A hearing that exposed the gap between law and enforcement
At an August 18, 2026 hearing of Parliament's Standing Committee on Public Accounts (Scopa), Hawks acting head Lieutenant General Siphesihle Nkosi delivered a number that should worry anyone who thought South Africa's cybercrime problem was a legislative one: the Directorate for Priority Crime Investigation (DPCI) has just 73 investigators with the necessary skills to handle cybercrime cases, spread across all nine provinces plus head office. That is the entire specialist capacity for a country of roughly 60 million people, sitting inside a unit that reported 2,515 staffing vacancies — close to a 49% vacancy rate — on a total budget of R2.7 billion, less than the R4 billion allocated to the VIP protection unit that guards cabinet members (GroundUp).
This is not a story about South Africa lacking a legal framework. The Cybercrimes Act 19 of 2020 — which criminalises unlawful access, data interference, cyber fraud and extortion, and compels electronic communications providers and financial institutions to assist investigations — passed the National Council of Provinces on July 1, 2020, and commenced on December 1, 2021 (Parliament of South Africa; gov.za). On paper, South Africa has had one of the more comprehensive cybercrime statutes on the continent for nearly five years. The Scopa hearing confirmed what analysts flagged when the Act commenced: the law was always going to be only as good as the police capacity behind it.
The Cyber Commissioner proposal — and its strongest case
Into that gap has stepped a proposal to create an Office of the Cyber Commissioner, most recently pushed by DA MP Glynnis Breytenbach via a proposed 20th Amendment to the Constitution. The pitch, restated in September 2025 as digital banking fraud surged, is to establish a new Chapter 9 institution — accountable directly to Parliament rather than to Cabinet — tasked with setting minimum cybersecurity standards across government and coordinating public-private threat monitoring, partly in response to AI-driven scams that DA figures say pushed banking fraud losses from roughly R1 billion to R1.4 billion between 2023 and 2024 (DA).
The case for it deserves to be stated fairly. South Africa's cyber-response mandate is genuinely fragmented — split across SAPS/the Hawks, the State Security Agency, the Justice Department's Cybercrimes Act structures, the Information Regulator under POPIA, and sector regulators like ICASA — with no single accountable body owning the national picture. A Chapter 9 institution, insulated from executive interference the way the Public Protector and Auditor-General are, could in principle set standards, coordinate incident response, and apply sustained pressure that a rotating cast of police generals answering to Cabinet cannot. Countries building dedicated cyber agencies (the UK's NCSC, Australia's ASD) have found that consolidation helps when the problem crosses departmental lines, as cybercrime plainly does.
Why the constitutional route is the wrong fix, right now
But a Chapter 9 institution requires a constitutional amendment — a two-thirds parliamentary majority the DA does not command and has not secured co-sponsors for since first raising the idea in 2022. That is not a fast fix; it is a multi-year political project layered on top of a capacity crisis that needs solving this budget cycle. Meanwhile, the actual bottleneck Nkosi described to Scopa is mundane and immediately addressable: DPCI cannot compete on salary with private-sector cybersecurity employers or better-funded public units, so trained investigators leave faster than they can be replaced. The Hawks are advertising 315 posts internally to backfill experienced investigators, but that is triage, not a structural solution to a unit whose entire cyber capacity is smaller than the security team of a mid-sized bank.
Creating a new constitutional office does nothing to fix that pay and retention problem — it adds a further layer to an already fragmented mandate without necessarily commanding the arrest, prosecution, or forensic powers that live inside SAPS and the National Prosecuting Authority. A standards-setting commissioner sitting alongside an under-resourced Hawks cyber unit risks producing more coordination meetings, not more prosecutions. The proportionate response is to fund and staff the enforcement architecture that already exists in law — competitive pay bands for scarce technical investigators, ring-fenced budget for the DPCI's cyber capacity, and closer operational integration with the Information Regulator and existing sector CERTs — before spending years amending the Constitution.
The stakes for businesses and investors
For companies operating in South Africa, this gap matters commercially, not just symbolically. The Cybercrimes Act imposes real compliance obligations on electronic communications and financial services providers to assist investigations — obligations businesses are, correctly, expected to meet. But a regime where the law criminalises conduct that a 73-person national unit cannot realistically investigate at scale creates weak deterrence for attackers while still imposing compliance costs on legitimate firms. That asymmetry — real obligations, unreal enforcement — is the actual policy failure Scopa surfaced on August 18, and it is one Treasury and SAPS can start fixing with the next budget vote, without waiting on a constitutional amendment that may never pass.