# What changed Joint Standard 2 of 2024, issued jointly by the Financial Sector Conduct Authority (FSCA) and the Prudential Authority, took effect on 1 June 2025. It requires financial firms to run a comprehensive cybersecurity awareness programme at least once a year. The standard explicitly requires that the programme cover all users and the governing body.
# Why this matters for boards Historically, many organisations treated cybersecurity awareness as an IT or HR task aimed at staff. The new standard puts boards in scope of the same training regime. Byron Robertson, managing director of IronTree, says a governing body that hasn't received the same training as staff will have little basis to ask the right questions after a breach or to approve a risk appetite it actually understands.
POPIA Section 19 already requires responsible parties in South Africa to implement appropriate, reasonable technical and organisational measures. Organisational measures include training. That means a board's lack of demonstrable cybersecurity understanding can be a regulatory vulnerability: governance failures are often the first area regulators and courts examine after an incident.
# Evidence that training works
- CSIR research cited by IronTree attributes roughly 95% of South African data breaches to human decisions rather than technical failures. That places emphasis on human-focused mitigations like training.
- KnowBe4's 2025 benchmarking report, based on 67.7 million simulated phishing tests across 62,000 organisations, found that about one in three employees clicked a simulated phishing link before training. After twelve months of continuous training, fewer than one in twenty did.
- Sophos's 2025 State of Ransomware report estimates the average cost of a ransomware incident to a South African business at around R19 million when ransom, downtime and recovery are counted. For many SMEs, that level of cost can be existential.
These figures support the reasoning behind training boards: if human decisions are the primary vector for breaches and training materially reduces risky user behaviour, extending training to those who govern strategic risk is a logical step.
# Practical implications for organisations Boards should stop treating cybersecurity awareness as optional background material. Organisations operating outside the financial sector should note that once a regulator writes a requirement like this into a sector standard, it tends to influence broader market expectations.
- Confirm whether current awareness programmes explicitly include governing-body sessions and documentation of attendance and content.
- Update governance materials and risk registers to show that board-level training occurred and what topics were covered.
- Tie board training to risk appetite discussions so the governing body can meaningfully evaluate cyber risk and remedial plans.
# Vendor note and starting options IronTree offers Security Awareness Training as a fully managed service that extends coverage to governing bodies as well as staff. The company also provides a free Phishing Risk Check that organisations can use as a starting point to gauge their exposure.
# Bottom line The regulatory bar in South Africa's financial sector now requires boards to be trained in cybersecurity. Given the large share of breaches attributed to human decisions and the high cost of incidents, governance-level awareness is now a practical compliance and risk-management requirement, not an optional extra.