South Africa connected devices IoT security regulation

South Africa's Critical Infrastructure Law Now Covers 500,000 Smart Meters — Enforcement Capacity Hasn't Caught Up

Fortinet says every Eskom smart meter and IPP connection is now sovereign infrastructure under the CIPA — but the rollout is 52% behind schedule.

South Africa's Smart Grid, By the Numbers People of Internet Research · South Africa 500,000+ Smart meters installed Installed on Eskom load-reduction … 6 million Three-year rollout target Eskom's stated smart meter target,… ~52% Behind installation schedule Eskom missed its March 2026 target… 122,000+ Installs postponed to violence Delayed due to intimidation and wo… peopleofinternet.com
South Africa's Smart Grid, By the Numb… People of Internet Research · South Africa 500,000+ Smart meters installed 6 million Three-year rollout target ~52% Behind installation sch… 122,000+ Installs postponed to vio… peopleofinternet.com

Key Takeaways

A grid that used to be one building is now millions of endpoints

For most of its history, Eskom's attack surface was a handful of power stations and control rooms — physically guarded, air-gapped where it mattered, and legible to a security planner in a way a single building is legible. That model is gone. Eskom is in the middle of installing smart meters on load-reduction feeders across the country, with more than 500,000 units already in the ground and Fortinet noting the utility's stated ambition to reach 6 million over the next three years (EWN; IT-Online). Layer on the independent power producers now feeding wind and solar into the same transmission network, and the grid has quietly become one of the largest distributed IoT deployments in the country — with each meter, inverter, and interconnection point a possible way in.

That is the premise behind Fortinet's June 29, 2026 warning, delivered by the firm's Martin Fernandes: the Critical Infrastructure Protection Act, 2019 — now fully commenced — has to be read as covering "every asset, from a residential smart meter to a massive wind farm" as a protected sovereign asset, not just the power stations the apartheid-era National Key Points Act was built to guard (IT-Online).

The case for treating a meter like a substation

The steelman here is straightforward and, on the technical merits, correct. A smart meter is not a passive dumb box; it is a two-way networked device sitting on the same logical grid as the transmission network it reports to, and a fleet of half a million (heading to six million) of them is a genuinely large attack surface that didn't exist when the old National Key Points Act was drafted. Fortinet's warning specifically points to a late-2025 incident in Poland's energy sector — serious enough to prompt a CISA global alert in February 2026 — in which attackers used distributed energy resources to deploy destructive tools that crippled remote terminal units and wiped human-machine interface data (IT-Online). Eskom's own recent history is not reassuring: in March 2022 the Everest ransomware gang claimed to have exfiltrated server credentials from Eskom's network and offered them for sale on the dark web. IPPs make the exposure worse, not better, in one specific sense — a private producer's network is typically less hardened than Eskom's core systems, and Fortinet is right that every interconnection point is a potential lateral-movement path into the national grid. A legal framework that formally designates grid-adjacent connected devices as critical infrastructure, with defined reporting obligations and an inspection regime, is a reasonable response to a real and growing risk. The Critical Infrastructure Protection Act, assented to in November 2019 and brought into force by Government Gazette 46024 of 10 March 2022, was built precisely to replace the narrower National Key Points Act with a broader, criteria-based designation process overseen by a Critical Infrastructure Council (gov.za; gov.za Council notice).

Where the argument runs ahead of the state's capacity

What Fortinet's framing elides is that South Africa's problem with Eskom infrastructure has never really been a shortage of legal designation — it has been a shortage of execution capacity, and the smart-meter rollout is itself the clearest illustration of that gap. Eskom missed its own March 2026 target of 577,347 meters installed on priority load-reduction feeders, running roughly 52% behind schedule, and more than 122,000 planned installations have been postponed specifically because of intimidation, violent incidents, and repeated work stoppages against the installation teams (ITWeb). Layering a sovereign-critical-infrastructure designation onto a fleet the utility cannot even physically install on schedule does not, by itself, produce better-secured meters — it produces a longer list of nominally protected assets that the same stretched security and inspection apparatus has to somehow cover. Analysts assessing the Act's predecessor bill made the same point about the broader grid years before smart meters entered the picture: security agencies tasked with protecting Eskom infrastructure were already under-resourced and prone to "factionalism, mismanagement and inefficiency," and extending the perimeter of what counts as critical infrastructure does nothing to fix that unless it comes with matching investment in the people and processes doing the protecting (The Conversation).

There is also a proportionality question the Act's designation framework doesn't yet answer well. Not every one of six million meters carries the same risk profile as a substation or an IPP interconnection point, and treating a residential meter and a wind-farm gateway as equivalent "sovereign assets" invites either uniform over-regulation that slows an already-delayed rollout further, or selective under-enforcement that undermines the designation's credibility. A tiered approach — differentiated security and reporting obligations scaled to a device's actual position in the grid topology, rather than a blanket sovereign-asset label — would let Eskom keep installing meters at the pace load-reduction relief actually requires, while concentrating scarce inspection and incident-response capacity on the interconnection points and control systems where a breach could genuinely cascade. The CIPA gives South Africa the legal vocabulary to do that. Whether the Critical Infrastructure Council uses it to differentiate risk, or simply expands the designated perimeter without expanding capacity to match, will determine whether this law makes the grid more secure or just makes the paperwork more sovereign.

Sources & Citations

  1. Critical Infrastructure Protection Act 8 of 2019 (gov.za)
  2. Critical Infrastructure Council members notice (gov.za)
  3. IT-Online: Fortinet warning on grid cyber risk
  4. ITWeb: Eskom smart meter rollout delays
  5. EWN: Smart meter rollout progress
  6. The Conversation: South Africa grid security gaps