Why Cyber Security
Dear reader
In the 2024/25 financial year, SA’s Information Regulator received 1,727 cyber security data breach reports. It’s expecting nearly 2,500 in the current financial year – a 45% increase.
It’s not because businesses have stopped spending on cyber security. A recent global survey of SMEs found South African companies are the most likely in the world to increase their security budgets this year. So, the money is moving, but the breaches keep climbing – why?
The real problem is not a lack of investment, but a gap between buying protection and building resilience.
National research into local cyber security found that:
- Only 50% of organisations run regular staff security training
- Only 36% have ever tested their incident response plan.
That means tools get bought. They don’t always get embedded.
Part of the gap comes down to a costly assumption: many business owners believe they’re simply too small or too obscure to be worth a criminal’s time. Cyber security practitioners consistently flag this as one of the most expensive mistakes a business can make – automated attacks don’t discriminate by company size, and smaller businesses are often easier targets.
The rest comes down to money. South African businesses have spent the past decade absorbing load shedding pressure and slower growth in an environment of weak GDP growth where tight credit policies squeeze cash flow. When budgets are already stretched, security competes for funding with keeping the business running at all – and it doesn’t always win.
Two things have happened which should help with closing that gap – fast.
Firstly, POPIA has teeth now — Sections 21 and 22 make the business, not just the IT department or the supplier, legally responsible for a breach and for reporting it, and the Information Regulator is actively enforcing that.
At the same time, larger clients are starting to ask smaller suppliers to prove their security posture before renewing a contract. Cyber security is quietly becoming a procurement requirement, not just a defensive measure. In 2025, 17% of data breaches in South Africa were traced back to third-party or supplier access – exactly the exposure large clients are now trying to close.
Closing this gap isn’t about buying more tools. It’s about governance — knowing what you’re protecting, who’s accountable for it, and whether your plan actually works when it’s tested. That’s a leadership decision, not a technical one.
If you’d like a clear-eyed view of where your business sits — spend versus resilience — we’d be glad to have that conversation.

Graeme Victor is the Founder and Chief Executive Officer of Du Pont Solutions, a leading South African IT Managed Services and technology solutions provider. With more than two decades of experience in technology, engineering and business leadership, Graeme combines exceptional technical insight with strategic business acumen to help organisations get the most from their IT and telecommunications investments.




