South Africa South Africa cybersecurity Bill SAPS

Rand Water Disclosed Its Cyberattack Because of a JSE Bond Rule, Not Any Cybersecurity Law

South Africa has no general duty for state entities to report cyberattacks — Rand Water spoke up only because it owes bondholders a covenant, not the public a law.

South Africa's Cyber-Disclosure Gap People of Internet Research · South Africa 72 hrs SAPS reporting window (dormant) Section 54 sets a 72-hour SAPS bre… ~5 yrs Years section 54 unenforced Carved out of the Act's Dec 2021 c… R50,000 Max fine, dormant provision Even if activated, section 54's pe… peopleofinternet.com
South Africa's Cyber-Disclosure Gap People of Internet Research · South Africa 72 hrs SAPS reporting window (dormant) ~5 yrs Years section 54 unenforced R50,000 Max fine, dormant provision peopleofinternet.com

Key Takeaways

A disclosure the law didn't require

On September 3, 2026, Rand Water — the bulk utility that supplies water to roughly 11 million people across Gauteng — told the market that a cybersecurity incident had crippled its payment software and GIS systems. The utility was careful to say water treatment, quality control and bulk supply kept running normally, with treasury operations shifted to disaster-recovery systems (TechCentral).

What's notable is why the public heard about it at all. Rand Water disclosed through a note to holders of its listed debt securities — a duty flowing from its presence on the JSE's debt board, not from any general South African cybersecurity statute. As TechCentral's reporting put it plainly: this is "a requirement not universally imposed on public sector entities," and absent that bond covenant, incidents at organs of state "tend to surface through leaks, auditor findings or the attackers themselves rather than through routine reporting."

The gap is real, and it is not a technicality

South Africa has two statutes that sound like they should cover this. Neither does.

POPIA's section 22 requires a "responsible party" to notify the Information Regulator and affected individuals of a security compromise — but only when there are reasonable grounds to believe personal information was accessed or acquired without authorisation (popia.co.za). An attack that disables payment processing or a GIS mapping system, without a confirmed personal-data exfiltration, may never trigger it.

The Cybercrimes Act 19 of 2020's section 54 looks closer to what critics are asking for: it would obligate a party to report a cybercrime to SAPS "without undue delay" and, where feasible, within 72 hours. But two things narrow it into irrelevance for this case. First, it applies only to "electronic communications service providers and financial institutions" — not water boards, municipalities or other organs of state (cybercrimesact.co.za). Second, and more strikingly, section 54 was deliberately carved out when the rest of Chapter 8 commenced on December 1, 2021 by presidential proclamation in Government Gazette 45562 (gov.za). Nearly five years later, it still hasn't been switched on (ITWeb). South Africa doesn't just lack a reporting duty for state entities — it has a narrower duty on paper, for a different set of actors, that has never been activated.

The case for a mandate, stated fairly

The argument for filling this gap is strong. Water, power, health and payment-clearing systems are exactly the infrastructure where an unreported breach compounds risk quietly: contractors, downstream municipalities and dependent utilities have no way to harden their own defences against a threat they don't know exists. Sunlight also disciplines incident response — JSE-listed entities that must speak to bondholders tend to patch and disclose faster than agencies that answer to no external clock. A National Cybersecurity Hub bulletin or a mandatory 72-hour SAPS report for organs of state, mirroring what section 54 already contemplates for the private sector, would close a structural blind spot that this incident has now made visible.

Why phasing it right matters more than passing it fast

But the smarter comparison isn't "other countries have breach laws" — it's South Africa's own record of writing a mandate it can't enforce. Section 54 sat dormant for a reason: the Cybercrimes Act's section 55 requires the police minister to build "sufficient human and operational capacity" to receive and act on these reports, including a 24-hour point of contact, before the reporting duty makes sense to switch on. SAPS's cybercrime capacity — chronically under-resourced on both staffing and budget — is precisely why regulators keep deferring the very provision meant to test it.

Extending a reporting mandate to every organ of state without first funding that intake capacity would produce theatre, not transparency: a rule on the books, ignored in practice, exactly like section 54 today. It would also invite a blunt instrument — treating a GIS outage at a water board the same as a ransomware attack on a hospital's patient records — when what utilities actually need is a tiered framework, proportionate to which systems (operational technology vs. back-office IT) were hit and what data was actually exposed.

The proportionate fix

The honest reading of Rand Water's disclosure isn't that South Africa needs another sweeping bill — it's that it should first commence the provision it already wrote, extend its scope from private ECSPs to critical-infrastructure organs of state, and pair that with the SAPS capacity-building section 55 already demands. A reporting duty that nobody can process is worse than the silence it replaces, because it manufactures false assurance. Build the intake first; then flip the switch everyone can already find in the statute book.

Sources & Citations

  1. Cybercrimes Act 19 of 2020 (gov.za, official text/commencement)
  2. POPIA Section 22 — Notification of Security Compromises
  3. TechCentral: Cyberattack hits South Africa's biggest water utility
  4. ITWeb: Some sections of Cyber Crimes Act now in force
  5. Cybercrimes Act — Section 54 obligations (ECSPs/financial institutions)