Every South African business that uses a computer, stores client information, or processes payments online carries cyber risk. That risk is not always covered by your insurance.

The assumption that standard commercial or business insurance policies cover cybercrime losses is one of the costliest misconceptions in South African risk management today. In most cases, they do not. When a business falls victim to a phishing attack, a ransomware incident, or a payment diversion fraud, the financial consequences, including lost funds, regulatory fines, legal liability, and recovery costs, typically fall entirely on the business owner.

This article explains the scale of the cyber threat facing South African businesses in 2026, the legal obligations that arise from a breach, and why cyber insurance has moved from a niche product to an essential component of any credible risk management plan.

What Is Cybercrime?

The Cybercrimes Act 19 of 2020 is the primary legislation governing cybercrime in South Africa. It defines and criminalises a broad range of cyber offences, including:

  • Unlawful access to computer systems or data
  • Interception of data without authorisation
  • Interference with data, programmes, or computer systems
  • Cyber fraud, forgery, and extortion
  • Possession or distribution of malicious software

For businesses, the most common forms of cybercrime are phishing attacks, business email compromise (BEC), ransomware, data breaches, and identity fraud. Each carries different financial consequences, and each can give rise to insurance claims, provided the right cover is in place.

What Is Cyber Insurance?

Cyber insurance is a specialist insurance product designed to protect businesses against the financial consequences of cybercrime and data breaches. Unlike standard business insurance, which covers physical assets, liability, and business interruption from conventional causes, cyber insurance specifically addresses losses arising from digital risks.

A cyber insurance policy typically provides cover across two broad categories:

First-party cover

This covers direct losses suffered by the insured business, which may include:

  • Costs of notifying affected customers and regulators after a data breach
  • Forensic investigation to establish what happened and how
  • Business interruption losses arising from a cyberattack or system shutdown
  • Ransom payments in the event of a ransomware attack
  • Costs of restoring or recovering data and systems
  • Crisis communication and reputation management

Third-party cover

This covers claims made against the insured business by others, which may include:

  • Legal liability to clients or third parties whose data was compromised
  • Regulatory fines and defence costs arising from POPIA non-compliance
  • Claims by customers for losses suffered as a result of a breach

 Most standard commercial short-term insurance policies expressly exclude cyber-related losses. A business that has not taken out dedicated cyber cover is, in most cases, self-insuring against one of the most prevalent business risks in South Africa today.

The Scale of the Problem in South Africa

South Africa is a high-value target. According to research by Accenture, it ranks as the third most targeted country for cyberattacks globally, behind only the United States and the United Kingdom. The financial impact is significant and measurable:

  • The South African Banking Risk Information Centre (SABRIC) estimates cybercrime costs the country approximately R2.2 billion annually.
  • Phishing attacks account for approximately 78% of all digital banking fraud in South Africa, according to SABRIC figures.
  • Business email compromise (BEC) cases rose by 26% in 2024, according to SABRIC data.
  • Approximately 54% of data breaches in South Africa involved compromised user identities, according to Accenture research.
  • 64% of audit leaders in Southern Africa identified cyber incidents as the primary business risk, according to the Africa Risk in Focus 2026 report.

In the first quarter of 2025, Parliament’s social media accounts were hijacked to promote a fraudulent cryptocurrency scheme. This is a reminder that no organisation, regardless of size or sector, is immune.

These figures represent reported and estimated losses. The true cost of cybercrime, including unreported incidents, reputational damage, and long-term client attrition, is likely considerably higher.

Why Standard Business Insurance Does Not Cover This

Business owners often discover the gaps in their cover only after a loss has occurred. Standard commercial and business insurance policies are designed around physical risks: fire, theft, flood, and liability from bodily injury. They were not designed with digital crime in mind, and most policies either exclude cyber losses entirely or contain ambiguities that allow insurers to decline claims.

Common exclusions or limitations in standard policies that affect cyber claims include:

  • Electronic data exclusions: Many property policies explicitly exclude damage to or loss of electronic data
  • Fraud exclusions: Some policies exclude losses arising from fraudulent electronic instructions, which capture many BEC and payment diversion scenarios
  • War and terrorism exclusions: State-sponsored cyberattacks have been excluded under these clauses in international cases, a risk that is growing as AI-assisted attacks increase
  • Voluntary parting exclusions: Where an employee was deceived into authorising a fraudulent payment, some insurers argue the loss was voluntary

Businesses that rely on a general commercial policy to cover cyber losses are likely to find, at the time of a claim, that cover does not exist or is contested. A dedicated cyber insurance policy removes that uncertainty.

The Legal Obligations That Follow a Breach

A cyberattack does not only result in direct financial loss. It also triggers legal obligations that carry their own costs and penalties.

The Cybercrimes Act 19 of 2020

This Act came into force on 1 December 2021. Under section 54(1), electronic communications service providers and financial institutions that become aware of a cybercrime, including unauthorised access, data interception, or system interference, must report the offence to the South African Police Service within 72 hours. Failure to comply is itself a criminal offence, carrying a fine of up to R50,000.

The Protection of Personal Information Act 4 of 2013 (POPIA)

POPIA applies to any business that processes personal information. Where a security compromise occurs, meaning personal information has been accessed, disclosed, or lost without authorisation, section 22 of POPIA requires notification to both the Information Regulator and the affected individuals as soon as reasonably possible. Non-compliance can result in fines of up to R10 million and, in serious cases, imprisonment of responsible persons.

