Joint Standard 2 of 2024 – Cybersecurity and Cyber Resilience Requirements, issued by South Africa’s Prudential Authority and Financial Sector Conduct Authority, comes into force today for banks, insurers, market infrastructures, investment managers, pension funds and other financial institutions.
Key points
- Principle-based requirements covering governance and cybersecurity strategy.
- Identification of assets and threats, and protection through identity, access, data and network security.
- Detection, response, recovery, testing and situational awareness.
- Incident notification to the regulators.
- Applies alongside Joint Standard 1 of 2023 on IT governance and risk management.
UK technology and service providers supporting South African financial institutions should expect closer scrutiny of their security controls, testing and incident reporting as clients work to demonstrate compliance.
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.