← Cyber Security and Resilience

Cyber security · Sub-domain seven

SA-Specific Risk Factors

2 rules in this sub-domain. Each rule carries a citation, a trigger, evidence requirements and a remediation pathway.

Applicability gate

A rule's presence does not establish a direct legal duty

Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.

Js2 2024
  • Insurance Broker: Most independent non-life Category I brokers are not directly in JS2's defined scope. A broker may be directly in scope if it separately meets a listed category, and may face contract or oversight requirements from an in-scope institution. Third-party provisions impose duties on the in-scope financial institution. They do not themselves make every supplier or intermediary directly subject to JS2.
  • Uma Binder Holder: UMA or binder-holder status is not itself listed in JS2's definition. Direct scope depends on another listed capacity; insurer contracts and oversight may create evidence requirements. JS2 paragraph 3.3 concerns juristic persons structured under an insurer or designated insurance group; it is not a blanket rule for every independent UMA or intermediary.
  • Insurer: An insurer as defined in the Insurance Act is directly in scope of JS2 from 1 June 2025. Apply proportionality and distinguish the insurer's own duty from requirements it places on third parties.
0
Critical — board exposure
2
High — significant exposure
0
Medium — material exposure
0
Low — hygiene

Rules

2 rules in SA-Specific Risk Factors

CYB-31 · Joint Standard 2 of 2024 (resilience) — SA-specific risk factor

Load-shedding cyber resilience — security controls remain active and effective during power outages

High

This risk is unique to South Africa. During load-shedding: firewalls and monitoring systems lose power if not UPS-backed, access control systems go offline, staff switch to personal mobile data (bypassing corporate security), and backup generators introduce new unmanaged network devices. Each of these creates a window of elevated cyber exposure that attackers know how to exploit.

Trigger
Security controls (firewall, EDR, SIEM) not on UPS/generator; access control systems offline during load-shedding; staff using personal mobile hotspots without VPN during load-shedding; inverter/battery units on corporate network with default credentials

CYB-32 · Joint Standard 2 of 2024 / FAIS Act risk management / Cyber insurance best practice

Cyber insurance alignment — cyber insurance in place; declared controls verified to match actual implementation

High

Cyber-insurance applications may ask the applicant to declare whether controls such as MFA, backups and incident response are implemented. Those declarations should be checked against current evidence before submission. A Provantis readiness assessment can organise that evidence but does not determine coverage or guarantee claim acceptance.

Trigger
No cyber insurance in place; cyber insurance application declarations not verified against actual controls; significant gap between declared and actual MFA, backup, or IRP status