Cyber resilience for South African short-term insurance

The cyber-readiness framework purpose-built for SA brokers and UMAs

Provantis is anchored to FSCA / Prudential Authority Joint Standard 2 of 2024 (in force 1 June 2025). A 32-rule library across seven sub-domains, a 19-check automated trust score, a structured self-assessment with five maturity bands — and the differentiators an underwriter actually asks about.

Why this exists

Joint Standard 2 binds insurers. Intermediary requirements depend on role and contract.

Joint Standard 2 of 2024 took effect on 1 June 2025. It applies directly to the financial institutions defined in paragraph 2 — including insurers and insurance controlling companies, CIS managers, discretionary FSPs and administrative FSPs. A Category I FSP is included only where it provides investment fund administration services, so most independent non-life brokerages are not directly in scope in that capacity. Paragraphs 4.2.3, 7.2.3(a)(iii), 7.7.1(b) and 8.1.1(f) place third-party contracting, information protection, testing-assurance and access-control duties on the in-scope institution. An insurer may reflect those duties in a broker or UMA contract, but the standard does not itself make every intermediary directly subject to JS2. Provantis helps assemble readiness evidence for the requirements that apply to your entity and relationships; applicability remains for professional review.

The deadline has passed

JS2 of 2024 has been in force since 1 June 2025 for the institutions in its defined scope. Those institutions must be able to demonstrate the controls and oversight the standard requires.

It reaches you through your insurers

JS2 binds the institutions defined in paragraph 2 — insurers among them. Most independent non-life Category I brokerages are not directly in scope in that capacity, but insurer contracts and oversight may require evidence from a broker or UMA where the service and risk justify it.

The underwriter is asking

Insurance and due-diligence questionnaires may ask for documented control evidence. A structured pack makes the evidence easier to review; it does not guarantee acceptance, renewal or coverage.

The framework

32 rules, seven sub-domains

The library is structured to mirror Joint Standard 2 governance language while staying operational for a broker or UMA. Every rule is citation-grade — traceable to a public regulatory instrument.

Sub-domain one

Joint Standard 2 Governance

Cybersecurity strategy, board oversight, risk appetite, roles and responsibilities, policy framework.

Sub-domain two

Digital Channel and Technical Security

HTTPS / HSTS, TLS posture, SPF / DKIM / DMARC, security headers, admin exposure, lookalike domains.

Sub-domain three

Identity and Access Control

Multi-factor authentication, privileged access, password hygiene, joiner / mover / leaver controls.

Sub-domain four

Operational Resilience

Backup, disaster recovery, business continuity, incident response, recovery time and recovery point objectives.

Sub-domain five

Third-Party and Supply Chain Risk

Outsourcing register, vendor due diligence, concentration risk, contractual cyber clauses, exit strategy.

Sub-domain six

People and Human Layer

Awareness training, phishing-drill cadence, role-based education, insider risk, social-engineering posture.

Sub-domain seven

SA-Specific Risk Factors

Load-shedding resilience, MFA fallback, generator and UPS posture, failover ISP, SA cyber-threat-actor context.

Two layers of evidence

Free scan + structured assessment

19 automated checks run for free in 60 seconds. The 32-rule readiness self-assessment is the deeper, attested evidence layer for paid customers.

The maturity ladder

Five bands, plain English, board-ready language

Every assessment lands you in one of five bands — with a description, a recommended action, and a clear path to the next level.

L1 · 0–24

Exposed

Critical controls absent. Immediate remediation and management attention required. This readiness band is not a legal compliance conclusion.

L2 · 25–49

Emerging

Basic controls exist but significant gaps remain. Prioritise critical safeguards and verify entity-specific regulatory and insurance requirements.

L3 · 50–69

Developing

Core controls are in place, but governance, testing and third-party risk frameworks need strengthening. Some assessed controls map to JS2 themes.

L4 · 70–84

Established

Solid readiness posture with documented, tested controls and evidence of management oversight. Compliance still depends on entity scope and a full professional review.

L5 · 85–100

Advanced

Advanced readiness posture with proactive threat intelligence and continuous monitoring. This score does not certify JS2 compliance.

The differentiators

What an underwriter actually asks for — in one place

The capabilities that separate a generic cyber tool from one built for SA short-term insurance.

Incident Response Plan generator

A board-ready IRP aligned to JS2 of 2024 and NIST SP 800-61 r2 — roles, escalation, comms tree, detection, containment, eradication, recovery, lessons learned. In minutes.

Cyber-insurance Evidence Pack

One executive PDF aggregating 90-day scan trend, latest readiness assessment, IRP, load-shedding attestation and vendor register — the underwriter walks in informed.

Continuous Drift Monitoring

Alerts when your cyber posture changes between scans — new open ports, expired TLS, missing DMARC, dropped headers — before the underwriter notices.

Lookalike-domain Detection

Detects typo-squat and homoglyph domains targeting your brand — the social-engineering vector behind most claim-driving incidents in SA broking.

Load-shedding Attestation

Structured business-continuity attestation for the SA operating context — UPS, generator, failover ISP, MFA fallback — included in the cyber-insurance pack.

Phishing-drill Tracker

Lightweight log of phishing exercises against your staff — campaign, click-rate, reporter-rate — surfaced in the human-risk view and the evidence pack.

Tech-stack Vendor Fingerprinting

Detects visible technology signals on your public surface and flags possible vendor concentration for further assessment.

Owner Verification Gate

Deeper authenticated scans require DNS TXT verification, providing a strong technical-control check and a guard against scope abuse.

“Know which requirements apply. Organise the evidence. Be ready for a professional or insurer review.”