Don’t do SECURITY. Do business SECURELY.

South Africa’s financial sector cyber resilience standard takes effect

Joint Standard 2 of 2024 now applies to South African financial institutions, setting principle-based cybersecurity and cyber resilience requirements.

Joint Standard 2 of 2024 – Cybersecurity and Cyber Resilience Requirements, issued by South Africa’s Prudential Authority and Financial Sector Conduct Authority, comes into force today for banks, insurers, market infrastructures, investment managers, pension funds and other financial institutions.

Key points

  • Principle-based requirements covering governance and cybersecurity strategy.
  • Identification of assets and threats, and protection through identity, access, data and network security.
  • Detection, response, recovery, testing and situational awareness.
  • Incident notification to the regulators.
  • Applies alongside Joint Standard 1 of 2023 on IT governance and risk management.

UK technology and service providers supporting South African financial institutions should expect closer scrutiny of their security controls, testing and incident reporting as clients work to demonstrate compliance.

Source: Joint Standard 2 of 2024 – Cybersecurity and cyber resilience (South African Reserve Bank / Prudential Authority)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights