A grid that used to be one building is now millions of endpoints
For most of its history, Eskom's attack surface was a handful of power stations and control rooms — physically guarded, air-gapped where it mattered, and legible to a security planner in a way a single building is legible. That model is gone. Eskom is in the middle of installing smart meters on load-reduction feeders across the country, with more than 500,000 units already in the ground and Fortinet noting the utility's stated ambition to reach 6 million over the next three years (EWN; IT-Online). Layer on the independent power producers now feeding wind and solar into the same transmission network, and the grid has quietly become one of the largest distributed IoT deployments in the country — with each meter, inverter, and interconnection point a possible way in.
That is the premise behind Fortinet's June 29, 2026 warning, delivered by the firm's Martin Fernandes: the Critical Infrastructure Protection Act, 2019 — now fully commenced — has to be read as covering "every asset, from a residential smart meter to a massive wind farm" as a protected sovereign asset, not just the power stations the apartheid-era National Key Points Act was built to guard (IT-Online).
The case for treating a meter like a substation
The steelman here is straightforward and, on the technical merits, correct. A smart meter is not a passive dumb box; it is a two-way networked device sitting on the same logical grid as the transmission network it reports to, and a fleet of half a million (heading to six million) of them is a genuinely large attack surface that didn't exist when the old National Key Points Act was drafted. Fortinet's warning specifically points to a late-2025 incident in Poland's energy sector — serious enough to prompt a CISA global alert in February 2026 — in which attackers used distributed energy resources to deploy destructive tools that crippled remote terminal units and wiped human-machine interface data (IT-Online). Eskom's own recent history is not reassuring: in March 2022 the Everest ransomware gang claimed to have exfiltrated server credentials from Eskom's network and offered them for sale on the dark web. IPPs make the exposure worse, not better, in one specific sense — a private producer's network is typically less hardened than Eskom's core systems, and Fortinet is right that every interconnection point is a potential lateral-movement path into the national grid. A legal framework that formally designates grid-adjacent connected devices as critical infrastructure, with defined reporting obligations and an inspection regime, is a reasonable response to a real and growing risk. The Critical Infrastructure Protection Act, assented to in November 2019 and brought into force by Government Gazette 46024 of 10 March 2022, was built precisely to replace the narrower National Key Points Act with a broader, criteria-based designation process overseen by a Critical Infrastructure Council (gov.za; gov.za Council notice).
Where the argument runs ahead of the state's capacity
What Fortinet's framing elides is that South Africa's problem with Eskom infrastructure has never really been a shortage of legal designation — it has been a shortage of execution capacity, and the smart-meter rollout is itself the clearest illustration of that gap. Eskom missed its own March 2026 target of 577,347 meters installed on priority load-reduction feeders, running roughly 52% behind schedule, and more than 122,000 planned installations have been postponed specifically because of intimidation, violent incidents, and repeated work stoppages against the installation teams (ITWeb). Layering a sovereign-critical-infrastructure designation onto a fleet the utility cannot even physically install on schedule does not, by itself, produce better-secured meters — it produces a longer list of nominally protected assets that the same stretched security and inspection apparatus has to somehow cover. Analysts assessing the Act's predecessor bill made the same point about the broader grid years before smart meters entered the picture: security agencies tasked with protecting Eskom infrastructure were already under-resourced and prone to "factionalism, mismanagement and inefficiency," and extending the perimeter of what counts as critical infrastructure does nothing to fix that unless it comes with matching investment in the people and processes doing the protecting (The Conversation).
There is also a proportionality question the Act's designation framework doesn't yet answer well. Not every one of six million meters carries the same risk profile as a substation or an IPP interconnection point, and treating a residential meter and a wind-farm gateway as equivalent "sovereign assets" invites either uniform over-regulation that slows an already-delayed rollout further, or selective under-enforcement that undermines the designation's credibility. A tiered approach — differentiated security and reporting obligations scaled to a device's actual position in the grid topology, rather than a blanket sovereign-asset label — would let Eskom keep installing meters at the pace load-reduction relief actually requires, while concentrating scarce inspection and incident-response capacity on the interconnection points and control systems where a breach could genuinely cascade. The CIPA gives South Africa the legal vocabulary to do that. Whether the Critical Infrastructure Council uses it to differentiate risk, or simply expands the designated perimeter without expanding capacity to match, will determine whether this law makes the grid more secure or just makes the paperwork more sovereign.