A disclosure the law didn't require
On September 3, 2026, Rand Water — the bulk utility that supplies water to roughly 11 million people across Gauteng — told the market that a cybersecurity incident had crippled its payment software and GIS systems. The utility was careful to say water treatment, quality control and bulk supply kept running normally, with treasury operations shifted to disaster-recovery systems (TechCentral).
What's notable is why the public heard about it at all. Rand Water disclosed through a note to holders of its listed debt securities — a duty flowing from its presence on the JSE's debt board, not from any general South African cybersecurity statute. As TechCentral's reporting put it plainly: this is "a requirement not universally imposed on public sector entities," and absent that bond covenant, incidents at organs of state "tend to surface through leaks, auditor findings or the attackers themselves rather than through routine reporting."
The gap is real, and it is not a technicality
South Africa has two statutes that sound like they should cover this. Neither does.
POPIA's section 22 requires a "responsible party" to notify the Information Regulator and affected individuals of a security compromise — but only when there are reasonable grounds to believe personal information was accessed or acquired without authorisation (popia.co.za). An attack that disables payment processing or a GIS mapping system, without a confirmed personal-data exfiltration, may never trigger it.
The Cybercrimes Act 19 of 2020's section 54 looks closer to what critics are asking for: it would obligate a party to report a cybercrime to SAPS "without undue delay" and, where feasible, within 72 hours. But two things narrow it into irrelevance for this case. First, it applies only to "electronic communications service providers and financial institutions" — not water boards, municipalities or other organs of state (cybercrimesact.co.za). Second, and more strikingly, section 54 was deliberately carved out when the rest of Chapter 8 commenced on December 1, 2021 by presidential proclamation in Government Gazette 45562 (gov.za). Nearly five years later, it still hasn't been switched on (ITWeb). South Africa doesn't just lack a reporting duty for state entities — it has a narrower duty on paper, for a different set of actors, that has never been activated.
The case for a mandate, stated fairly
The argument for filling this gap is strong. Water, power, health and payment-clearing systems are exactly the infrastructure where an unreported breach compounds risk quietly: contractors, downstream municipalities and dependent utilities have no way to harden their own defences against a threat they don't know exists. Sunlight also disciplines incident response — JSE-listed entities that must speak to bondholders tend to patch and disclose faster than agencies that answer to no external clock. A National Cybersecurity Hub bulletin or a mandatory 72-hour SAPS report for organs of state, mirroring what section 54 already contemplates for the private sector, would close a structural blind spot that this incident has now made visible.
Why phasing it right matters more than passing it fast
But the smarter comparison isn't "other countries have breach laws" — it's South Africa's own record of writing a mandate it can't enforce. Section 54 sat dormant for a reason: the Cybercrimes Act's section 55 requires the police minister to build "sufficient human and operational capacity" to receive and act on these reports, including a 24-hour point of contact, before the reporting duty makes sense to switch on. SAPS's cybercrime capacity — chronically under-resourced on both staffing and budget — is precisely why regulators keep deferring the very provision meant to test it.
Extending a reporting mandate to every organ of state without first funding that intake capacity would produce theatre, not transparency: a rule on the books, ignored in practice, exactly like section 54 today. It would also invite a blunt instrument — treating a GIS outage at a water board the same as a ransomware attack on a hospital's patient records — when what utilities actually need is a tiered framework, proportionate to which systems (operational technology vs. back-office IT) were hit and what data was actually exposed.
The proportionate fix
The honest reading of Rand Water's disclosure isn't that South Africa needs another sweeping bill — it's that it should first commence the provision it already wrote, extend its scope from private ECSPs to critical-infrastructure organs of state, and pair that with the SAPS capacity-building section 55 already demands. A reporting duty that nobody can process is worse than the silence it replaces, because it manufactures false assurance. Build the intake first; then flip the switch everyone can already find in the statute book.