South African small businesses are targeted by cyber criminals precisely because they tend to have weaker defences than large corporates. POPIA has added regulatory liability to the financial loss. Cyber insurance covers both sides.
Small businesses consistently underestimate their cyber exposure. The assumption is that criminals target large corporates where the payoff is bigger. The reality is the opposite: large corporates have dedicated security teams, enterprise-grade software, and 24-hour monitoring. Small businesses often have none of these. A successful ransomware attack or data breach on a small business generates less per incident but requires far less effort to execute.
South Africa has also seen a significant increase in cyber incidents in recent years. According to reporting from Interpol’s Africa Cyberthreat Assessment, South Africa consistently ranks among the most-targeted countries on the continent. For small businesses, the financial consequences of a successful attack (system downtime, data recovery costs, client notification, and potential POPIA penalties) can be business-ending.
What cyber insurance covers
Cyber insurance is split into two categories: first-party cover (losses your business suffers directly) and third-party cover (claims made against your business by others who were affected).
First-party cover (your own losses)
- Ransomware and extortion response: The cost of engaging specialist cyber incident response teams, forensic investigation to determine how the breach occurred, and in some cases, ransom payments where the insurer and response team determine this is the only viable option. Note: insurers generally advise against paying ransoms, and payment is never automatic.
- Business interruption: Revenue lost during the period your systems are down or inaccessible, including the cost of restoring systems and data to their pre-attack state.
- Data recovery: The cost of recovering, reconstructing, or replacing corrupted or destroyed data and software.
- Crisis communication: Public relations and crisis communication costs incurred to manage the reputational impact of a breach.
- Notification costs: POPIA requires that affected individuals and the Information Regulator be notified when a data breach occurs. The cost of identifying who was affected and notifying them is covered under most cyber policies.
Third-party cover (claims by others)
- Data breach liability: Claims by customers, suppliers, or other third parties whose personal or confidential information was compromised in a breach that originated from your systems.
- Privacy regulatory defence: Legal costs associated with an investigation or enforcement action by the Information Regulator under POPIA. This includes the cost of responding to an information notice and defending against a compliance notice.
- Network security liability: Claims by third parties whose systems were affected because of a security failure in your network, for example if malware originating from your systems infected a client’s network.
POPIA and what it means for small businesses
The Protection of Personal Information Act came into full effect in July 2021. It applies to any business that processes personal information, which includes virtually every business in South Africa that holds customer data, employee records, or supplier information.
Under POPIA, a data breach triggers mandatory notification obligations. You must notify the Information Regulator and, in most cases, the affected individuals. Failure to do so, or failure to have adequate data protection measures in place, can result in a compliance notice, a fine of up to R10 million, or criminal prosecution in serious cases.
What POPIA means for your cyber insurance: A cyber policy with a POPIA or privacy regulatory defence component covers the legal and administrative costs of responding to an Information Regulator investigation and the cost of notifying affected individuals after a breach. Without this cover, those costs fall on the business directly.
The three most common cyber threats to South African SMEs
Ransomware
Ransomware encrypts your files and demands payment for the decryption key. A successful attack can take down an entire business network in minutes. Recovery without paying typically requires restoring from backup, which only works if your backups are clean, recent, and stored separately from the infected network. Many small businesses discover at the worst moment that their backups are either corrupted or were also encrypted in the attack.
Business email compromise (BEC)
An attacker gains access to a business email account (usually through a phishing attack) and uses it to divert payments. A supplier’s invoice arrives with changed banking details. A payment instruction appears to come from the business owner. By the time the fraud is discovered, the funds are gone and rarely recoverable. BEC is one of the largest sources of financial loss from cyber crime globally and is highly prevalent in South Africa.
Phishing attacks
Phishing emails impersonate trusted organisations (banks, SARS, couriers, or suppliers) to trick staff into revealing credentials, downloading malware, or making fraudulent payments. Most successful cyber attacks on small businesses begin with a phishing email that one staff member opened. No technical controls eliminate this risk entirely; training and processes reduce it, but residual exposure remains.
What cyber insurance does not cover
Cyber insurance has exclusions that small business owners should understand before purchasing:
- Pre-existing breaches: An incident that began before the policy inception date is not covered. If your network was compromised and you did not know it, and the breach is discovered after the policy starts, some policies will exclude it if the breach pre-dates the cover.
- Insider threats from authorised users: Some policies exclude losses caused by deliberate acts of employees or principals of the business. Check the policy wording on this point.
- Infrastructure failure (not security-related): A power outage, ISP outage, or cloud provider failure that is not caused by a cyber attack or security failure is typically not covered by cyber insurance; that falls under business interruption.
- War and state-sponsored attacks: Losses attributable to state-sponsored cyber attacks or acts of cyberwar are excluded under most standard cyber policies. This exclusion has become more contested as the boundary between criminal and state-sponsored attacks blurs, but it remains standard policy language.
Critical check: Not all cyber policies cover funds transfer fraud (BEC) as standard. If this is a risk for your business (and it is for any business that makes electronic payments), confirm that funds transfer fraud is specifically included in the policy, not excluded or sublimited to a nominal amount.
What to look for when comparing cyber policies
Cyber insurance policy quality varies significantly. When comparing options for a small business:
- Check whether incident response is provided in-house (the insurer provides access to a panel of cyber specialists) or whether you must find and fund your own response team.
- Confirm that business interruption is included and understand how the waiting period works; most cyber BI cover has a waiting period of 8 to 24 hours before cover kicks in.
- Confirm that the POPIA notification costs and regulatory defence are included.
- Check whether funds transfer fraud (BEC) is covered and at what limit.
- Look at the ransomware clause: specifically whether the policy pays only after proven impossibility of recovery without payment, or whether it supports the response process regardless of payment.
Frequently asked questions
Does my existing commercial insurance cover a cyber attack?
Standard commercial property, liability, and business interruption policies were not designed with cyber risk in mind, and most explicitly exclude cyber-related losses. A fire is physical damage to property. A cyber attack does not physically damage property in the traditional sense; the damage is to data, systems, and operations. Some policies have cyber exclusions that are explicit; others simply have no cyber coverage because the policy predates the cyber risk era. Cyber cover must be arranged as a standalone product or as a specific extension to your existing commercial policy.
Is cyber insurance worth it for a very small business?
This depends on what data you hold and how your business operates. A business that holds customer financial data, medical information, or large volumes of personal contact information has a POPIA exposure that makes cyber cover relevant regardless of size. A business that relies entirely on digital systems for trading has a business interruption exposure from a cyber attack. The premium for small business cyber cover has become more accessible as the market has grown. Whether it is worth it is a question of whether you could absorb the cost of a breach, a notification exercise, and a POPIA investigation without it affecting the business’s survival.
What does the Information Regulator do if I have a data breach?
When you notify the Information Regulator of a breach, they assess whether the breach resulted from a failure of your information security obligations under POPIA. They can issue an information notice requiring you to provide details about your data processing activities, an enforcement notice requiring corrective action, or a compliance notice. If you fail to comply with an enforcement or compliance notice, you may be referred for prosecution. Fines can reach R10 million. A cyber policy with regulatory defence cover pays for legal representation during this process and, where the policy terms allow, assistance with the compliance notice response.
Can I reduce my cyber insurance premium by improving my security?
Yes. Insurers assess cyber risk based on your security posture. Businesses with multi-factor authentication enabled on all accounts, regular and segregated backups, patched and updated software, staff phishing awareness training, and documented incident response procedures are lower risk and typically attract lower premiums or broader coverage terms. Some insurers provide pre-binding questionnaires that directly link your answers to the premium. Improving your actual security practices before applying for cyber cover is worthwhile both for the premium and for reducing your real-world risk.
Concerned about your cyber exposure?
We advise South African businesses on cyber insurance options appropriate to their size, data profile, and budget. Get in touch and we will help you understand what cover is relevant for your business.
Related reading
- Cyber Insurance: Graham Silva
- Business Interruption Insurance Explained
- Professional Indemnity Insurance
This article is for general information only and does not constitute financial advice. Cyber risk and policy terms evolve rapidly. Consult a registered financial services provider before making cover decisions. Graham Silva Insurance Consultants CC, FSP No. 5671, is an authorised financial services provider regulated by the FSCA.
