PSiRA may expand its regulation of cybersecurity services in South Africa. What would this mean for cybersecurity service providers? How do you, as a cybersecurity service provider, feel about being regulated by the Private Security Industry Regulatory Authority (PSiRA)? PSiRA, which regulates physical security in South Africa, now wishes to extend its mandate to the regulation of cybersecurity services. This has significant practical implications for cybersecurity service providers, for example, registration, codes of conduct, and enforcement.
Are you ready for this additional red tape?
PSiRA regulates the private security industry in South Africa. It mainly oversees physical security services, such as security guards, armed response companies, and other related types of protection services. Under the Private Security Industry Regulation Act 56 of 2001 (PSiRA Act), companies that provide these physical security services must register with PSiRA and follow its rules. However, as cybercrime and online threats continue to grow, PSiRA is now exploring whether cybersecurity services should also fall under its regulatory authority.
Who would be regulated?
- Cybersecurity Service Providers (CSSPs) (i.e., Cloudflare, Mimecast, etc.).
- Managed Security Service Providers (MSSPs).
- Cybersecurity consulting firms.
If your company is in the business of protecting systems, networks, or data for a fee, this definition might be about you.
According to section 1 of the PSIR Act, a security service provider is defined as a person who provides a security service to another for payment or benefit, including those who are not registered under the Act. PSiRA argues that cybersecurity service providers and related professionals fall under this definition as they safeguard digital systems and data for clients for remuneration.
What would they likely have to do?
- Register with PSiRA (there is a registration Fee).
- Comply with PSiRA’s code of conduct as it is legally binding.
- PSiRA might introduce minimum training standards that these cybersecurity service providers would also be required to comply with.
- Be subject to enforcement action by PSiRA if they contravene the Act or its Code of Conduct.
How we can help you with the regulation of cybersecurity services
- Comply with cybersecurity regulations by joining our cybersecurity compliance programme.
- Respond to PSiRA’s plans by asking us to put on a webinar to unpack this with other cybersecurity providers.