Cybersecurity: how the Cell C and SABS attacks could have been prevented
Two recent, high-profile cyberattacks—one on mobile telecommunications provider Cell C and another on the South African Bureau of Standards (SABS)—have rocked South Africa.
Image: Independent Newspapers
Cybercrime has become the single biggest threat to businesses worldwide.
According to the Allianz Risk Barometer 2025, cyber incidents — including ransomware attacks, data breaches and IT outages — are now the top global business risk, marking their fourth year at the top.
A decade ago, only 12% of global respondents cited cyber as a major concern. In 2025, that number surged to 38%.
Allianz noted, 'Cyber is the top risk across North and South America, Europe, and Africa,' dominating industry concerns from aviation to legal services. More importantly, it now ranks as the number one risk in South Africa, overtaking long-standing issues like load shedding and political instability.
This concern is not just theoretical.
Two recent, high-profile cyberattacks—one on mobile telecommunications provider Cell C and another on the South African Bureau of Standards (SABS)—have rocked South Africa.
Both incidents have raised serious questions about compliance, cybersecurity readiness, and whether these attacks could have been prevented.
Cell C confirmed in a December 2024 media release that it had suffered a major ransomware attack.
Sensitive unstructured customer data — including ID numbers, bank details, driver's licenses, medical records and passport information — was compromised and later leaked on the dark web.
Video Player is loading.
Play Video
Play
Unmute
Current Time
0:00
/
Duration
-:-
Loaded :
0%
Stream Type LIVE
Seek to live, currently behind live
LIVE
Remaining Time
-
0:00
This is a modal window.
Beginning of dialog window. Escape will cancel and close the window.
Text Color White Black Red Green Blue Yellow Magenta Cyan
Transparency Opaque Semi-Transparent Background Color Black White Red Green Blue Yellow Magenta Cyan
Transparency Opaque Semi-Transparent Transparent Window Color Black White Red Green Blue Yellow Magenta Cyan
Transparency Transparent Semi-Transparent Opaque
Font Size 50% 75% 100% 125% 150% 175% 200% 300% 400% Text Edge Style None Raised Depressed Uniform Dropshadow Font Family Proportional Sans-Serif Monospace Sans-Serif Proportional Serif Monospace Serif Casual Script Small Caps
Reset
restore all settings to the default values Done
Close Modal Dialog
End of dialog window.
Advertisement
Video Player is loading.
Play Video
Play
Unmute
Current Time
0:00
/
Duration
-:-
Loaded :
0%
Stream Type LIVE
Seek to live, currently behind live
LIVE
Remaining Time
-
0:00
This is a modal window.
Beginning of dialog window. Escape will cancel and close the window.
Text Color White Black Red Green Blue Yellow Magenta Cyan
Transparency Opaque Semi-Transparent Background Color Black White Red Green Blue Yellow Magenta Cyan
Transparency Opaque Semi-Transparent Transparent Window Color Black White Red Green Blue Yellow Magenta Cyan
Transparency Transparent Semi-Transparent Opaque
Font Size 50% 75% 100% 125% 150% 175% 200% 300% 400% Text Edge Style None Raised Depressed Uniform Dropshadow Font Family Proportional Sans-Serif Monospace Sans-Serif Proportional Serif Monospace Serif Casual Script Small Caps
Reset
restore all settings to the default values Done
Close Modal Dialog
End of dialog window.
Next
Stay
Close ✕
While a follow-up communication was sent to customers in early January 2025, the eight-day delay between public disclosure and customer notification drew criticism.
The SABS breach followed a similar pattern — ransomware paralysed the organisation's systems in November 2024, with clients being informed on 26 November. Shockingly, it was later revealed in Parliament that, by February 2025, core systems remained encrypted and inaccessible. This marked the third cyberattack on the SABS in just five years.
Herman Stroop, Lead ISO Specialist at WWISE (World Wide Industrial & Systems Engineers), said that both attacks were entirely preventable.
'Neither Cell C nor SABS were ISO/IEC 27001 certified — a globally recognised standard for information security management,' Stroop said.
'This standard isn't just a technical checklist. It's a framework that forces an organisation to understand its vulnerabilities, assess its risks, and apply controls that address these risks in a structured, auditable way,' Stroop added.
The ISO/IEC 27001 standard focuses on Confidentiality, Integrity, and Availability (CIA)—the foundation of modern information security.
It requires organisations to conduct ongoing risk assessments, implement policies and technical controls, and continuously monitor and update these defences in response to emerging threats.
