Home » Industry News » Security Surveillance & Access Control & Cyber Security News » Opinion Piece: POPIA breach reporting is exposing gaps in incident response

Opinion Piece: POPIA breach reporting is exposing gaps in incident response

Opinion Piece: POPIA breach reporting is exposing gaps in incident response

By Ryan Boyes, Senior Security Administrator at Galix 

Cyber incidents are not new, but the way organisations are expected to respond to them is changing. Under the Protection of Personal Information Act (POPIA), breach reporting has increased significantly in South Africa. More than 1,600 incidents were reported between April and September 2025, and organisations are under greater pressure to detect, report, and respond within defined timelines. The challenge is not only identifying a breach but also understanding what needs to be reported, who needs to be involved and how quickly the organisation can assess the incident, coordinate a response and meet reporting obligations. This is often where organisations struggle to respond effectively. Cybersecurity and compliance specialists are invaluable in assisting organisations to put structured response processes in place, align them with regulatory requirements, test them and ensure they can be executed when needed. 

Reporting is easier, but responding is the challenge

Incident reporting has increased for several reasons. Organisations are required to report certain breaches, and individuals are more aware of how to raise concerns. At the same time, the Information Regulator’s online reporting tool has made it easier to submit incidents and begin the process. This means organisations can no longer avoid reporting – if an incident is not reported and later becomes public, the consequences are often more serious than the breach itself. 

One challenge is that organisations may not fully understand the requirements or how to act when an incident occurs. This leads to delays, incomplete reporting, or inconsistent responses. As a result, they may struggle to demonstrate that they followed a defined process after the incident. It is not enough to have controls in place beforehand. Organisations must be able to show how they responded.  For example, if an organisation commits to reporting within a certain timeframe but fails to do so, it becomes clear that the process is either not in place or not working. 

This is where governance becomes critical. Having a documented response plan is not enough. Organisations need to demonstrate that it is applied consistently and that it holds up under pressure. 

Incident response cannot be isolated

Another mistake many businesses make is treating incident response as a separate IT process. However, in reality, different types of incidents can and often do overlap. A fire can affect systems and expose data. A network outage can create conditions that lead to a breach. Physical access during an emergency can introduce risk. If response plans are split across different areas, these connections are missed. 

A more effective approach is to treat incident response as a single, integrated process that considers different scenarios and how they interact. Testing is also important. Many organisations have response plans, but without testing, it is difficult to know whether the process will hold up when required.

Independent oversight strengthens response

External cybersecurity and compliance specialists can be highly beneficial in this process. They help organisations understand their environment, identify gaps and align their response processes with regulatory requirements. They also provide an independent perspective, testing whether documented processes actually work and highlighting areas where improvement is needed. 

They typically draw on recognised frameworks such as ISO standards like ISO 27001, the National Institute of Standards and Technology (NIST) Cybersecurity Framework, or the Centre for Internet Security (CIS) Critical Security Controls to bring structure. The focus is not only on implementing controls but also on ensuring there is a management system in place to monitor, review, and improve them over time. 

Response is now part of compliance

A structured approach to incident response has become essential, because breach reporting under POPIA is not only about disclosure. It also reveals whether an organisation is prepared to respond effectively when something goes wrong. 

Organisations that treat incident response as part of their overarching governance are better positioned to meet reporting requirements and manage the impact of an incident. Those that treat it as a once-off exercise are more likely to fall short. 

As the number of reported breaches continues to increase, this distinction is becoming more visible. It is no longer enough to detect an incident. Organisations need to show that they can respond in a structured and consistent way and demonstrate the effectiveness of their response when an incident occurs.

To enquire about Cape Business News' digital marketing options please contact sales@cbn.co.za

Related articles

The two-pot temptation: what borrowing from your future self costs you

The two-pot temptation: what borrowing from your future self costs you Nearly half of under-60s with retirement products have dipped into their savings pots, mostly...

City urges national alignment on Ease of Doing Business reforms

City urges national alignment on Ease of Doing Business reforms  A renewed focus on reducing red tape and an Ease of Doing Business initiative from...

MUST READ

Sasol Green Hydrogen strategy shifts towards Northern Cape partnerships

Sasol Green Hydrogen strategy shifts towards Northern Cape partnerships The energy giant admits it cannot go it alone at Boegoebaai, pivoting to a collaborative 'catalyst...

RECOMMENDED