Cyber security · Sub-domain two
7 rules in this sub-domain. Each rule carries a citation, a trigger, evidence requirements and a remediation pathway.
Applicability gate
Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.
Rules
CYB-06 · POPIA s.19 / Joint Standard 2 of 2024 / ECTA
All client-facing web properties (website, quote portals, client portals) must enforce HTTPS with a valid, current TLS certificate. HTTP requests must redirect to HTTPS. HSTS (Strict-Transport-Security) header must be present. Session cookies must carry Secure and HttpOnly flags.
CYB-07 · Joint Standard 2 of 2024 / POPIA s.19
TLS configuration must achieve a minimum A rating on the SSL Labs Server Test or equivalent. This covers: TLS version (1.2 minimum, 1.3 preferred), cipher suite strength, certificate chain validity, and OCSP stapling.
CYB-08 · Joint Standard 2 of 2024 / POPIA s.19 / BEC risk
Business Email Compromise (BEC) is the highest-frequency financial fraud vector against SA insurance brokers. All email-sending domains must have: SPF (hard fail -all), DKIM signing, and DMARC at minimum p=quarantine. This prevents domain spoofing and is a primary BEC defence. Missing DMARC p=none provides zero protection.
CYB-09 · Joint Standard 2 of 2024 / POPIA s.19 / OWASP Top 10
HTTP security headers provide a critical layer of browser-side protection against XSS, clickjacking, MIME sniffing, and data leakage. These headers are visible in any HTTP response and their absence signals a basic security gap to both regulators and attackers.
CYB-10 · Joint Standard 2 of 2024 / OWASP Top 10 A05
Public exposure of administrative interfaces (/admin, /wp-admin, /cpanel, /phpmyadmin, etc.) without strong authentication is one of the most exploited weaknesses in SA SME environments. Admin portals must not be publicly reachable or must require MFA before any content is served.
CYB-11 · RFC 9116 / NCSC guidance / Joint Standard 2 best practice
The security.txt standard (RFC 9116) defines how organisations can communicate their vulnerability disclosure policy and security contact. Its presence signals security maturity and enables ethical hackers to report issues before they are exploited. Required at /.well-known/security.txt.
CYB-12 · Joint Standard 2 of 2024 / BEC risk management
Domain hijacking and typosquatting are primary vectors for broker impersonation in SA. Attackers register domains like 'apexinsurancecoza.com' or 'apex-insurance.co.za' to intercept clients, divert payments, or conduct phishing campaigns. Registry Lock prevents unauthorised domain transfers.