According to Stroop, the absence of such a system is often due to a lack of strategic commitment from leadership.
'Cybersecurity is wrongly seen as an IT issue,' he says. 'Top management often fails to view it as a core business risk, resulting in underinvestment in preventative frameworks like ISO/IEC 27001. One key challenge in South Africa is poor enforcement of existing regulations. While the Protection of Personal Information Act (POPIA) and Minimum Information Security Standards (MISS) lay out clear expectations for information governance, many organisations either ignore or delay compliance due to a perceived lack of consequences," Stroop said.
'The irony is that prevention is far cheaper than remediation,' Stroop noted.
'In many cases, organisations suffer reputational damage, legal liability, and operational downtime that far exceed the cost of implementing an ISO-compliant Information Security Management System.'
Cell C and SABS also provide examples of poor transparency. Details about the nature of the attacks and how they were handled remain vague.
'When an organisation isn't ISO-certified, it usually doesn't have the documentation, procedures or incident response plans to respond properly — let alone communicate clearly — during a breach,' Stroop added.
According to the Information Regulator, South Africa sees between 150 and 300 cyberattacks reported each month—and that's just the reported incidents. Many go unreported due to reputational fears or because organisations are not compliant with POPIA and fear investigation.
Stroop believes that ISO 27001 should be mandated for public institutions and critical infrastructure operators.
'Without minimum compliance levels, we're just waiting for the next disaster,' he says. 'It's not a matter of if, but when.'
And there is movement. Some insurance providers are beginning to offer premium reductions for ISO-certified organisations, while major corporate clients now demand ISO 27001 certification from vendors.
'It's becoming a market differentiator,' Stroop concludes. 'Organisations serious about protecting their data and reputation cannot afford to ignore ISO 27001 any longer.'
In a digital age where the threat landscape evolves daily, being unprepared is no longer an option.
BUSINESS REPORT

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles

IOL News
3 hours ago
- IOL News
SA is regressing on the advancements in female leadership and localisation
The year 2015 marked a seismic shift in the story of South African enterprise. The then appointed Lottery Operator, was the first to be owned and led by a woman. That was a big moment. As a Black female entrepreneur committed to telling Africa's story through its people, its victories, and its integrity, I saw this as more than a business win — it was a symbol of what transformation should look like in South Africa. This leadership didn't just check boxes on a scorecard; it embodied the spirit of empowerment. The visionary headship of the black-woman-led operator steered the National Lottery into a new era defined by innovation, local technological excellence, and profound social impact. Today, that legacy is under threat. The recent appointment of Sizekhaya Holdings as the fourth National Lottery operator is not just disappointing, it is deeply troubling. It challenges the integrity of our procurement processes, undermines genuine gender empowerment, and raises pressing questions about foreign influence and compromised leadership. As Africans, we have long fought to reclaim our narrative. But reclaiming is not enough. We must now protect and own it — and that means ensuring that Africa's progress is authored by its own people. That means calling out tokenism when it disguises itself as transformation. It was disheartening to observe Sizekhaya Holdings' leadership structure seems to be a step backwards. While four women are listed in leadership positions, only two hold executive roles. The others are non-executive directors – titles that sound impressive but wield limited operational power. This performative inclusion dilutes the very progress women like Charmaine Mabuza made. Even more concerning are the glaring red flags surrounding the bidding process itself. How can we discuss a 'clean' tender when key members of the evaluation committee have direct ties to Sizekhaya's major shareholder, Goldrush? One committee member has financial interests linked to the same bidder. These are not mere oversights; they are breaches of trust that demand our immediate attention. Trust is the bedrock of any public institution. Instead of silence from the Ministry, we need transparency. We need accountability. The technology behind the new operator raises serious concerns. Why are we outsourcing such a critical national system to Genlot, a Chinese firm, when it has been proven that we have local capacity to deliver world-class innovation? This isn't just about software – it's about sovereignty. Almost half the National Lottery's revenue could now flow offshore. Is that the cost of ignoring local excellence that we are willing to pay as a nation? As a woman who has built from the ground up, I understand the power of being given a chance — but also the responsibility to honour that opportunity with service, not self-interest. The National Lottery is more than a contract. It is a vehicle for transformation, one that impacts millions of lives. We cannot afford to politicise it or hand it over to interests that do not serve the public good. This moment demands more than frustration. It demands action. The question South Africa must ask is this: Whose interests are we serving now? Because if we do not champion local excellence, we are handing our power away on a silver platter, and history has shown us how that ends. The National Lottery should remain a symbol of our ability to uplift ourselves, not a cautionary tale of how easily progress can be reversed. South Africa is not for sale. And neither is our story. Jabulile Buthelezi - Kalonji is a strategic communications and stakeholder relations management professional, public speaker, author and publisher.

