Cyber Incident Response in South Africa: First 24 Hours
Cybersecurity incident response in South Africa used to be a niche speciality. It is now a core business skill, because the question is no longer whether your company will face an incident, but when, and whether your team knows what to do in the first 24 hours. This guide walks through a practical first-24-hours plan for South African businesses, including the POPIA breach notification clock that starts ticking the moment you detect a problem.
The first 24 hours after a cyber incident decide most of the outcomes. Get them right and you contain the damage, meet your legal deadlines, and keep the business running. Get them wrong and a bad week becomes a bad quarter. In South Africa there is an added pressure: POPIA requires you to notify the Information Regulator of a security compromise within 72 hours, which means your response has to move faster than most boardrooms expect.
What counts as a cyber incident?
Be precise about definitions, because imprecise teams waste the first hours arguing instead of acting. A cyber incident is any event that threatens the confidentiality, integrity, or availability of your data or systems. In practice South African businesses see four main types:
- Ransomware: attackers encrypt your files and demand payment. South African victims have ranged from single doctor’s rooms to national retailers.
- Business email compromise: an attacker takes over a mailbox and redirects invoice payments. The FBI’s Internet Crime Report ranks BEC among the costliest cyber crimes year after year.
- Data exfiltration: someone copies customer or staff data out of your environment, often quietly, before any ransom note appears.
- Insider incidents: a departing employee, a contractor, or a compromised account with legitimate access.
If you are unsure whether something qualifies, treat it as if it does. The cost of investigating a false alarm is a few hours. The cost of ignoring a real breach is measured in millions of rand and a POPIA enforcement process.
Hour 0 to 1: Confirm, contain, and call
The first hour is about speed, not perfection. Do these things in order:
- Confirm it is real. Check whether the alert is a genuine event or a monitoring false positive. Two people should verify independently. Do not wait for 100% certainty before containing; 80% confidence is enough to act.
- Contain laterally. Isolate affected machines from the network. Pull the network cable, disable the VPN account, block the sender. Do not power machines off, because memory evidence lives in RAM and shutting down destroys it.
- Assemble the response team. Your incident lead, IT lead, legal, comms, and an executive decision maker. For most SMEs that is three to five people, not a committee. Put them in one chat group with a single decision maker.
- Start the log. Timestamp everything: what you saw, who you told, what you did. This log becomes your evidence for the regulator, your insurer, and possibly the police.
Hour 1 to 4: Assess scope and preserve evidence
Once contained, work out how wide the problem goes. Which systems did the attacker touch? Which accounts were used? What data was accessed, if any? Pull authentication logs, firewall logs, and endpoint records. If you use managed security services, your provider should already have telemetry; ask for it in writing.
Preserve evidence as you go. Take images of affected machines rather than working on them directly. Export log files before retention windows expire. Keep the ransom note and any attacker communications, including the bitcoin wallet addresses, because insurers and police will ask for them.
This is also when you engage external help. If you have cyber insurance, call the insurer’s emergency line early, because many policies require you to use their panel providers. If you do not, engage an incident response firm. South Africa has capable IR firms, and the earlier they arrive, the less mess they inherit.
Hour 4 to 24: Notify, decide, and stabilise
By hour four you should know enough to make the big calls. The three decisions that matter most:
Do you notify the Information Regulator? POPIA section 22 requires notification of security compromises. The law expects you to notify where there is a real risk of harm, and the practical reality is that most ransomware and data exfiltration events meet that bar. Notify within 72 hours of discovering the compromise, and remember that the clock starts at discovery, not at the end of your investigation. The Information Regulator’s guidance covers what the notification must contain.
Do you pay the ransom? Most insurers, lawyers, and law enforcement advise against paying. Payment funds the next attack, offers no guarantee of working decryption, and may create legal exposure if the criminal group is sanctioned. Build the ability to recover without paying, which is the real protection. We covered the broader playbook in our ransomware protection guide.
What do you tell staff and customers? Say something early, even if it is only “we are investigating a security incident and will update you.” Silence breeds speculation, and speculation breeds panic. Assign one person to own all communication.
