Cyber security · Sub-domain six
4 rules in this sub-domain. Each rule carries a citation, a trigger, evidence requirements and a remediation pathway.
Applicability gate
Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.
Rules
CYB-27 · Joint Standard 2 of 2024 — paragraph 7.2.7 (cybersecurity awareness and training) / FICA s.43
Human error and social engineering are implicated in over 80% of successful cyber attacks. All staff must complete cyber security awareness training at onboarding and annually thereafter. Training must cover: phishing recognition, BEC, password hygiene, safe data handling, and incident reporting. Completion must be tracked per individual.
CYB-28 · Joint Standard 2 of 2024 — paragraph 7.2.7 (awareness and training) / NIST SP800-50
Phishing simulations are the most effective way to measure and improve staff resilience against email-based attacks. Simulations must be conducted at minimum quarterly, with failure rates tracked over time and declining. Staff who fail must receive immediate targeted training — not disciplinary action.
CYB-29 · Joint Standard 2 of 2024 / SAIA CSIRT BEC advisory
Business Email Compromise is the number-one financial fraud vector against SA insurance brokers. Attackers compromise email, then impersonate the broker to redirect premium payments or claims settlements. The most effective preventive control is a verbal verification protocol: any change to banking details must be confirmed via a known phone number — never via email alone.
CYB-30 · Joint Standard 2 of 2024 — paragraph 7.2.2(a)(v)–(vi) (remote access and BYOD) / POPIA s.19
With load-shedding forcing staff to work from homes or alternative locations, remote working security is a persistent gap. All remote access to corporate systems and client data must be via VPN or a Zero Trust Network Access (ZTNA) solution. BYOD (personal device) usage for client data access must be governed by a formal policy with minimum security requirements.