IOL News
7 hours ago
- IOL News
City loses court case against Cell C over stadium damage
Cape Town stadium. Image: City of Cape Town THE City has lost its court bid to claim damages against Cell C over damage to the Cape Town stadium. The Western Cape High Court ruled that the debt had prescribed, and the claim was dismissed with costs. According to court papers, the issue dates back to 2015 when the City gave Cell C permission to access the stadium to install infrastructure for its customers. Cell C had contracted Huawei to do the installation work. 'On November 18, 2015, the (City) discovered extensive damage to the external façade of the stadium which was caused by a metal panel which had dislodged from gridline 50 on level 6 of the stadium and which fell on or through the façade, damaging the same. "At all material times it was (Cell C's) duty to ensure that the installation was done without any harm or damage to the stadium and inasmuch as the damage was caused by (Huawei), alternatively, the third, alternatively the fourth defendant's action, it remained the duty of (Cell C) to ensure that no damage was done to the stadium and it could not rid itself of this duty by appointing a contractor,' court papers read. Video Player is loading. Play Video Play Unmute Current Time 0:00 / Duration -:- Loaded : 0% Stream Type LIVE Seek to live, currently behind live LIVE Remaining Time - 0:00 This is a modal window. Beginning of dialog window. Escape will cancel and close the window. Text Color White Black Red Green Blue Yellow Magenta Cyan Transparency Opaque Semi-Transparent Background Color Black White Red Green Blue Yellow Magenta Cyan Transparency Opaque Semi-Transparent Transparent Window Color Black White Red Green Blue Yellow Magenta Cyan Transparency Transparent Semi-Transparent Opaque Font Size 50% 75% 100% 125% 150% 175% 200% 300% 400% Text Edge Style None Raised Depressed Uniform Dropshadow Font Family Proportional Sans-Serif Monospace Sans-Serif Proportional Serif Monospace Serif Casual Script Small Caps Reset restore all settings to the default values Done Close Modal Dialog End of dialog window. Advertisement Next Stay Close ✕ Ad loading The City's main claim was against Cell C with an alternative claim against Huawei and the other sub-contractors separately, in the event that the court found that they were independent contractors and that Cell C could not be held liable for any of their actions. However, both Cell C and Huawei invoked a special plea of prescription. They argued that the cause of action arose on November 18, 2015 and that the summons instituting the proceedings was served on them after the three year prescription period. 'The (City's) claim would prescribe within a period of three years as it falls within the ambit of section 11(d) of the Prescription Act. In his opening statement counsel for (Cell C) submitted that the (City) sought to impose strict liability on it in terms of its pleaded case. This rendered the actual identity of the defendant / entity who caused the damage irrelevant. Furthermore, Cell C submitted that as the (City) discovered the loss on November 18, 2015 and served its summons on November 21, 2018, (the City's) claim against it had prescribed.' Lawyers for Huawei argued that there were no grounds on which the City could succeed. An ICS service engineer for Huawei testified and that he was responsible for the network provision. The engineer compiled a report on the day of the incident at the stadium. It was recorded that on November 18, 2015 the stadium management stated that the damage was caused by Huawei's contractors as they worked on location. The report contained Huawei's denial that they were responsible for the damage and concluded that there was no conclusive proof in respect of who was responsible for the damage. A City employee testified that while he was aware of a theory that a cherrypicker from another company could have caused the damage, 'no one placed any credibility in the theory'. He said that there was one of four entities (Cell C, Huawei and the other subcontractors) which could be liable for the damage and that he held a meeting with representatives of all four entities on November 18, 2015. However, according to court papers, the employee never asked which contractor replaced the panel and who was responsible for supervising the work on level 6.

