Cybersecurity Law

Cybersecurity or information security is a crucial part of information management. We are experts on the legal aspects regards the security of information (infosec). You can read our advice, or about the products or services we offer related to this focus area below:

Executive cyber liability risks

Time to talk about executive cyber liability risks. Managing cybersecurity and compliance at a senior level carries more significant personal risks than ever. Regulators worldwide are increasingly holding individual executives, such as Chief Information Security Officers (CISOs) and Chief Compliance [...]

By |2025-03-27T16:00:19+02:00March 27th, 2025|Categories: Cybersecurity Law|Tags: |

Cybersecurity law compliance: Getting it ‘just right’

Like Goldilocks sampling porridge, businesses face the challenge of getting their cybersecurity measures 'just right' — not too weak to invite breaches nor too cumbersome to stifle operations. In today's landscape, fraught with AI-driven scams and rampant ransomware attacks, achieving [...]

By |2025-03-27T16:17:39+02:00March 20th, 2025|Categories: Cybersecurity Law|Tags: |

Implementing the cybersecurity triad

Implementing the cybersecurity triad effectively is like managing traffic at a busy intersection. 'Confidentiality', 'Integrity', and 'Availability' each represent a different stream of traffic. If one stream isn't managed correctly, it disrupts everything, causing chaos and risks to security. Cyber [...]

By |2025-03-18T19:10:59+02:00March 18th, 2025|Categories: Cybersecurity Law|Tags: |

AI voice cloning scams

Artificial intelligence (AI) brings convenience to our lives, but imagine your voice being stolen and used as a weapon by criminals. AI voice cloning scams use your voice, or that of someone you trust, to deceive you into transferring money [...]

By |2025-03-18T13:54:08+02:00March 17th, 2025|Categories: AI Governance, Cybersecurity Law|Tags: , , , |

Information security vs cyber security: What’s the difference?

Information Security vs Cyber Security - what’s the Difference? Information security and cybersecurity are not separate concepts—they are the same discipline applied in different eras. Information security existed long before digital technology, focusing on protecting physical records and sensitive information. [...]

By |2025-10-07T14:44:32+02:00February 26th, 2025|Categories: Cybersecurity Law|Tags: , , |

Joint Standard on Cybersecurity and Cyber Resilience Requirements

The Joint Standard on Cybersecurity and Cyber Resilience Requirements sets the minimum standards for financial institutions to implement best practices and processes to identify and guard against cybersecurity and cyber resilience risks. The Financial Sector Conduct Authority (FSCA) and the [...]

By |2026-05-06T09:39:25+02:00February 24th, 2025|Categories: Cybersecurity Law|Tags: , , |

Enterprise security policy development

Cybersecurity is a necessity for all organisations today, not a luxury. Modern businesses face complex and evolving threats targeting their data, networks, and systems. Even one vulnerability can result in severe breaches, financial loss, and damage to reputation. Just as [...]

By |2024-09-12T17:35:20+02:00September 12th, 2024|Categories: Cybersecurity Law|Tags: |

DoJ enforcement action | Personal information compromise

The Information Regulator’s DoJ enforcement action, followed by the DoJ infringement notice, highlights the risks of failing to address a personal information compromise under the Protection of Personal Information Act (POPIA). The Department of Justice (DoJ) failed to secure the [...]

Cybersecurity risks in the two-pot retirement system

Picture your retirement savings as a fortress: one side built up over the years, while a new door suddenly appears, unlocked. This is South Africa's two-pot retirement system, launched on 1 September 2024, giving people early access to their retirement [...]

By |2024-09-11T10:34:17+02:00September 11th, 2024|Categories: Cybersecurity Law|Tags: , , |

Information security incident reports

Navigating the stormy seas of information security requires more than just a robust ship; it also demands a vigilant crew equipped with precise navigation tools. Information security incident reports are essential tools in the world of data protection. This document [...]

By |2024-08-13T18:00:45+02:00August 13th, 2024|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

Privacy obligations in the BEC case of ENS v Hawarden

In the matter of ENS v Hawarden, the SCA overturned the judgment in the High Court in Gauteng, holding ENS liable for the loss suffered by Mrs Hawarden because of a business email compromise. The SCA's finding is primarily based [...]

CrowdStrike outage: What happened and what we can learn?

On Friday, 19 July 2024, a global IT outage disrupted many users worldwide. CrowdStrike, a leading cybersecurity firm, released a faulty security update that caused Microsoft Windows devices to crash. The CrowdStrike outage impacted Microsoft's Windows 365 Cloud PCs, apps, [...]

By |2024-07-23T15:23:29+02:00July 23rd, 2024|Categories: Cybersecurity Law|Tags: , |