IronTree says South African financial-sector regulations now require governing bodies, as well as employees, to undergo annual cybersecurity awareness training, reflecting growing recognition that cyber risk is a board-level responsibility. With human decisions contributing significantly to breaches, the company argues that effective training can strengthen cyber resilience and help boards better understand and oversee the risks for which they are accountable.
A change buried in financial sector regulation last year raises a standard the rest of the market hasn't caught up to.
Johannesburg, South Africa – 23 September 2026 - A regulation that came into effect in South Africa's financial sector in mid-2025 has quietly redefined what a cybersecurity awareness programme is meant to cover, and now includes the governing body as well as employees, says IT security firm, IronTree.
The FSCA and Prudential Authority's Joint Standard 2 of 2024, effective from 1 June 2025, requires financial institutions to run a comprehensive cybersecurity awareness programme at least annually. It has to cover all users. It also has to cover the governing body.
"Most businesses still treat cybersecurity awareness as something IT does for staff," says Byron Robertson, Managing Director of IronTree. "This standard says the board has to be trained too, and once one regulator writes that down, it tends not to stay isolated to one sector."
The reasoning behind the rule matches South Africa's own breach data. Robertson says that CSIR research attributes roughly 95% of South African data breaches to human decisions rather than technical failures: “A governing body that has never been through the same training its staff receive has little basis to ask the right questions when a breach happens, or to sign off on a risk appetite it doesn't understand.”
POPIA Section 19 already requires appropriate, reasonable technical and organisational measures from every responsible party in the country, not only financial institutions. Organisational measures include training. “A board that cannot show it understood the risk it approved is a harder position to defend than an untrained employee,” says Robertson, because governance failures are usually the first thing regulators and courts look at.
There is evidence that the training itself works. KnowBe4's 2025 benchmarking report, drawn from 67.7 million simulated phishing tests across more than 62 000 organisations, found that roughly one in three employees clicks a simulated phishing link before training. After twelve months of continuous training, fewer than one in twenty do. Robertson sees no reason the effect would stop at board level.
The cost of getting it wrong keeps climbing. Sophos's 2025 State of Ransomware report puts the average cost of a ransomware incident to a South African business at around R19 million once ransom, downtime and recovery are counted. For most SMEs, that is not a bad quarter. It is the end of the business, and the risk sits with the board whether or not the board has been trained to see it.
IronTree's Security Awareness Training is available as a fully managed service, extended to cover governing bodies as well as staff. Businesses that want a starting point can run IronTree's free Phishing Risk Check first. Ends
For more information:
Samantha Hogg-Brandjes | GinjaNinja | samantha@ginjaninja.co.za | +27-84-458-4857
