← Cyber Security and Resilience

Cyber security · Sub-domain five

Third-Party and Supply Chain Risk

4 rules in this sub-domain. Each rule carries a citation, a trigger, evidence requirements and a remediation pathway.

Applicability gate

A rule's presence does not establish a direct legal duty

Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.

Js2 2024
  • Insurance Broker: Most independent non-life Category I brokers are not directly in JS2's defined scope. A broker may be directly in scope if it separately meets a listed category, and may face contract or oversight requirements from an in-scope institution. Third-party provisions impose duties on the in-scope financial institution. They do not themselves make every supplier or intermediary directly subject to JS2.
  • Uma Binder Holder: UMA or binder-holder status is not itself listed in JS2's definition. Direct scope depends on another listed capacity; insurer contracts and oversight may create evidence requirements. JS2 paragraph 3.3 concerns juristic persons structured under an insurer or designated insurance group; it is not a blanket rule for every independent UMA or intermediary.
  • Insurer: An insurer as defined in the Insurance Act is directly in scope of JS2 from 1 June 2025. Apply proportionality and distinguish the insurer's own duty from requirements it places on third parties.
0
Critical — board exposure
3
High — significant exposure
1
Medium — material exposure
0
Low — hygiene

Rules

4 rules in Third-Party and Supply Chain Risk

CYB-23 · Joint Standard 2 of 2024 — paragraphs 4.2.3, 7.2.3(a)(iii), 7.7.1(b) and 8.1.1(f) (third-party) / Joint Standard 1

Third-party cyber risk register — all material vendors assessed for cyber security posture

High

Most SA short-term insurance brokers depend on 3–6 shared technology platforms: a policy admin system (TIAL, Genius, Flexi), a comparator, insurer extranets, and a CRM. A compromise of any single vendor can expose every broker using that platform simultaneously. A formal third-party cyber risk register must document all vendors with access to client data, their assessed risk, and oversight controls.

Trigger
No third-party cyber risk register; vendors with access to client PII not assessed; no cyber security clauses in vendor contracts; no exit plan for key vendors
Automated
Yes — 1 machine check

CYB-24 · Joint Standard 2 of 2024 — paragraph 4.2.3 (SLA roles and responsibilities) / POPIA s.20-21 / Joint Standard 1

Outsourcing agreements — cyber security obligations contractually defined for all material outsourcing

High

All material outsourcing agreements must include: data security obligations, incident notification requirements (breach notification within 24–72 hours to the Responsible Party), right to audit, data return/destruction on termination, and sub-outsourcing restrictions. This extends to cloud providers, IT support companies, and managed service providers.

Trigger
Vendor agreements lack cyber security clauses; no breach notification obligation on vendors; no right to audit vendors; IT support company has admin access without a formal agreement

CYB-25 · Joint Standard 1 of 2023 (IT continuity management) / Joint Standard 2 of 2024 — paragraph 7.4 (response and recovery)

Policy administration system (PAS) risk — single-vendor dependency assessed with continuity controls

Medium

Almost all SA short-term insurance brokers depend on a single Policy Administration System. A ransomware attack on the PAS vendor — or a cloud outage — can render the broker operationally blind. The risk of this dependency must be explicitly assessed, with documented manual fallback procedures and SLA-backed recovery commitments from the vendor.

Trigger
PAS vendor dependency not documented in risk register; no manual fallback procedures for PAS outage; PAS vendor has not provided cyber security assurance or SLA for recovery from a cyber incident
High

Three of South Africa's biggest data exposures in recent years were caused by misconfigured cloud storage (S3 buckets, Azure Blob storage) left publicly accessible. Any cloud-hosted system holding client data must be audited for public exposure, default credential usage, and excess permissions (over-privileged service accounts).

Trigger
No cloud security review in last 12 months; cloud storage buckets with public access enabled; default cloud service account credentials in use; no cloud security posture management (CSPM) tool deployed