On 31 August 2026, Information Regulator chair Pansy Tlakula stood in front of the microphones and called the trend "very alarming." The numbers behind that phrase, reported by ITWeb on 3 September and echoed by Moonstone, are worth reading slowly. Over 8,000 cumulative security compromise notifications since POPIA came into force. 1,220 of them since 1 April 2026 alone. A monthly average that has climbed from 198 to 284, a jump of roughly forty percent year on year, with the regulator projecting the annual total will clear 3,000. What follows are four things enterprise boards in South Africa should take from that briefing, and one thing they should stop doing.
- The regulator has sized the exposure out loud.
For years, South African executives have discussed cyber risk in the language of hypotheticals. The Information Regulator has now put a public number on the frequency, and it is rising. 1,220 notifications in five months is not a rounding error. It is roughly eight organisations per working day telling the state they have lost control of personal information. Tlakula's word choice matters here. "Alarming" from a regulator is not rhetorical colour. It is a signal that the supervisory posture is shifting from education to enforcement, and that the audit questions coming down the line will be sharper. Boards that have been treating POPIA compliance as a documentation exercise now have a dated, on-record baseline against which their own incident rate will be measured. The exposure is no longer abstract. It has a monthly cadence and a trajectory.
- Tlakula named the causes, and they are not technical.
The regulator did not point at zero-day exploits or state-sponsored intrusion. She pointed at inadequate controls and employee negligence. That is a diagnosis every CISO in the country recognises but few boards have absorbed. Inadequate controls means the basics are missing or misconfigured. Access reviews, patching discipline, log retention, joiner-mover-leaver processes, third-party assurance. Employee negligence means the humans in the chain are clicking, forwarding, sharing, and reusing passwords in ways training has not changed. Neither cause is solved by procuring another tool. Both are solved by running a programme. The distinction matters because procurement cycles default to product. A new endpoint agent, a new SIEM, a new email gateway. The regulator is describing something that a purchase order cannot fix.
- Programme failure is a governance problem, not an IT problem.
If the two named causes are controls and people, then the accountable owner sits above the CISO. Controls decay when nobody is measuring them month to month. People stay negligent when training is annual, generic, and untested. Drills do not happen because nobody has scheduled them and no executive has asked to see the results. Vendor assurance lapses because the register is out of date and the questionnaires go unread. Each of these is a management discipline, not a technology choice. The boards that will come out of the next twelve months in better shape are the ones treating cyber resilience the way they already treat financial control. Named owners. Monthly evidence. Independent testing. Consequences when the evidence is thin. The regulator's framing gives audit committees the language to ask for exactly that.
- Vendor sprawl is quietly part of the problem.
Most large South African enterprises are running a security estate assembled over a decade of point purchases. An identity vendor here, a detection vendor there, a managed service for the SOC, a separate provider for awareness training, another for phishing simulations, a fourth for penetration testing, and a scattering of consultants who show up for the annual review. Each contract is defensible on its own. Together they create the exact gap Tlakula described. Nobody owns the whole picture. Controls fall between vendors. Employees are trained by one supplier and phished by another with no shared view of who is failing. Third-party risk assessments sit in a spreadsheet that nobody has opened since onboarding. Consolidating accountability does not mean consolidating to a single tool. It means one partner answerable for the programme, with the specialists composed underneath, and one monthly conversation with the board about what is working and what is not.
- The next twelve months will separate the prepared from the exposed.
If the regulator's projection holds and notifications clear 3,000 for the year, a meaningful share of South African enterprises will be reporting an incident. Some of those organisations will be able to show the regulator a live programme. Documented controls tested in the last quarter. Training with completion rates and phishing simulation results. Drills run against a defined scenario. A vendor register that is current. Incident response rehearsed with named humans. Others will produce a policy document dated 2023 and a procurement record. The gap between those two postures is what will determine both regulatory outcome and public consequence. The organisations that treat the next year as a window to build the programme, not to buy another product, are the ones that will still be having the conversation on their own terms.
The through-line across all five points is the same. Cyber resilience at enterprise scale is not a shopping problem. It is a running problem. Controls that work in January drift by June. Staff who passed training in March forget by September. Vendors who were assured at onboarding change their sub-processors quietly. The organisations that stay ahead of the notification statistics are the ones that have accepted this and organised themselves for it, with one accountable partner holding the programme together and specialists doing the specialist work underneath. Tlakula has given every South African board the number they needed to have this conversation seriously. The question is whether the response is another line item, or a programme with an owner.

