POPIA enforcement and the SME supply chain risk
As POPIA enforcement intensifies, RubiBlue warns South African SMEs that the compliance gap is now a business risk as third-party threats gain momentum
By Chris Ogden
South African small and medium-sized enterprises (SMEs) that handle personal information are facing a far more rigorous regulatory environment as the Information Regulator moves from guidance and preparation towards active enforcement of POPIA. Attackers have made third-party suppliers a preferred route into big organisations, and, at the same time, those organisations are pushing data protection accountability down to the SMEs they rely on. Being a trusted vendor carries real security and POPIA obligations.Now in its tenth year of operation and the fifth since POPIA’s enforcement provisions took effect, the Regulator has confirmed that it has moved to proactive monitoring, sending letters directly to companies and demanding proof of compliance. Security notifications have risen from 202 in 2021/2022 to 2,898 in 2025/2026 – a significant year-on-year increase – with more than 1,200 arriving in the first half of the year. This is compounded by the rapid increase in supply chain attacks that have become one of the defining cyber-threat themes of 2026.
Key highlights:
- The Information Regulator has shifted to proactive monitoring, writing directly to companies and demanding proof of POPIA compliance.
- Reported security compromises to the Regulator rose from 202 in 2021/2022 to 2,898 in 2025/2026, with more than 1,200 in the first half of the year alone.
- Verizon’s 2026 Data Breach Investigations Report found third-party involvement in breaches rose 60% year on year, now featuring in 48% of all breaches.
- The World Economic Forum found 65% of large organisations rank third-party and supply chain risk as their leading resilience challenge.
- SMEs need to protect their systems and ensure compliance to prepare for the day the regulator and clients ask for proof.
Chris Ogden, CEO and Founder, RubiBlue says: “Rather than confront a well-defended enterprise head on, attackers are compromising their suppliers. Software vendors and service providers provided trusted services to enterprises and attackers are using those trusted connections to gain access. It’s the equivalent of breaking into the warehouse instead of opening every shop one by one and even well-protected companies are at risk.”
According to Verizon, third-party breaches have increased by 60% since 2025, and the World Economic Forum found that 65% of large organisations now cite third-party and supply chain risks as their primary resilience challenge. In South Africa, companies that include Satrix, Bidvest Bank and EasyEquities have recently experienced data exposure due to third-party service providers and the threat is only set to increase.
The entry points the attackers use are also rarely complicated. A routine software update, a managed service provider’s remote access tool, a compromised supplier email account, an infected invoice – the attackers don’t have to overcome firewalls and endpoint security because they are exploiting systems that were built to accept these connections.
The result is that larger companies are writing security obligations into contracts, requiring data processing agreements and asking smaller suppliers to prove their compliance before work is awarded. This means that now is the time to close the gap to ensure the SME is protected for the customer and compliant for the regulator.
SMEs that can hold their place in the supply chain treat security as something they can demonstrate, and this comes down to six practical moves:
- Map the data and know exactly what client personal information you hold, where it sits and who can reach it.
- Formalise relationships with a data processing agreement for every client and sub-contractor so all obligations are clear on all sides.
- Close the common entry points by patching and updating software, controlling remote access tools and enforcing multi-factor authentication on every account that touches client data.
- Restrict access to sensitive systems and keep at least one backup that no supplier credential can reach.
- Run regular vulnerability scans and penetration tests and fix what they highlight.
- Keep records that show a client or the regulator how data is protected, retained and deleted and have a breach response and reporting plan in place.
RubiBlue builds these controls for its own platforms that process sensitive policyholder data for more than 1000 funeral parlours and reach more than twelve million policyholders. The company offers the same building blocks to SME suppliers through its security and compliance solutions that include vulnerability reporting, penetration testing, patch management and preventative monitoring and more.
Ogden concludes: “Suppliers that keep their place in the chain are the ones who can show their security holds up on the day a client or the regulator asks. And they will ask – compliance has become a condition of doing business and it costs far less to build it now than to explain its absence after a breach.”
Nothing is 100% safe in this digital world, but it’s the responsibility of the third-party providers align with best practices and create a culture internally around information security and ensure they have done their best to protect their systems and data.