What was reported
According to figures reported by MyBroadband following a briefing by the Information Regulator of South Africa, the regulator has recorded more than 8,000 cybersecurity breaches since it began operating. In the five months from 1 April 2026 it received 1,220 breach notifications, and it indicated that if that rate continues the country would pass 3,000 reported breaches for the year.
8,000+
Cybersecurity breaches recorded by the Information Regulator since inception
1,220
Breach notifications received in the five months from 1 April 2026
3,000+
Reported breaches projected for 2026 if the current rate continues
The regulator also made a point that matters more than any of those figures: a significant number of breaches are never reported to it at all. The 8,000 is therefore not a measurement of how much is happening. It is a measurement of how much has been disclosed, which is a different and considerably smaller thing.
That distinction is the reason this is worth writing about. An organisation benchmarking itself against the reported numbers is benchmarking against an undercount, and the gap between the two is made up of incidents that were absorbed quietly — or never detected in the first place. Detection, not disclosure, is where most of the missing volume lives.
Why this matters beyond the IT department
A serious compromise stopped being a technology problem some time ago. It is now an operational one, because the systems attacked are the systems the business runs on. When identity is compromised, email, files, finance systems and cloud services are all reachable through the same door. When endpoints are encrypted, the question is not what was lost but how long the organisation can trade without it.
That is the framing an executive team needs. Not the malware family or the CVE number, but which business processes stop, for how long, and what has to be told to whom.
The real cost of a breach
The information itself is rarely the whole loss. Four consequences turn up consistently, and they compound:
Operational disruption
Systems become unavailable, and employees and customers lose access to the services they depend on. Recovery time, not data volume, is usually what determines the commercial damage.
Data exposure
Personal, financial, employee and customer information may be exposed or removed from the environment. Unlike an outage, this cannot be undone once it has happened.
Regulatory exposure
Organisations processing personal information carry obligations under POPIA, including putting appropriate security safeguards in place and notifying the regulator and affected people where required.
Reputational damage
Customers, employees and partners hand over information on the assumption it will be looked after. That assumption is difficult to rebuild once it has been publicly tested.
The SABS enforcement notice, and what it signals
The same reporting covers the Information Regulator's enforcement notice against the South African Bureau of Standards, following the ransomware attack that made its ICT systems inaccessible and forced it to process salaries manually. According to the report, the notice identified shortcomings including inadequate security safeguards, known vulnerabilities that had not been addressed, the absence of an incident response plan, and issues with how personal information was collected and processed.
We would not read that as a story about one organisation. Read it as a list of what a regulator looks at after an incident — and note how little of it concerns the attack itself. Most of those findings describe conditions that existed beforehand and would have been visible to anyone who went looking. That is the uncomfortable part, and it is also the encouraging part, because conditions that can be found in advance can be fixed in advance.
Security is a system, not a product
The instinctive response to a breach headline is procurement. A firewall is renewed, endpoint protection is upgraded, a Microsoft 365 security tier is added, backup software is replaced. None of that is wrong, and none of it is sufficient, because the strength of an environment is determined by how its layers are configured and maintained rather than by which products appear on the invoice.
A firewall with permissive rules nobody has reviewed, endpoint protection reporting to a console nobody watches, and a backup job that has never been restored from are all products that were bought correctly and are protecting nothing. Every layer below depends on the one above it being sound:
- IdentityWho can sign in, from where, and with what additional proof.
- EndpointWhat the device is running, whether it is patched, and what it is allowed to execute.
- EmailThe route most attacks still arrive by — filtering, authentication and user reporting.
- NetworkSegmentation, firewall policy and what is deliberately reachable from outside.
- CloudTenant configuration, privileged roles and the settings that were left at default.
- DataWhat is held, where it lives, who may reach it and how long it is kept.
- Backup & recoveryImmutable copies, separated credentials, and a restore that has been tested.
- Monitoring & responseSomeone seeing the alert, and a defined action when they do.
Each layer is worth investment. None of them substitutes for another, and a weakness in identity is not compensated for by strength in backup — it simply changes which stage of the incident goes badly.
Eight questions every organisation should be asking
These are the questions we work through in an assessment. They are deliberately answerable — if any one of them produces a pause rather than an answer, that is the finding:
Do we know what we are protecting?
An accurate inventory of systems, applications, users and critical data. Controls cannot be applied consistently to an estate nobody has mapped.
Is MFA enforced where it matters?
Privileged accounts, cloud services, remote access and sensitive applications first — not only the executive team.
Are our systems patched?
Known vulnerabilities identified, prioritised by exposure rather than score alone, remediated and then verified.
Can we detect suspicious activity?
Logging that reaches somewhere, alerting somebody watches, and an escalation path that works outside office hours.
Are our backups actually recoverable?
A successful backup job is not evidence of anything. A completed restore test, with the time it took recorded, is.
Do users know how to recognise an attack?
Phishing, credential theft and social engineering remain among the most reliable entry points, and they target people rather than systems.
Do we have an incident response plan?
Who decides, who investigates, who communicates, and how systems are isolated — agreed before it is needed, not drafted during.
When did we last test our security?
Controls should be reviewed and exercised. A control assumed to be working and a control shown to be working are not the same control.
Cyber resilience checklist
- Multi-factor authentication enabled on privileged accounts and remote access
- Privileged access reviewed and separated from day-to-day accounts
- Security patches current across servers, endpoints, network devices and firewalls
- Endpoint protection deployed and actively monitored
- Email security configured, including authentication records
- Firewall policies reviewed against what is genuinely required
- Backups monitored, with failures raising an alert
- Recovery tested end to end, with the elapsed time recorded
- Security awareness training running and current
- Incident response plan documented, with named roles
- Security logs collected, retained and monitored
- Critical data identified, classified and its retention agreed
Building cyber resilience
Effective cybersecurity starts with understanding the environment, identifying which risks genuinely matter to this organisation, and putting proportionate controls around people, identities, endpoints, networks, applications and data. It is ongoing operational work, and it is measured by whether controls hold when tested rather than by how much was spent.
Define IT helps organisations assess where they currently stand, strengthen the layers that need it most, and keep those controls maintained as part of a broader technology strategy — across cybersecurity, managed services, backup and recovery, and the infrastructure underneath all of it.
The organisations that come through an incident well are rarely the ones that bought the most security. They are the ones that knew what they had, watched it, and had practised getting it back.
Key takeaways
- The reported total is a disclosure figure, not an incident figure — the regulator states many breaches are never reported at all.
- Frame breach risk in business terms: which processes stop, for how long, and what must be disclosed to whom.
- Most post-incident regulatory findings describe conditions that existed beforehand, which means they can be found and fixed beforehand.
- Security strength comes from how layers are configured and maintained, not from the number of products deployed.
- Treat a completed restore test, not a successful backup job, as the evidence that recovery works.



