Practical, South African-grounded thinking on POPIA, King IV, the Cybercrimes Act and the threats we see in the field, written for the people who have to make the call.
Notification duties start the moment you know. Here is what a defensible response looks like under the Regulator.
Principle 12 asks the board to govern technology and information. Translating that into reporting they can actually use.
Posture drifts between audits. Continuous monitoring turns the yearly report into a confirmation, not a surprise.
How a single spoofed invoice became a seven-figure loss, and the controls that would have stopped it.
A calm, staged path from gap assessment to certification, and the evidence auditors actually want to see.
Most cloud incidents are not clever attacks. They are exposed buckets and over-broad roles. Benchmarking against CIS.
Act 19 of 2020 created new offences and reporting duties. What directors need to understand about their exposure.
When systems go down, patient care is on the line. Building recovery that assumes compromise will happen.
A monthly note on regulation, threats and assurance in South Africa. No noise, just what changed and what to do about it.