South Africa has a
cybersecurity crisis and
not enough developers to fix it. Here is what to do.
Two-thirds of South African government departments are vulnerable to cyberattacks right now. The World Bank says the digital skills pipeline is not meeting demand. SABS was shut down by a ransomware attack. Cybercrime costs South Africa billions annually. The education system cannot fix this fast enough. The practical answer for SA businesses is not to wait — it is to outsource to organisations that already have the expertise.
Let us start with the number that should be in every boardroom in South Africa right now: two-thirds. Two-thirds of assessed South African government departments are vulnerable to cyberattacks — not because of sophisticated nation-state adversaries exploiting zero-days, but because of missing backup systems and disaster recovery plans that have never been tested. Basic. Foundational. Missing.
The South African Bureau of Standards (SABS) found this out the hard way. A ransomware attack caused major operational shutdowns and data encryption — forcing a public entity responsible for national standards to halt operations while attackers held its data. That is not an edge case. That is what happens when cybersecurity is treated as a budget line rather than an operational requirement.
The World Bank's September 2026 report on South Africa's digital skills pipeline is equally direct: the education system is producing graduates, but not the graduates the economy needs. There is a structural mismatch between what employers require — software developers, network engineers, cybersecurity specialists — and what the pipeline delivers. High unemployment coexists with critical skill shortages because the unemployment is in categories the economy is moving away from, and the shortage is in categories the economy is moving toward.
The three problems that compound each other
// Chapter 01 — Why this is harder than it looksWhat the attack landscape actually looks like for SA businesses
// Chapter 02 — What you are up againstThe cybercrime targeting South African businesses is not primarily sophisticated. It is opportunistic — and opportunistic attacks succeed because of the exact vulnerabilities the World Bank and the Auditor General have documented: missing backups, untested recovery plans, unpatched systems, weak authentication, and staff who have not been trained to recognise phishing attempts.
Ransomware is the most common and most damaging. An attacker gains access — often through a phishing email that a staff member clicks — encrypts the organisation's data, and demands payment for the decryption key. If backups exist and are current and tested, the organisation recovers. If they do not — as is the case for two-thirds of assessed government departments — the choice is between paying criminals and losing data permanently.
Business email compromise is the financial category. An attacker gains access to or spoofs a senior employee's email account and instructs the finance department to transfer funds to a fraudulent account. South African businesses have lost hundreds of millions of rands to this attack type. It requires no technical sophistication — just a convincing email and an absence of verification protocols.
Supply chain attacks are growing. Your organisation may have reasonable security — but if your software supplier, your cloud provider, or your managed service partner does not, their compromise becomes your exposure. The 2025 Hugging Face breach that delayed GPT-6 Astra's release is a global example of exactly this attack type at scale.
The outsourcing case — why it is the practical answer
// Chapter 03 — What to do when you cannot hire what you needA senior cybersecurity specialist in South Africa commands a salary that most SMEs and even many mid-sized enterprises cannot sustain as a permanent hire. The skills are scarce. The market rate reflects that scarcity. And a single hired expert covers one specialisation — you need penetration testing expertise, incident response capability, infrastructure hardening knowledge, and ongoing monitoring. That is four roles in a market where one is already difficult to fill.
Outsourcing to specialist organisations solves this at a fraction of the cost of hiring. You get access to a team rather than an individual, expertise across the full security stack rather than one specialisation, and a working relationship that adapts as your needs change rather than a fixed headcount that either under-delivers during quiet periods or is overwhelmed during incidents.
The businesses that should be considering outsourcing are not just enterprises. They are any South African organisation that:
What outsourced security should actually include
// Chapter 04 — What to look for and what to askNot all outsourced security services are equivalent. The market includes genuine expertise and it includes resellers of automated scanning tools that produce reports without producing security. When evaluating an outsourced security partner for your South African business, ask specifically for:
Penetration testing with human analysis. Automated scanners find known vulnerabilities. Human penetration testers find the vulnerabilities that scanners miss — the logic flaws, the authentication bypasses, the business-specific attack paths. Ask whether the test is fully automated, partially automated with human review, or fully manual. The answer tells you a great deal about the quality of the engagement.
Backup verification — not just backup existence. Having a backup is not the same as having a working backup. The two-thirds of government departments with missing or untested disaster recovery plans almost certainly believe they have backups. The test is whether those backups can be restored, how long restoration takes, and whether the restored system works. An outsourced security review should include verification that your backups actually restore — not just that they run.
Staff phishing simulation. The most sophisticated security infrastructure fails when a staff member clicks the wrong link. Simulated phishing campaigns — where the security partner sends realistic phishing emails to your staff and measures click rates — are the only honest assessment of your human attack surface. The results are often uncomfortable. They are always useful.
POPIA compliance review. South Africa's Protection of Personal Information Act imposes specific obligations on how personal data is stored, processed, and protected. A security review that does not include POPIA compliance assessment is incomplete for any South African organisation handling customer data.
The skills gap is real — but it is not your problem to solve alone
// Chapter 05 — The conclusionSouth Africa's digital skills shortage is a systemic problem that will take years to address through education reform, infrastructure investment, and coordinated policy. None of that happens fast enough to protect your business from the ransomware campaign that is running right now, the phishing attempt that will land in your staff's inbox next week, or the unpatched vulnerability in your legacy system that an attacker will find before you do.
The practical response to a systemic problem is not to wait for the system to fix itself. It is to access the expertise that exists — through outsourcing relationships with specialist organisations that have already done the work of building the skills the market cannot hire fast enough.
There are genuinely good cybersecurity businesses operating in South Africa. Forge Vertical is one of them, with active researcher credentials and production security work to back the claim. There are others. Find one. Engage them before an incident forces the conversation. The cost of prevention is always smaller than the cost of recovery — especially in a country where two-thirds of government departments cannot recover at all.