← Cyber Security and Resilience

Cyber security · Sub-domain six

People and Human Layer

4 rules in this sub-domain. Each rule carries a citation, a trigger, evidence requirements and a remediation pathway.

Applicability gate

A rule's presence does not establish a direct legal duty

Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.

Js2 2024
  • Insurance Broker: Most independent non-life Category I brokers are not directly in JS2's defined scope. A broker may be directly in scope if it separately meets a listed category, and may face contract or oversight requirements from an in-scope institution. Third-party provisions impose duties on the in-scope financial institution. They do not themselves make every supplier or intermediary directly subject to JS2.
  • Uma Binder Holder: UMA or binder-holder status is not itself listed in JS2's definition. Direct scope depends on another listed capacity; insurer contracts and oversight may create evidence requirements. JS2 paragraph 3.3 concerns juristic persons structured under an insurer or designated insurance group; it is not a blanket rule for every independent UMA or intermediary.
  • Insurer: An insurer as defined in the Insurance Act is directly in scope of JS2 from 1 June 2025. Apply proportionality and distinguish the insurer's own duty from requirements it places on third parties.
1
Critical — board exposure
2
High — significant exposure
1
Medium — material exposure
0
Low — hygiene

Rules

4 rules in People and Human Layer

CYB-27 · Joint Standard 2 of 2024 — paragraph 7.2.7 (cybersecurity awareness and training) / FICA s.43

Cyber awareness training — all staff complete annual training; new staff trained at onboarding

High

Human error and social engineering are implicated in over 80% of successful cyber attacks. All staff must complete cyber security awareness training at onboarding and annually thereafter. Training must cover: phishing recognition, BEC, password hygiene, safe data handling, and incident reporting. Completion must be tracked per individual.

Trigger
No cyber awareness training programme; staff training records absent; training not completed within last 12 months; new staff not trained within 30 days of joining

CYB-28 · Joint Standard 2 of 2024 — paragraph 7.2.7 (awareness and training) / NIST SP800-50

Phishing simulation — regular simulated phishing tests conducted; failure rates tracked and reducing

Medium

Phishing simulations are the most effective way to measure and improve staff resilience against email-based attacks. Simulations must be conducted at minimum quarterly, with failure rates tracked over time and declining. Staff who fail must receive immediate targeted training — not disciplinary action.

Trigger
No phishing simulation programme; simulations conducted less than quarterly; failure rates not tracked or not declining over time

Business Email Compromise is the number-one financial fraud vector against SA insurance brokers. Attackers compromise email, then impersonate the broker to redirect premium payments or claims settlements. The most effective preventive control is a verbal verification protocol: any change to banking details must be confirmed via a known phone number — never via email alone.

Trigger
No verbal verification protocol for changed banking details; no dual-authorisation requirement for outgoing payments above a defined threshold; staff unaware of BEC risk pattern

CYB-30 · Joint Standard 2 of 2024 — paragraph 7.2.2(a)(v)–(vi) (remote access and BYOD) / POPIA s.19

Mobile and remote working security — VPN or Zero Trust enforced; personal device (BYOD) policy in place

High

With load-shedding forcing staff to work from homes or alternative locations, remote working security is a persistent gap. All remote access to corporate systems and client data must be via VPN or a Zero Trust Network Access (ZTNA) solution. BYOD (personal device) usage for client data access must be governed by a formal policy with minimum security requirements.

Trigger
Staff accessing client data over public WiFi without VPN; no remote access policy; personal devices accessing client data without minimum security controls; no mobile device management (MDM) on devices with client data