IOL News
8 hours ago
- IOL News
Mashatile promises land back to the people
Deputy President Paul Mashatile. Image: Independent Media Archives Deputy President Paul Mashatile delivered a firm commitment in Parliament: the new government will return the land to the people - and ensure they don't lose it again to banks. Answering questions in the National Assembly on Thursday, Mashatile said the government was determined to protect land reform beneficiaries from being trapped by commercial debt. 'Our role as a new government is to return the land to the people and do it in such a way that we protect them from the commercial banks,' he said. 'We don't want a situation where they lose land again because of loans.' Questions about land ownership were asked by the DA MP, Willie Aucamp and MK Party MP, Andile Mngxitama. Mashatile also explained that most land-related funding currently comes from state institutions like the Land Bank and other government financial entities. But he acknowledged that commercial finance still plays a role - one that must be tightly regulated to prevent exploitation. 'We must also tap into resources in commercial banks, but with state support so people are not exploited. We are doing exactly that, he said. Video Player is loading. Play Video Play Unmute Current Time 0:00 / Duration -:- Loaded : 0% Stream Type LIVE Seek to live, currently behind live LIVE Remaining Time - 0:00 This is a modal window. Beginning of dialog window. Escape will cancel and close the window. Text Color White Black Red Green Blue Yellow Magenta Cyan Transparency Opaque Semi-Transparent Background Color Black White Red Green Blue Yellow Magenta Cyan Transparency Opaque Semi-Transparent Transparent Window Color Black White Red Green Blue Yellow Magenta Cyan Transparency Transparent Semi-Transparent Opaque Font Size 50% 75% 100% 125% 150% 175% 200% 300% 400% Text Edge Style None Raised Depressed Uniform Dropshadow Font Family Proportional Sans-Serif Monospace Sans-Serif Proportional Serif Monospace Serif Casual Script Small Caps Reset restore all settings to the default values Done Close Modal Dialog End of dialog window. Advertisement Video Player is loading. Play Video Play Unmute Current Time 0:00 / Duration -:- Loaded : 0% Stream Type LIVE Seek to live, currently behind live LIVE Remaining Time - 0:00 This is a modal window. Beginning of dialog window. Escape will cancel and close the window. Text Color White Black Red Green Blue Yellow Magenta Cyan Transparency Opaque Semi-Transparent Background Color Black White Red Green Blue Yellow Magenta Cyan Transparency Opaque Semi-Transparent Transparent Window Color Black White Red Green Blue Yellow Magenta Cyan Transparency Transparent Semi-Transparent Opaque Font Size 50% 75% 100% 125% 150% 175% 200% 300% 400% Text Edge Style None Raised Depressed Uniform Dropshadow Font Family Proportional Sans-Serif Monospace Sans-Serif Proportional Serif Monospace Serif Casual Script Small Caps Reset restore all settings to the default values Done Close Modal Dialog End of dialog window. Next Stay Close ✕ Addressing concerns over support for emerging farmers, Mashatile pointed to the estimated two million small-scale farmers already receiving government assistance. 'It's not enough to give land,' he said. 'You must support people to till that land. That's what we're doing with the Land Bank and other institutions.' One of the key challenges, Mashatile admitted, is the lack of title deeds - particularly among older farmers and those in rural areas. This limits access to credit, as commercial banks demand security. A programme is underway, he said, to issue title deeds to land reform beneficiaries. Earlier this year, President Cyril Ramaphosa signed the Expropriation Act. The Act aims to allow the government to acquire private property for public purposes or in the public interest. But the government must tread carefully in traditional areas. 'Sometimes traditional leaders say they must hold the title for everyone,' Mashatile noted. 'We have to engage with them.' Collaboration between the Ministers of Agriculture and Land Reform, he added, is ongoing to resolve these complexities and ensure land reform delivers real, lasting change. Mashatile on Thursday also sent a clear and uncompromising message underscoring the government's intensified focus on consequence management in the water sector to combat corruption and inefficiency. 'We are stepping up consequence management. Water boards, municipal managers, and service providers will be held accountable - no exceptions,' Mashatile stated, addressing concerns over poor performance, criminal interference, and service delivery failures. He acknowledged that many of the country's water authorities were managed at the municipal level, with oversight from the Department of Water and Sanitation. 'Their performance is under scrutiny. We cannot afford weak leadership in these critical institutions. When individuals don't deliver, action must follow, because failure costs lives and fuels corruption,' he said. However, Mashatile spotlighted the growing threat posed by 'water mafias' - organised criminal networks that sabotage public infrastructure to profit from tanker contracts. 'They have embedded themselves within city systems, disrupting services so that municipalities are forced to rely on outsourced water supply. What began as a temporary solution for emergencies has become a captured industry,' he said. Mashatile affirmed that these networks are being targeted. 'We are actively dismantling their influence. Protecting our cities from this kind of corruption is a top priority.' Mashatile confirmed that a high-level task team, working with the Minister of Water and Sanitation, is developing stricter accountability measures and performance standards for all water institutions. Cape Times