[{"data":1,"prerenderedAt":18},["ShallowReactive",2],{"$fq-yeyOFOG1yjTHnbogVvqY9GH1D200Ux5N6CJ_2txcY":3},{"slug":4,"title":5,"excerpt":6,"html":7,"publishedAt":8,"updatedAt":8,"author":9,"tags":10,"featureImage":15,"readingTime":16,"canonical":17},"learning-from-south-african-data-sovereignty","Learning from South African Data Sovereignty","South Africa's data sovereignty isn't only a government problem. The frameworks and products already exist; what's missing is the ability to operate them.…","\n\u003C!--kg-card-begin: html-->\n\u003Cdiv id=\"elevenlabs-audionative-widget\" data-height=\"90\" data-width=\"100%\" data-frameborder=\"no\" data-scrolling=\"no\" data-publicuserid=\"ae3cda78c4a99172f99dbfb050207098d88a71401457ade2c9f5329e0b9185ed\" data-playerurl=\"https://elevenlabs.io/player/index.html\" data-projectid=\"3wgBnFltKaCmoC2HZaZ1\" >\u003C/div>\u003Cscript src=\"https://elevenlabs.io/player/audioNativeHelper.js\" type=\"text/javascript\">\u003C/script>\n\u003C!--kg-card-end: html-->\n\u003Cp>Lindsey Schutters has written an excellent article in the \u003Cem>Daily Maverick\u003C/em>, \"\u003Ca href=\"https://www.dailymaverick.co.za/article/2026-09-22-sa-is-under-cyber-siege-and-the-situation-will-only-get-worse/?ref=blogs.fluencysecurity.com\">SA is under cyber siege — and the situation will only get worse\u003C/a>,\" and every South African business leader should read it. It is about the struggle South Africa is having with its data sovereignty, both in government and across the country. His conclusion is hard to argue with. The situation is getting worse, because the foundation that sovereignty depends on, the policies, the procedures and the frameworks that define how a country protects what is its own, is not in place yet. Meanwhile, everything around it is moving at AI speed. The gap between what we have built and what we can protect is widening every month.\u003C/p>\u003Cp>It is easy to read an article like this and point fingers at the government: the corruption, the failure to do X, Y and Z. But your neighbor's company is failing to do X, Y and Z too, and if we are honest, so is yours. There is an old line about removing the log from your own eye before you remove the splinter from another's, and it fits here exactly. The sovereignty of a nation is not only held in government systems. It is held in our banks, our manufacturers, our retailers and every company that holds South African data. The list of companies that disclosed incidents in the past month alone, Bidvest Bank, CarTrack and Toyota South Africa among them, shows that business is missing what government is missing: clear policy, a framework to operate against, and the sense of urgency to fix it. So the article is more than a critique of Pretoria. It is a lesson every business leader can take into their own company. If you believe South African data sovereignty matters, the first data to secure is your own. Anyone who seriously tries will quickly understand how hard the government's job is. It is hard, but it can be done.\u003C/p>\u003Cp>The way forward starts with a better plan, and the good news is that we don't have to write it ourselves. The United States and Europe have spent forty years learning, mostly the hard way, what happens when business moves onto information systems and those systems become what criminals go after. That learning has been written down. NIST SP 800-53, ISO 27001, SOC 2 and the CIS Controls are all on the shelf, and so is a large market of products built to support them. Nothing about South Africa's situation requires us to invent a South African-only answer. The plans exist, and the tools to carry them out exist.\u003C/p>\u003Cp>A framework, though, is not a solution. We made this point in \"\u003Ca href=\"https://fluencysecurity.com/blog/how-ai-changed-the-soc-part-3-a-certificate-is-not-a-fitness-test/\">A Certificate Is Not a Fitness Test\u003C/a>.\" A company can meet every requirement of a standard and still deliver something that fails at the one job that matters. A framework tells you what a complete security program covers. It does not run that program for you. Adopting the framework and buying the products is the easy part. The real question is how we learn to implement and execute against them better.\u003C/p>\u003Cp>Think about Formula 1. The car is incredibly important, and no team wins without a good one. Yet the driver, and the crew who rebuild that car in the pits in under three seconds, are just as pivotal as the car itself. Give a championship car to a team that doesn't know how to run it and it will finish at the back of the field. Security works the same way. Installing a product is not the same as operating it. The frameworks and products are the car. Operation is the driver and the pit crew, and that is where South African companies are falling short.\u003C/p>\u003Cp>Operating security as a business starts with knowing what is valuable to us, because a plan that isn't built around what matters to the business is just a list of controls. From there, we set goals and execute against them, and everyone involved understands why each piece is in place. That understanding separates a company that operates its security from one that only owns it. Without it, security turns into plugging holes in a dike: each patch answers the last leak, the next one is already forming, and the work never ends.\u003C/p>\u003Cp>The firewall is the classic example of a product that is installed but not operated, and the truth is we don't even need one today. We should not be exposing services from our own infrastructure anymore. Our services and our data have moved to the cloud, and the only perimeter left is our people interacting with content, which is dangerous enough. Yet many South African businesses still think in terms of networks and perimeters. The real operating job is protecting users from the content they touch, protecting the endpoints they touch it from, and protecting their access to the cloud. The Sophos numbers bear this out: 85% of South African breaches involved identity compromise. Those attackers didn't break through a perimeter. They logged in.\u003C/p>\u003Cp>That is the uncomfortable truth underneath all of this: \u003Cstrong>prevention is not good enough\u003C/strong>. We can buy every product on the market and ask it to prevent, and prevention will still fail, because a valid login is not something a product can refuse. This is exactly why the frameworks exist. NIST 800-53 and ISO 27001 don't assume prevention will hold. They devote whole sections to monitoring, detection and incident response, because their purpose is to produce organizations that dynamically recognize when something is broken and fix it before the impact crushes them. That is what operating means in practice. We collect activity across users, endpoints and the cloud as one picture, understand where the gaps are, and close them before they become a gaping hole that all our data leaves through. The products make that possible, but only an operating organization makes it happen.\u003C/p>\u003Cp>Operating also means seeing all of it. That means collecting activity across users, endpoints and the cloud as one picture, understanding where the gaps are, and closing them before they become a gaping hole that all our data leaves through. This is what the frameworks describe and what the products make possible. None of it happens unless someone is operating it.\u003C/p>\u003Cp>All of this has to happen now, because waiting is itself a decision, and it is the wrong one. A government can fail at security and still be a government the next morning. A company often can't. Businesses that don't operate their security well go out of business, and there is no version of this where you get better after it happens to you. Aviation has long carried a grim joke about the FAA, which critics call the \"tombstone agency\" because its safety improvements so often follow a crash. We cannot run cybersecurity that way. For years the industry talked about waiting for the \"Pearl Harbor of cyber,\" the one catastrophic event that would finally force everyone to act. We have had it a couple of times already, and the GPAA was South Africa's. If a national pension fund offline for four months did not create the urgency, the next event won't either. Meanwhile, the attacks are moving at AI speed, and every month we wait widens the distance we have to close.\u003C/p>\u003Cp>There is an old saying that it is great to learn from your own mistakes, but better to learn from someone else's. In cybersecurity we are surrounded by other people's mistakes: companies across the United States and Europe that learned these lessons over forty years, our neighbors in the breach notices this month, and the South African government itself, whose struggles Schutters lays out so clearly. None of those lessons cost us anything unless we ignore them. The frameworks are written, the products are built, and the mistakes have already been made for us. What is left is the decision to start operating today, not after the next incident makes the decision for us.\u003C/p>\u003Cp>Data sovereignty is usually talked about as something a nation declares: laws about where data may live, policies about who may touch it, a promise from government that what is South African stays South African. But no declaration protects anything by itself. A country's sovereignty is the sum of how well the organizations inside it actually operate, meaning every bank, retailer, manufacturer and pension fund that holds a piece of the nation's data and either defends it or doesn't. The government will get its policies in place eventually, and we should hope it does. But sovereignty is not waiting on Pretoria. It is built or lost every day inside our own companies. The frameworks are on the shelf and the products are in the rack. What wins is the team that knows how to run them. The strength of our companies is the strength of our country.\u003C/p>","2026-09-28T04:10:30.000-04:00","Chris Jordan",[11,12,13,14],"Cybersecurity","SOC","South Africa","Data Sovereignty","https://storage.ghost.io/c/40/d4/40d450c8-df95-4dae-b590-5f6312e7dcb7/content/images/2026/09/ElevenLabs_image_gpt-image-2_Wide-cinematic-_2026-09-26T14_59_53.png",6,"https://fluencysecurity.com/blog/learning-from-south-african-data-sovereignty/",1790583068318]