If you are in an active incident right now
Skip the reading. Disconnect affected systems from the network (do not wipe or reboot them), and get incident help immediately — our breach response line or your own security provider. Every hour of delay widens the damage and shortens your legal runway.
Hour 0–4: Contain, Don't Destroy
- Isolate affected machines — pull the network cable, disable the WiFi, suspend compromised accounts. Do not format, reboot, or "clean up": you are standing in evidence.
- Change credentials from a clean device. Assume passwords on the affected system are captured. Start with email, banking, and admin accounts.
- Start a timeline document immediately. Who noticed what, when, and what was done. The Information Regulator, your insurer, and your lawyers will all ask for this.
Hour 4–24: Assess Scope
- What data was accessible: client personal information? Patient records? Payment data? Staff records? POPIA's obligations scale with what was exposed.
- How the attacker got in — phishing, exposed service, stolen credentials, third-party provider. If a forensic capability exists (in-house or contracted), it takes over here.
- Whether it's ongoing. Many "incidents" are discovered mid-operation. Containment isn't complete until persistence mechanisms are found and removed.
Hour 24–72: Notify — It's the Law
Under Section 22 of POPIA, a responsible party must notify the Information Regulator and affected data subjects "as soon as reasonably possible" after discovering a compromise of personal information — and the Cybercrimes Act adds a 72-hour reporting duty to the SAPS for qualifying offences. In practice: work to 72 hours as your outer limit, and document why if you need longer.
- Information Regulator: security-compromise notification via the forms on inforegulator.org.za. Include what happened, what data was affected, and what you're doing about it.
- Affected people: in writing, in plain language, with concrete advice (change passwords, watch statements). Hiding a breach that later surfaces is reputationally fatal and legally worse.
- Sector bodies: banking-related fraud goes to SABRIC; regulated professions may owe their councils a notification (HPCSA, LPC).
After the Fire: The Part Everyone Skips
The businesses that get breached twice are the ones that patched the symptom and skipped the post-incident review. Close the actual entry point, rotate every credential that could have been exposed, verify your backups actually restore, and write down what changed — that document is gold in any future vetting, insurance, or tender process.
Live Threat Maps & Intelligence Worth Bookmarking
These are the public, real-time platforms security teams actually keep open. They're also the fastest way to make cyber risk feel real to a board or a business partner:
- Kaspersky Cybermap — the classic real-time global attack visualisation; South Africa consistently features in the most-attacked rankings.
- Check Point Live Threat Map — live attack flows by country, industry and attack type.
- FortiGuard Threat Map — Fortinet's telemetry view of global attack activity.
- Cloudflare Radar — internet health, outage and attack-trend data, filterable to South Africa specifically.
- SABRIC — South African banking crime intelligence: the local fraud and scam patterns targeting SA businesses right now.
- Have I Been Pwned — check whether your business email addresses already appear in known breach dumps. Free, and every SA business should run its domain through it.
The uncomfortable truth: a 72-hour response is only achievable if the plan existed before the breach. Incident contacts, isolation steps, notification templates, and tested backups are decided calmly in advance or chaotically at 2am. Our Data Breach Response service builds the plan — and answers the 2am call if it's ever needed.