A Sustained Breakdown in Organisational Readiness
South Africa is not experiencing a spike in cybercrime, it is experiencing a sustained breakdown in organisational readiness. The latest figures from the Information Regulator make that impossible to ignore.
In the first quarter alone, organisations reported 788 data breach incidents in South Africa. This adds to an already escalating trend of personal information compromises across both public and private sector environments.
This is not an isolated surge. It forms part of a broader trend that has produced thousands of incidents each year. The regulator confirmed 2,374 breaches during the 2024/25 financial year, an average of 198 per month. Since April 2025, organisations have reported a further 1,947 breaches, representing a 40% year-on-year increase.
The volume is concerning. The consistency is even more alarming. Month after month, organisations continue to report the same categories of compromise: credential theft, system intrusion, misconfigured access, and delayed detection. The pattern remains stable, suggesting the underlying problem is not technical surprise, but operational inertia.
The Information Regulator has repeatedly warned organisations to invest in “appropriate technical and organisational measures” to secure personal data. Yet the data suggests many still treat cybersecurity as a procurement exercise rather than a structural discipline.
The Impact of POPIA Compliance Changes
The April 2025 amendments to POPIA sharpened this obligation further. They introduced mandatory digital portal reporting for all security compromises and raised compliance expectations around direct marketing, cross-border transfers, and evidence keeping. Non-compliance now carries penalties of up to R10 million. The regulatory pressure is no longer theoretical.
The Dangers of Fragmented Security Environments
This is where the market tension becomes uncomfortable for enterprise IT partners such as Troye, which operates across infrastructure, virtualisation, and cyber security services.
Many organisations have accumulated layers of security tools over time. Separate procurement cycles have created fragmented environments that are difficult to monitor, manage, and secure consistently.
While these tools may be individually capable, they often operate in isolation. This creates gaps between systems where threats can go undetected.
The expectation placed on integrators is becoming increasingly unrealistic. Organisations want comprehensive protection outcomes, but those outcomes cannot be delivered through disconnected tools alone.
Effective cyber resilience now depends on integrating security visibility, telemetry, and response into a single operational view. Teams can then identify, correlate, and act on risks before they escalate.
The results of fragmented procurement strategies are predictable. Security tools exist, but without the operational layer to unify them, security outcomes continue to lag.
Why Security Spending Is Not Delivering Resilience
Gartner’s 2025 cybersecurity trends report highlights this disconnect.
The research shows a decisive shift away from perimeter-based defence. Organisations are moving towards identity-centric security, continuous exposure management, and resilience-driven architectures. Modern breaches rarely begin with infrastructure failure. They typically start with identity compromise or configuration exposure.
In practical terms, many enterprises still rely on security models designed for static networks. Meanwhile, attackers operate through cloud identities, SaaS permissions, and automated exploitation paths that ignore traditional boundaries.
This is why breach numbers remain stubbornly high even as security spending increases. Investment is not the issue, architecture and operational capacity is.
The controversial implication is that many organisations are not under secured, they are incorrectly secured. They have invested heavily in point detection tools, reporting dashboards, and compliance alignment. However, they have not invested enough in reducing actual exposure paths or in real-time detection and response capabilities.
This creates a widening gap between perceived security and actual resilience.
South Africa’s 788 breach quarter should therefore not be interpreted as a statistical spike. It should be viewed as confirmation that current security operating models are not evolving at the same pace as threat actors.
From Tool-Centric Security to Exposure-Centric Design
Organisations need to shift from tool-centric security to exposure-centric design and strengthen their operational response capacity. Until they do, the question is not whether breaches will continue, but how normalised they become before governance catches up.
Exposure-centric design means something specific. It requires organisations to map the actual paths attackers exploit, reduce identity sprawl, eliminate misconfigured access before it is weaponised, and ensure detection remains continuous rather than periodic.
It also requires organisations to accept that very few internal teams can maintain that discipline at scale on their own.
Managed detection and response, SOC as a service, and continuous threat monitoring are not luxury add-ons. In the current environment, they are the baseline.
About Troye Interactive Solutions
Troye is a South African IT solutions and managed services provider specialising in secure digital workspaces, hybrid cloud, and modern IT infrastructure. Since 1998, it has helped organisations simplify IT environments, enhance user experience, and enable secure, high-performance operations across distributed workplaces.
The company delivers end to end solutions across digital workspace, virtualisation, cloud and hybrid infrastructure, networking, cybersecurity, data protection, and managed services, including design, implementation, support, and disaster recovery.
Through partnerships with leading vendors such as Citrix, Microsoft, Nutanix, VMware, Veeam, NetScaler, HPE Aruba, Arctic Wolf, and Check Point, Troye delivers tailored, vendor agnostic solutions backed by deep technical expertise and ongoing managed services.
Troye, a black empowered company, supports organisations globally in driving digital transformation, improving productivity, strengthening security, and optimising IT investments.
By Troye managing director, Helen Kruger