issues are presently not tied together. Making public procurement conditional on verified minimum cybersecurity practice would nnot be without challenges, but could leverage the size of the state's own market to incentivise proactive cybersecurity investment as the commercially economic rational choice, which for many organisation it presently is not.
There is already precedent for precisely this approach of tying basic cybersecurity requirements to state contracts. Since 2014, the UK's Procurement Policy Note 014 (PPN 014) has required suppliers bidding for certain public contracts to hold Cyber Essentials or Cyber Essentials Plus certification, or demonstrate equivalent controls are in place, on a basis calibrated to the risk and sensitivity of the contract.40 In Canada's 2025 Program for Cyber Security Certification (CPCSC), certification is required only at contract award rather than during bidding, giving suppliers time to prepare.41 Canada explicitly designed its CPCSC to align technically with the US Cybersecurity Maturity Model Certification (CMMC), so that suppliers meeting one do not have to duplicate effort for the other, an interoperability feature worth noting.42
Each government has calibrated its certification system to the behaviour most important within its own procurement and threat context, rather than adopting a one-size-fits-all standard, mirroring evidence from other regulated infrastructure sectors that incentive-based regulatory design, rather than uniform rules, drives more effective technology modernisation and investment.43 Read together, organisational theory, the economics of penalty design and comparative infrastructure regulation converge on the same conclusion: incentives, not penalties alone, are what move institutions to invest ahead of harm.
At the same time, government procurement is a known site of corruption, and a new compliance gate will most certainly be a new point at which a tender could be manipulated. One remedy is to recognise as a starting point the SANAS-accredited SANS ISO/IEC 27001 certification, an existing, independently audited standard already gaining traction in South African commercial practice,44 as the evidentiary basis for meeting the minimum threshold, keeping the assessment in the hands of accredited third parties and mitigating the scope for the process to become a new site of corruption. In effect, the government would be adopting the same commercially rational strategic approach employed by commercial buyers with large purchasing power. Such a policy should also include a review after an initial period, so its effect on both cybersecurity outcomes and SME participation can be assessed and adjusted accordingly, with breach-notification rates among certified suppliers and tender participation rates by SME size band as plausible starting metrics for that review.
References
- ‘South Africa Named Africa’s Cybercrime Hotspot’ IOL (4 August 2026) View source, accessed 18 August 2026. ↩
- Interpol, African Cyberthreat Assessment Report 2026 (Interpol, August 2026) View report, accessed 18 August 2026. ↩
- ibid. ↩
- ‘Bleak Picture Painted as Cybercrime Costs SA R2.2 Billion Annually’ IOL (Pretoria, 6 April 2023) View source, accessed 18 August 2026. ↩
- ‘South Africa Under Attack’ MyBroadBand (28 July 2025) View source, accessed 18 August 2026. ↩
- ‘Held for Ransom: SA Top Target for Cyber Crime’ ESET Newsroom (24 March 2025) View source, accessed 18 August 2026. ↩
- Heloise Pieterse, ‘The Cyber Threat Landscape in South Africa: A 10-Year Review’ (2021) 28 African Journal of Information and Communication 1. ↩
- James Stark, ‘South African Businesses Hit by 2,113 Cyber Attacks a Week’ MyBroadBand (19 August 2025), reporting on Check Point Software Technologies, Global Threat Intelligence Report (July 2025) View source, accessed 19 August 2026. ↩
- (n 1). ↩
- (n 2). ↩
- Scott Timcke, Mark Gaffley and Andrew Rens, ‘The Centrality of Cybersecurity to Socioeconomic Development Policy: A Case Study of Cyber-Vulnerability at South Africa’s Transnet’ (2023) 32 African Journal of Information and Communication 1. ↩
- ibid. ↩
- (n 6). ↩
- ‘South Africa Under Attack’ MyBroadBand (3 February 2025) View source, accessed 18 August 2026. ↩
- ‘State Security Agency Unleashed on Mounting Cyber Crime’ ITWeb (17 July 2024) View source, accessed 18 August 2026. ↩
- (n 5). ↩
- Question to the Minister in the Presidency, NW1770, Parliamentary Monitoring Group View source, accessed 18 August 2026. ↩
- ‘SA Data Breaches Surge 40% as Regulator Warns of Cybersecurity Shortfalls’ The Citizen (13 November 2025) View source, accessed 18 August 2026. ↩
- (n 8). ↩
- ‘InfoReg Exposes POPIA Violators as Data Breaches Mount’ ITWeb (14 November 2025) View source, accessed 18 August 2026. ↩
- (n 20). ↩
- Information Regulator, Annual Report for the Year Ended 31 March 2025 (Information Regulator, 2025) View report, accessed 18 August 2026. ↩
- ‘InfoReg Accelerates Digital Projects Despite Budget Constraints’ ITWeb (12 March 2025) View source, accessed 18 August 2026. ↩
- ‘Question to the Minister of Police - NO413’ (Parliamentary Monitoring Group, 2024) View source, accessed 19 August 2026. ↩
- Elmarie Burger-Smidt quoted in ‘Top-Notch Cyber Crimes Act Ultimately Fails to Deliver’ ITWeb (2 June 2022) View source, accessed 19 August 2026. ↩
- Question to the Minister of Police, NW1543, Parliamentary Monitoring Group (2024) View source, accessed 19 August 2026, confirming 2,679 cybercrime cases reported and opened in the 2022/23 and 2023/24 financial years, with 33 and 50 cases respectively referred to the National Prosecuting Authority (83 in total); corroborated in Jan Gerber, ‘Capacity Crisis: SA Hit by 2 679 Cybercrimes in 2 Years, but Cops Referred Only 83 to NPA’ News24 (18 December 2024) View source, accessed 19 August 2026 (full analysis paywalled beyond the headline figures, which the parliamentary reply independently confirms). ↩
- (n 8). ↩
- Cybercrimes Act 19 of 2020 (South Africa). ↩
- Jacqueline Fick quoted in ‘Lack of National Cyber Security Strategy Puts SA at Risk’ ITWeb (6 June 2024) View source, accessed 18 August 2026. ↩
- Thuli Mkhwanazi and Lynn Futcher, ‘Strengthening South Africa’s Cybersecurity Strategy: Insights from a Thematic Analysis’ (IEEE, 2024) View source, accessed 18 August 2026. ↩
- Russell Buchan and Joe Devanny, South Africa’s Cyber Strategy Under Ramaphosa: Limited Progress, Low Priority (Carnegie Endowment for International Peace, January 2024). ↩
- (n 2). ↩
- African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) (adopted 27 June 2014, entered into force 8 June 2023). ↩
- (n 2). ↩
- Peter B Clark and James Q Wilson, ‘Incentive Systems: A Theory of Organizations’ (1961) 6(2) Administrative Science Quarterly 129 View source. ↩
- IT-Online, ‘ISO 27001 Is Becoming a Baseline Requirement for Doing Business’ (IT-Online, 19 June 2026) View source, accessed 19 August 2026. ↩
- CX Consulting, ‘Compliance Services’ (cxconsulting.co.za) View source, accessed 19 August 2026. ↩
- Kelly Kristen Lear and John W Maxwell, ‘The Impact of Industry Structure and Penalty Policies on Incentives for Compliance and Regulatory Enforcement’ (1998) 14 Journal of Regulatory Economics 127 View source. ↩
- Preferential Procurement Regulations, reg 16 (National Treasury) View source, accessed 19 August 2026; South African Revenue Service, ‘Government Connect Issue 5’ (SARS, August 2022) View source, accessed 19 August 2026. ↩
- UK Government, ‘PPN 014: Cyber Essentials Scheme’ (GOV.UK, 17 February 2025) View source, accessed 19 August 2026. ↩
- Public Services and Procurement Canada, ‘Program Overview’ (Canada.ca) View source, accessed 19 August 2026. ↩
- Public Services and Procurement Canada, ‘How to Meet Level 1 Cyber Security Certification Requirements’ (Canada.ca) View source, accessed 19 August 2026. ↩
- Shane Greenstein, Susan McMaster and Pablo T Spiller, ‘The Effect of Incentive Regulation on Infrastructure Modernization: Local Exchange Companies’ Deployment of Digital Technology’ (1995) 4(2) Journal of Economics & Management Strategy 187 View source. ↩
- SANS Standards South Africa, ‘Information Technology SANS Standards’ (sansstandards.co.za) View source, accessed 19 August 2026; IT-Online (n 36). ↩
Need support on cyber security governance?
TECHila Law helps organisations and public bodies assess cyber security governance exposure, align compliance programmes with the Cybercrimes Act and POPIA, and design practical, incentive-based responses to South Africa’s cybercrime crisis.