← SA-Specific Risk Factors

CYB-31 · Cyber security

Load-shedding cyber resilience — security controls remain active and effective during power outages

This risk is unique to South Africa. During load-shedding: firewalls and monitoring systems lose power if not UPS-backed, access control systems go offline, staff switch to personal mobile data (bypassing corporate security), and backup generators introduce new unmanaged network devices. Each of these creates a window of elevated cyber exposure that attackers know how to exploit.

High priority

Trigger

When this rule fires

Security controls (firewall, EDR, SIEM) not on UPS/generator; access control systems offline during load-shedding; staff using personal mobile hotspots without VPN during load-shedding; inverter/battery units on corporate network with default credentials

Applicability gate

Confirm the entity's role before treating this as a duty

This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.

  • Insurance Broker: Most independent non-life Category I brokers are not directly in JS2's defined scope. A broker may be directly in scope if it separately meets a listed category, and may face contract or oversight requirements from an in-scope institution. Third-party provisions impose duties on the in-scope financial institution. They do not themselves make every supplier or intermediary directly subject to JS2.
  • Uma Binder Holder: UMA or binder-holder status is not itself listed in JS2's definition. Direct scope depends on another listed capacity; insurer contracts and oversight may create evidence requirements. JS2 paragraph 3.3 concerns juristic persons structured under an insurer or designated insurance group; it is not a blanket rule for every independent UMA or intermediary.
  • Insurer: An insurer as defined in the Insurance Act is directly in scope of JS2 from 1 June 2025. Apply proportionality and distinguish the insurer's own duty from requirements it places on third parties.

Citation

Mapped source

This control maps to the public instruments below. The mapping does not establish entity applicability.

Section
Joint Standard 2 of 2024 (resilience) — SA-specific risk factor
Legislation
  • Joint Standard 2 of 2024
  • Joint Standard 1 of 2023

Remediation

How to close the gap

Assess power backup for all security-critical infrastructure (firewall, EDR server, SIEM). Ensure load-shedding policy requires VPN even on mobile data. Audit all inverter/UPS devices on the network and change default credentials. Include load-shedding scenario in IRP tabletop exercise.

Evidence required

Evidence to prepare if this control applies

  • UPS/generator coverage inventory for security infrastructure
  • Load-shedding acceptable use policy (VPN on mobile data required)
  • Inverter/UPS device audit with credential change confirmation
  • Tabletop exercise including load-shedding scenario