The 72-hour POPIA clock, explained simply
The rule is simple: once you know there has been a compromise, you have 72 hours to notify the Information Regulator, and you must notify affected data subjects as soon as reasonably possible after that. The notification must cover the nature of the compromise, the data involved, the likely consequences, and what you are doing about it.
What trips businesses up is the starting point. The clock starts when you have reasonable suspicion of a compromise, not when your investigation finishes. A team that waits a week “to be sure” has already blown the deadline. Write this into your incident response plan now, before you need it. For a broader compliance view, see why cyber risk now belongs on the board agenda.
What a good incident response plan contains
You cannot invent a response plan during an incident. The plan you need fits on a few pages:
- A named incident lead and backup, with contact numbers that work after hours
- The criteria for declaring an incident, so nobody debates definitions at 2am
- Containment steps per incident type, written for the systems you actually run
- Legal notification triggers and the 72-hour POPIA deadline in bold
- Insurer details and panel provider requirements
- Communication templates for staff, customers, and the regulator
Test the plan twice a year with a tabletop exercise. An hour around a table with a scenario will find more gaps in your plan than any amount of document review, and it costs nothing but coffee.
How much does a breach cost a South African business?
Useful numbers to take to your next board meeting: IBM’s Cost of a Data Breach Report puts the global average breach cost at USD 4.44 million in its 2025 edition, with costs substantially higher where incidents took months to identify. South African breach costs run lower in absolute terms but hit proportionally harder, because few local SMEs carry the cash buffer to absorb a multi-million rand event. Detection speed is the biggest lever you control: the same report shows breaches contained in under 200 days cost dramatically less than those that linger.
Ransomware adds its own economics. Beyond the ransom demand itself, factor in lost trading days, forensic fees, system rebuilds, and customer churn. The cheapest incident is the one you never have, which is why pre-emptive cybersecurity beats reacting every time.
FAQ: Cyber incident response in South Africa
What is cyber incident response?
Cyber incident response is the structured process a business follows to detect, contain, investigate, and recover from a cyber attack. In South Africa it also includes POPIA obligations, meaning you must notify the Information Regulator within 72 hours of discovering a security compromise and inform affected people. A written plan, a named response lead, and tested containment steps are the core components.
How fast must a South African business report a data breach?
POPIA requires notification to the Information Regulator within 72 hours of becoming aware of a security compromise, followed by notification to affected data subjects as soon as reasonably possible. The clock starts at discovery, not at the end of the investigation. Waiting a week to be certain usually means you missed the legal deadline.
What are the first three things to do in a cyber incident?
Confirm the incident is real with two independent checks, contain the spread by isolating affected systems and disabling compromised accounts, and start a timestamped log of every action. In that first hour you should also assemble your response team and alert your insurer if you have cover. Do not power affected machines off, because that destroys evidence held in memory.
Should a South African business pay a ransomware demand?
Generally no. Payment funds the next attack, rarely guarantees working decryption, and can create legal exposure if the criminal group is under sanctions. Insurers and law enforcement both advise against paying. The better investment is offline backups, a tested recovery plan, and pre-emptive controls that make paying unnecessary.
Does every cyber incident require POPIA notification?
No. Notification is required where there is a real risk of harm to data subjects, such as identity theft or financial loss. In practice most ransomware events, data exfiltration, and business email compromise cases meet that bar. When in doubt, notify, because the regulator views late notification far more harshly than cautious over-notification.
Conclusion: Prepared beats fast, every time
Cyber incident response rewards preparation, not improvisation. The businesses that survive incidents with their reputation and balance sheet intact are the ones that wrote the plan, named the people, and ran the tabletop exercise before the phone rang. The 72-hour POPIA clock does not wait for committee meetings, and attackers do not pause while you draft an email. If your business does not have a tested incident response plan, that is the gap to close this quarter. Talk to Hayshack about building a response plan that fits your business, your systems, and your legal obligations.







