← Articles · Cybersecurity · South Africa · Skills Gap

South Africa has a
cybersecurity crisis and
not enough developers to fix it. Here is what to do.

Two-thirds of South African government departments are vulnerable to cyberattacks right now. The World Bank says the digital skills pipeline is not meeting demand. SABS was shut down by a ransomware attack. Cybercrime costs South Africa billions annually. The education system cannot fix this fast enough. The practical answer for SA businesses is not to wait — it is to outsource to organisations that already have the expertise.

Jarrit Hosking
Forge Vertical · Cape Town · September 9, 2026 · Active HackerOne researcher
12 min read
// The scale of what South Africa is facing

Let us start with the number that should be in every boardroom in South Africa right now: two-thirds. Two-thirds of assessed South African government departments are vulnerable to cyberattacks — not because of sophisticated nation-state adversaries exploiting zero-days, but because of missing backup systems and disaster recovery plans that have never been tested. Basic. Foundational. Missing.

The South African Bureau of Standards (SABS) found this out the hard way. A ransomware attack caused major operational shutdowns and data encryption — forcing a public entity responsible for national standards to halt operations while attackers held its data. That is not an edge case. That is what happens when cybersecurity is treated as a budget line rather than an operational requirement.

The World Bank's September 2026 report on South Africa's digital skills pipeline is equally direct: the education system is producing graduates, but not the graduates the economy needs. There is a structural mismatch between what employers require — software developers, network engineers, cybersecurity specialists — and what the pipeline delivers. High unemployment coexists with critical skill shortages because the unemployment is in categories the economy is moving away from, and the shortage is in categories the economy is moving toward.

66%
Govt depts vulnerable to attack
Billions
Cybercrime cost annually
Critical
Shortage: developers + security
88.1%
WC internet access — most exposed

The three problems that compound each other

// Chapter 01 — Why this is harder than it looks
🔓
The skills gap is structural, not temporary
The World Bank report does not describe a short-term mismatch that will resolve as graduates enter the market. It describes a structural pipeline failure — unequal device access in schools, unreliable internet in educational institutions, and foundational digital training gaps that mean students arrive at tertiary level without the prerequisites for technology careers. Fixing this takes a decade of sustained investment. South African businesses do not have a decade to wait.
Legacy systems cannot be secured with modern tools
Many South African public and private sector organisations are running legacy systems that predate modern security architecture. These systems were not designed to integrate with cloud security tools, AI-powered threat detection, or modern authentication frameworks. Securing them requires specialist knowledge of both the legacy environment and the modern security landscape — a combination that is exceptionally rare and expensive to hire permanently.
🌐
Higher connectivity = higher attack surface
The Western Cape's 88.1% internet access rate — the highest in South Africa — is a development achievement and a security liability simultaneously. More connected systems, more exposed endpoints, more remote access, more cloud-hosted data. The attack surface grows proportionally with connectivity. The security investment has not kept pace. The organisations with the most to protect have often invested the least in protecting it.

What the attack landscape actually looks like for SA businesses

// Chapter 02 — What you are up against

The cybercrime targeting South African businesses is not primarily sophisticated. It is opportunistic — and opportunistic attacks succeed because of the exact vulnerabilities the World Bank and the Auditor General have documented: missing backups, untested recovery plans, unpatched systems, weak authentication, and staff who have not been trained to recognise phishing attempts.

Ransomware is the most common and most damaging. An attacker gains access — often through a phishing email that a staff member clicks — encrypts the organisation's data, and demands payment for the decryption key. If backups exist and are current and tested, the organisation recovers. If they do not — as is the case for two-thirds of assessed government departments — the choice is between paying criminals and losing data permanently.

Business email compromise is the financial category. An attacker gains access to or spoofs a senior employee's email account and instructs the finance department to transfer funds to a fraudulent account. South African businesses have lost hundreds of millions of rands to this attack type. It requires no technical sophistication — just a convincing email and an absence of verification protocols.

Supply chain attacks are growing. Your organisation may have reasonable security — but if your software supplier, your cloud provider, or your managed service partner does not, their compromise becomes your exposure. The 2025 Hugging Face breach that delayed GPT-6 Astra's release is a global example of exactly this attack type at scale.

The accountability gap: South African cybercrime costs billions annually, worsened by a lack of accountability and slow implementation of security recommendations. Auditor General reports have flagged missing disaster recovery plans repeatedly. The same vulnerabilities appear in consecutive annual reports. The problem is not that South Africa does not know what needs to be done — it is that implementation is not happening. For private sector businesses, waiting for the government to set the standard is not a strategy.
The most common cybersecurity failures in South Africa are not sophisticated. They are basic. Missing backups. Untested recovery plans. Unpatched systems. Weak passwords. Staff who clicked a link. Every one of these is preventable with the right expertise applied before the attack, not after.

The outsourcing case — why it is the practical answer

// Chapter 03 — What to do when you cannot hire what you need

A senior cybersecurity specialist in South Africa commands a salary that most SMEs and even many mid-sized enterprises cannot sustain as a permanent hire. The skills are scarce. The market rate reflects that scarcity. And a single hired expert covers one specialisation — you need penetration testing expertise, incident response capability, infrastructure hardening knowledge, and ongoing monitoring. That is four roles in a market where one is already difficult to fill.

