← The rule library

Cyber security & resilience

Cyber Security and Resilience

A cyber security readiness framework for South African short-term insurance brokers and intermediaries. Maps controls to Joint Standard 2 of 2024 (effective 1 June 2025), digital channel security, identity controls, operational resilience, third-party risk, people risk, and SA-specific factors including load-shedding cyber exposure and BEC prevention.

Applicability gate

A rule's presence does not establish a direct legal duty

Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.

Js2 2024
  • Insurance Broker: Most independent non-life Category I brokers are not directly in JS2's defined scope. A broker may be directly in scope if it separately meets a listed category, and may face contract or oversight requirements from an in-scope institution. Third-party provisions impose duties on the in-scope financial institution. They do not themselves make every supplier or intermediary directly subject to JS2.
  • Uma Binder Holder: UMA or binder-holder status is not itself listed in JS2's definition. Direct scope depends on another listed capacity; insurer contracts and oversight may create evidence requirements. JS2 paragraph 3.3 concerns juristic persons structured under an insurer or designated insurance group; it is not a blanket rule for every independent UMA or intermediary.
  • Insurer: An insurer as defined in the Insurance Act is directly in scope of JS2 from 1 June 2025. Apply proportionality and distinguish the insurer's own duty from requirements it places on third parties.
1 Jun 2025
JS2 commencement date
32
readiness rules
9
critical priority
8
auto-verifiable from domain

Framework context

Why this category exists

Provantis provides a structured cyber security readiness framework designed for South African short-term insurance brokers and intermediaries.

Market context

The operating environment

Joint Standard 2 of 2024 took effect on 1 June 2025 for the financial institutions defined in the standard. Brokers and UMAs may be directly in scope only through a listed capacity, or may face contract and oversight requirements from an in-scope institution. This category supports readiness and evidence review without certifying legal compliance, insurer acceptance or insurance outcomes.

Citations

Key legislation

  • FSCA/PA Joint Standard 2 of 2024 — Cybersecurity and Cyber Resilience (effective 1 June 2025)
  • FSCA/PA Joint Standard 1 of 2023 — IT Governance and Risk Management (effective 15 Nov 2024)
  • FAIS Act 37 of 2002 — general cyber risk management obligation (all FSPs)
  • POPIA 4 of 2013 — s.19 Security Safeguards condition
  • King V Code on Corporate Governance 2025 — Principle 12 (Technology and Information)
  • ECTA 25 of 2002 — electronic transaction security obligations
  • ASISA/SAIA CSIRT guidelines — sector-specific incident reporting

Readiness guidance

Start with SD1 (Joint Standard 2 governance) and SD3 (identity/MFA) — these are the most common compliance failures and the highest-impact controls. SD2 (digital channel) can be assessed automatically from the broker's domain name alone. Always validate cyber insurance declarations (SD7-CYB-32) against actual control evidence. For SA-specific context, assess load-shedding resilience (CYB-31) separately — this is a uniquely South African risk factor not covered by international frameworks.

Automated checks

8 of 32 rules verifiable from a domain alone

TLS posture, email authentication (SPF / DKIM / DMARC), security response headers, vulnerability disclosure and domain protection are scored automatically. The remaining rules require a self-attestation or an evidence upload.