Both pieces of legislation can apply to the same incident simultaneously. A well-structured cyber insurance policy will cover the costs of legal compliance following a breach, including regulatory notification, legal advice, and, where applicable, defence costs.

The cost of POPIA compliance following a breach, including notification, legal counsel, regulatory engagement, can be substantial for a small business. Cyber insurance cover for regulatory response costs can make the difference between a manageable incident and a financially devastating one.

Which Businesses Need Cyber Insurance?

The short answer is any business that uses a computer, stores client data, or processes payments electronically. In practice, the following types of businesses carry the highest exposure:

  • Professional practices: Attorneys, accountants, financial advisors, and healthcare providers hold large volumes of sensitive personal information and are high-value targets
  • Retail and e-commerce businesses: Online payment processing and customer data storage create multiple points of vulnerability
  • Small and medium enterprises: Frequently targeted because they are assumed to have fewer security controls than larger organisations
  • Property and construction businesses: High-value transactions and payment instruction communications create significant BEC exposure
  • Any business with remote or hybrid employees: Expanded attack surfaces and uncontrolled device environments increase risk

The businesses that believe they are too small to be targeted are, statistically, the most frequently attacked. Cybercriminals operate opportunistically and at scale. The cost of attempting to breach a small business is negligible, and the rewards are sufficient to justify the attempt.

Practical Steps for South African Businesses

Overberg Wealth & Risk Management assists clients in identifying their cyber risk exposure and ensuring their insurance arrangements address it. The following steps form the foundation of a sensible approach:

1. Audit Your Existing Insurance Cover

Review your current business, professional indemnity, and commercial policies to identify whether cyber losses are explicitly covered, excluded, or ambiguous. Do not assume cover exists. If in doubt, ask your financial advisor to provide written confirmation of what is and is not covered.

2. Assess Your Cyber Risk Profile

Identify what personal and financial data your business holds, how it is stored, who has access, and what the impact of a breach would be. The higher the value and sensitivity of the data you hold, the greater your exposure, and the more important adequate cover becomes.

3. Implement Baseline Security Controls

Cyber insurance does not replace security. It protects against losses when security measures fail. Insurers will typically require evidence of reasonable security controls as a condition of cover. These include strong password policies, multi-factor authentication, regular software updates, and encrypted data backups.

4. Train Your Staff

Approximately 78% of digital banking fraud in South Africa involves phishing. Human error is the most common point of failure. Staff training on identifying suspicious emails, verifying payment instructions, and reporting incidents is a requirement both for reducing risk and for maintaining the conditions of a cyber insurance policy.

5. Have an Incident Response Plan

Know what to do when an incident occurs. This includes isolating affected systems, preserving evidence, engaging your insurer, and meeting your regulatory reporting obligations under POPIA and the Cybercrimes Act. Your cyber insurance policy should include access to incident response support.

Conclusion

At Overberg Wealth & Risk Management, we help business owners understand their full risk exposure, including the cyber risks that standard policies leave uncovered, and put the right protection in place before it is needed.

Contact our team for advice and a free quote

Frequently Asked Questions

1. Does my existing business insurance cover cybercrime losses?

In most cases, no. Standard commercial and business insurance policies typically exclude or significantly limit cover for cyber-related losses, including data breaches, ransomware, and payment fraud. You should review your policy wording carefully or ask your broker to confirm your position in writing. A dedicated cyber insurance policy is the appropriate product for cyber-related risks.

2. What does cyber insurance cover in South Africa?

Cyber insurance typically covers both first-party losses, such as business interruption, data recovery, ransom payments, and regulatory notification costs, and third-party liability, including claims by clients whose data was compromised and costs arising from POPIA compliance obligations. Policy terms vary between insurers, and it is important to compare cover carefully.

3. Is cyber insurance expensive for small businesses?

Premiums vary depending on the size of the business, the type of data it holds, its security measures, and its industry. For many small businesses, the cost of a basic cyber insurance policy is modest relative to the potential losses from a single incident. Businesses with stronger security controls typically attract lower premiums. You may want to obtain a quote and compare it against your actual cyber risk exposure.

4. What are a South African business’s legal obligations after a data breach?

Under section 22 of POPIA, businesses must notify the Information Regulator and affected individuals as soon as reasonably possible after becoming aware of a security compromise involving personal information. Financial institutions and electronic communications service providers also have an obligation under section 54(1) of the Cybercrimes Act 19 of 2020 to report specific cyber offences to SAPS within 72 hours. Non-compliance with POPIA can result in fines of up to R10 million.

5. What steps should a business take immediately after a cyberattack?

Isolate affected systems to prevent further damage, preserve any evidence of the attack, notify your insurer as soon as possible, and take legal advice on your regulatory reporting obligations under POPIA and the Cybercrimes Act. Do not pay a ransom or engage with attackers without first consulting your insurer. Your cyber insurance policy should include access to incident response specialists who can guide you through the process.

 

 

 

While every reasonable effort is taken to ensure the accuracy and soundness of the contents of this publication, neither the writers of articles nor the publisher will bear any responsibility for the consequences of any actions based on information or recommendations contained herein. Our material is for informational purposes.

We use cookies to improve your experience on our website. By continuing to browse, you agree to our use of cookies
X