Outsourcing to specialist organisations solves this at a fraction of the cost of hiring. You get access to a team rather than an individual, expertise across the full security stack rather than one specialisation, and a working relationship that adapts as your needs change rather than a fixed headcount that either under-delivers during quiet periods or is overwhelmed during incidents.

The businesses that should be considering outsourcing are not just enterprises. They are any South African organisation that:

// Profile 01
SMEs with customer data
Any business holding customer personal information is subject to POPIA. A data breach is not just a reputational problem — it is a regulatory liability. SMEs are disproportionately targeted because attackers know their security posture is typically weaker than enterprises. Outsourced security is affordable at SME scale. A breach is not.
// Profile 02
Businesses with online payment systems
Any organisation processing payments online has PCI-DSS obligations and a payment system that is actively targeted. A vibe-coded checkout, an unaudited payment integration, or an e-commerce platform running on an outdated plugin set is a liability. Outsourced security review and hardening of payment infrastructure is not optional — it is the cost of doing business online responsibly.
// Profile 03
Organisations on legacy systems
Legacy systems cannot be secured by generalist IT staff who have not worked with them specifically. And they cannot simply be replaced overnight. A specialist who understands the security boundaries of legacy South African government and corporate systems — and knows how to harden them without breaking the business processes that depend on them — is a scarce resource that outsourcing makes accessible.
// Profile 04
Growing businesses adding digital services
A business that is adding an app, a client portal, or an API integration is adding attack surface simultaneously. Security built into the development process costs a fraction of security added after a breach. Outsourcing security review during development — not just after launch — is the correct sequencing.

What outsourced security should actually include

// Chapter 04 — What to look for and what to ask

Not all outsourced security services are equivalent. The market includes genuine expertise and it includes resellers of automated scanning tools that produce reports without producing security. When evaluating an outsourced security partner for your South African business, ask specifically for:

Penetration testing with human analysis. Automated scanners find known vulnerabilities. Human penetration testers find the vulnerabilities that scanners miss — the logic flaws, the authentication bypasses, the business-specific attack paths. Ask whether the test is fully automated, partially automated with human review, or fully manual. The answer tells you a great deal about the quality of the engagement.

Backup verification — not just backup existence. Having a backup is not the same as having a working backup. The two-thirds of government departments with missing or untested disaster recovery plans almost certainly believe they have backups. The test is whether those backups can be restored, how long restoration takes, and whether the restored system works. An outsourced security review should include verification that your backups actually restore — not just that they run.

Staff phishing simulation. The most sophisticated security infrastructure fails when a staff member clicks the wrong link. Simulated phishing campaigns — where the security partner sends realistic phishing emails to your staff and measures click rates — are the only honest assessment of your human attack surface. The results are often uncomfortable. They are always useful.

POPIA compliance review. South Africa's Protection of Personal Information Act imposes specific obligations on how personal data is stored, processed, and protected. A security review that does not include POPIA compliance assessment is incomplete for any South African organisation handling customer data.

// Forge Vertical's security research credentials Forge Vertical operates as an active security researcher on HackerOne, Bugcrowd, and YesWeHack. We hold active Anthropic Cyber Verification Programme (CVP) approval — one of a small number of organisations globally with expanded AI capability access for dual-use cybersecurity research. Our security work covers CI/CD vulnerabilities, web application security, and penetration testing within safe harbour agreements. We are not just building websites — we are actively finding vulnerabilities in production systems and reporting them responsibly. That hands-on research is what informs the security advice we give to clients.
// Work with Forge Vertical
Security-first development and cybersecurity outsourcing for South African businesses
Forge Vertical builds websites, SaaS platforms, and AI-integrated systems with security hardened from the first commit — not bolted on after launch. We also provide security review services, penetration testing for web applications, POPIA compliance assessment, and Cloudflare configuration for South African businesses that need expertise they cannot justify hiring full-time. Active HackerOne researcher. Anthropic CVP approved. Cape Town based, global scope.

The skills gap is real — but it is not your problem to solve alone

// Chapter 05 — The conclusion

South Africa's digital skills shortage is a systemic problem that will take years to address through education reform, infrastructure investment, and coordinated policy. None of that happens fast enough to protect your business from the ransomware campaign that is running right now, the phishing attempt that will land in your staff's inbox next week, or the unpatched vulnerability in your legacy system that an attacker will find before you do.

The practical response to a systemic problem is not to wait for the system to fix itself. It is to access the expertise that exists — through outsourcing relationships with specialist organisations that have already done the work of building the skills the market cannot hire fast enough.

There are genuinely good cybersecurity businesses operating in South Africa. Forge Vertical is one of them, with active researcher credentials and production security work to back the claim. There are others. Find one. Engage them before an incident forces the conversation. The cost of prevention is always smaller than the cost of recovery — especially in a country where two-thirds of government departments cannot recover at all.

Written by
Jarrit Hosking
Forge Vertical · Cape Town · September 9, 2026 · Active HackerOne researcher