Intelligent CIO Africa Issue 117 | Page 30

INTELLIGENT TECHNOLOGY
CYBER DEFENCE

POPIA breach reporting exposes gaps in incident response

Ryan Boyes, Senior Security Administrator at Galix

South Africa’ s rising volume of data breach notifications under the Protection of Personal Information Act( POPIA) is putting organisations’ incident response capabilities under greater scrutiny, exposing gaps between having security policies in place and being able to execute them when an incident occurs.

More than 1,600 incidents were reported between April and September 2025, while greater awareness of regulatory obligations and the Information Regulator’ s online reporting process have made breaches more visible.
According to Ryan Boyes, Senior Security Administrator at Galix, the challenge increasingly lies not in reporting an incident but in what happens immediately afterwards.
“ The challenge is not only identifying a breach but also understanding what needs to be reported, who needs to be involved and how quickly the organisation can assess the incident, coordinate a response and meet reporting obligations,” he said.
While organisations may have incident response policies, Boyes said many still struggle to translate those plans into coordinated action. Delayed or incomplete reporting can reveal weaknesses in escalation procedures, responsibilities and governance.
“ It is not enough to have controls in place beforehand. Organisations must be able to show how they responded,” he said.
This is shifting the compliance conversation from preventative security towards demonstrable response capability. Organisations increasingly need to show not only that appropriate controls existed but that established procedures were followed when those controls failed.
“ Having a documented response plan is not enough. Organisations need to demonstrate that it is applied consistently and that it holds up under pressure,” Boyes said.
A further weakness is the tendency to treat cyber incident response primarily as an IT responsibility. In practice, Boyes said incidents can cut across cybersecurity, physical security, business continuity, compliance and operational functions.
“ A fire can affect systems and expose data. A network outage can create conditions that lead to a breach. Physical access during an emergency can introduce risk,” he said.
This makes fragmented response plans increasingly problematic. If different teams operate independently, organisations risk overlooking connections between physical, operational and cyber incidents.
“ A more effective approach is to treat incident response as a single, integrated process that considers different scenarios and how they interact,” Boyes said.
Testing is equally important. Organisations may have detailed response procedures, but exercises and simulations can expose gaps in decisionmaking, escalation and communication before a genuine breach occurs.
Boyes also sees a growing role for independent cybersecurity and compliance specialists in assessing whether organisations are genuinely prepared.
“ They help organisations understand their environment, identify gaps and align their response processes with regulatory requirements,” he said.“ They also provide an independent perspective, testing whether documented processes actually work and highlighting areas where improvement is needed.”
Frameworks such as ISO 27001, the NIST Cybersecurity Framework and CIS Critical Security Controls can provide structure, but Boyes said organisations need to go beyond implementing individual controls. Continuous monitoring, review and improvement are necessary as both threats and regulatory expectations evolve.
The increase in POPIA reporting ultimately provides regulators and organisations with greater visibility into how effectively incidents are being managed.
“ A structured approach to incident response has become essential, because breach reporting under POPIA is not only about disclosure. It also reveals whether an organisation is prepared to respond effectively when something goes wrong,” Boyes said.
The distinction is increasingly important. Organisations with established governance, tested processes and clear accountability are better positioned to manage an incident and demonstrate compliance.
“ It is no longer enough to detect an incident,” Boyes said.“ Organisations need to show that they can respond in a structured and consistent way and demonstrate the effectiveness of their response when an incident occurs.” •
30
INTELLIGENT CIO AFRICA www. intelligentcio. com