Tech4law iconTech4lawSep 28, 2026 ~4 min source read

South African financial-sector regulation now requires boards to receive cybersecurity training

A mid-2025 regulatory change (Joint Standard 2 of 2024) expands the definition of a cybersecurity awareness programme to include governing bodies, aligning board responsibility with existing data-protection and risk expectations.

South African boards now have a legal duty to be trained in cybersecurity, says IronTree

Share this story

Send the public story page.

Useful takeaways from this story.

Joint Standard 2 of 2024 (effective 1 June 2025) requires financial institutions to run an annual cybersecurity awareness programme that covers all users and the governing body.

POPIA Section 19 already requires appropriate technical and organisational measures, including training, so untrained boards may face harder regulatory scrutiny after an incident.

Ransomware incidents carry high financial risk for South African firms: Sophos’s 2025 report estimates an average cost of around R19 million per incident, increasing the stakes for board-level awareness and oversight.

# What changed Joint Standard 2 of 2024, issued jointly by the Financial Sector Conduct Authority (FSCA) and the Prudential Authority, took effect on 1 June 2025. It requires financial firms to run a comprehensive cybersecurity awareness programme at least once a year. The standard explicitly requires that the programme cover all users and the governing body.

# Why this matters for boards Historically, many organisations treated cybersecurity awareness as an IT or HR task aimed at staff. The new standard puts boards in scope of the same training regime. Byron Robertson, managing director of IronTree, says a governing body that hasn't received the same training as staff will have little basis to ask the right questions after a breach or to approve a risk appetite it actually understands.

POPIA Section 19 already requires responsible parties in South Africa to implement appropriate, reasonable technical and organisational measures. Organisational measures include training. That means a board's lack of demonstrable cybersecurity understanding can be a regulatory vulnerability: governance failures are often the first area regulators and courts examine after an incident.

# Evidence that training works

  • CSIR research cited by IronTree attributes roughly 95% of South African data breaches to human decisions rather than technical failures. That places emphasis on human-focused mitigations like training.
  • KnowBe4's 2025 benchmarking report, based on 67.7 million simulated phishing tests across 62,000 organisations, found that about one in three employees clicked a simulated phishing link before training. After twelve months of continuous training, fewer than one in twenty did.
  • Sophos's 2025 State of Ransomware report estimates the average cost of a ransomware incident to a South African business at around R19 million when ransom, downtime and recovery are counted. For many SMEs, that level of cost can be existential.

These figures support the reasoning behind training boards: if human decisions are the primary vector for breaches and training materially reduces risky user behaviour, extending training to those who govern strategic risk is a logical step.

# Practical implications for organisations Boards should stop treating cybersecurity awareness as optional background material. Organisations operating outside the financial sector should note that once a regulator writes a requirement like this into a sector standard, it tends to influence broader market expectations.

  • Confirm whether current awareness programmes explicitly include governing-body sessions and documentation of attendance and content.
  • Update governance materials and risk registers to show that board-level training occurred and what topics were covered.
  • Tie board training to risk appetite discussions so the governing body can meaningfully evaluate cyber risk and remedial plans.

# Vendor note and starting options IronTree offers Security Awareness Training as a fully managed service that extends coverage to governing bodies as well as staff. The company also provides a free Phishing Risk Check that organisations can use as a starting point to gauge their exposure.

# Bottom line The regulatory bar in South Africa's financial sector now requires boards to be trained in cybersecurity. Given the large share of breaches attributed to human decisions and the high cost of incidents, governance-level awareness is now a practical compliance and risk-management requirement, not an optional extra.

More context around this story.

ABA Cyber Task Force Co-Chair Eyes AI Education Boost
Law360 iconLaw360Sep 11, 2026

ABA Cyber Task Force Co-Chair Eyes AI Education Boost

With the legal industry presenting a more and more enticing target for cyberattacks, it's becoming increasingly important for practitioners to know how to best protect clients' data and most effectively use emerging artificial intelligence tools — a task that the American Bar Association's Cybersecurity Legal Task Forc

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app