CYB-31 · Cyber security
This risk is unique to South Africa. During load-shedding: firewalls and monitoring systems lose power if not UPS-backed, access control systems go offline, staff switch to personal mobile data (bypassing corporate security), and backup generators introduce new unmanaged network devices. Each of these creates a window of elevated cyber exposure that attackers know how to exploit.
Trigger
Security controls (firewall, EDR, SIEM) not on UPS/generator; access control systems offline during load-shedding; staff using personal mobile hotspots without VPN during load-shedding; inverter/battery units on corporate network with default credentials
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Assess power backup for all security-critical infrastructure (firewall, EDR server, SIEM). Ensure load-shedding policy requires VPN even on mobile data. Audit all inverter/UPS devices on the network and change default credentials. Include load-shedding scenario in IRP tabletop exercise.
Evidence required