infosec law

EU Data Act switching: cloud exits

A company group with a subsidiary in the EU decides that the cloud SaaS platform it has used for years is no longer the right fit. EU Data Act switching rules now shape what happens next. Legal counsel is asked [...]

Cybersecurity flow-down clauses – Whose compliance obligations?

A security addendum arrives from a customer. They want incident notification within 24 hours, the right to audit you on site, approval before you change a subcontractor, and cooperation with their penetration testing. These are cybersecurity flow-down clauses: contractual terms [...]

By |2026-08-12T13:35:29+02:00August 12th, 2026|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

POPIA’s security requirement – A cybersecurity primer for IOs

Think of security compliance the way you think of a vehicle’s roadworthiness test. The certificate matters, but you only stay safe if the brakes still work today. POPIA's security requirement is not a maintenance checklist or a once-off project. POPIA […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.
By |2026-03-04T09:56:05+02:00March 3rd, 2026|Categories: Cybersecurity Law|Tags: |

Cybersecurity compliance for officers – From librarian to navigator

Let's talk cybersecurity compliance for officers. Many organisations treat cybersecurity compliance like a library. They collect policies, file them away, and assume that because the shelf is complete, the building is safe. But in 2026, regulators aren't looking for a [...]

By |2026-02-11T17:47:00+02:00January 22nd, 2026|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

DORA compliance for vendors – a practical playbook

DORA compliance for vendors is now a live requirement, and selling technology to European financial firms is therefore like constructing a new building in a crowded city: you must meet the code, welcome inspections, and prove the structure can take [...]

By |2025-11-14T19:33:31+02:00November 14th, 2025|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

Telco cybersecurity in South Africa – finding a signal in the noise

Let's talk telco cybersecurity in South Africa. Securing a telecommunications network is like trying to tune into a radio station amid heavy static: operators must carefully adjust both their security controls and their compliance processes to cut through the noise. [...]

Cybersecurity compliance mapping – finding every obligation

What is cybersecurity compliance mapping? Navigating cybersecurity compliance today is like conducting a precise archaeological dig: you must carefully uncover each layer of obligations without damaging your organisation's underlying structure. Each jurisdiction, sector, and obligation presents distinct challenges, demanding meticulous [...]

By |2025-07-31T11:41:07+02:00July 22nd, 2025|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

Data classification best practices

We've all got that chaotic drawer at home — a messy collection of old chargers, mystery keys, forgotten receipts, and batteries that may or may not work. While such clutter at home might only cause mild frustration, allowing your business [...]

Cybersecurity is mission-critical

Imagine your business as a body, thriving and responding to opportunities, with your digital systems acting as its nervous system. Just as any impairment to nerves can paralyse a body, a cybersecurity breach can disrupt or incapacitate your organisation. Cybersecurity [...]

By |2025-07-10T10:47:28+02:00July 10th, 2025|Categories: Cybersecurity Law|Tags: |

Cybersecurity compliance fairy tales – dispelling the myths

It's cybersecurity compliance fairy tale storytime. Let's banish them to the past, where they belong. Cybersecurity compliance can feel like chasing dragons — many discuss it, but few truly understand how to implement it effectively. Organisations often mistakenly believe that [...]

By |2025-06-05T18:29:44+02:00June 5th, 2025|Categories: Cybersecurity Law|Tags: |

South African cybersecurity laws – unravelling the knot

Understanding South African cybersecurity laws can feel like trying to cut through the legendary Gordian knot - a challenging yet essential task. Cyber threats are increasing rapidly, making it crucial for organisations in South Africa to understand these regulations clearly. [...]

By |2025-10-20T09:32:08+02:00June 4th, 2025|Categories: Cybersecurity Law|Tags: |

King V and cybersecurity – locking down corporate governance

The King V Code is changing corporate governance in South Africa by moving cybersecurity from a purely technical issue to a central responsibility for company boards. The Institute of Directors in Southern Africa (IoDSA) published King V's draft on 24 [...]

By |2025-05-26T14:58:04+02:00May 26th, 2025|Categories: Cybersecurity Law, Governance|Tags: , , |