Cyber Security Summit South Africa β 38th Edition
The Cyber Security Summit South Africa, now in its thirty-eighth iteration, convenes in Johannesburg, South Africa. This event serves as a critical platform for cybersecurity professionals to address the evolving landscape of digital threats and explore innovative solutions. It brings together industry leaders, policymakers, and technical experts to foster collaboration and share insights on safeguarding digital infrastructure.
Committees & topics
Why it matters
In an increasingly interconnected world, cybersecurity is not merely a technical concern but a fundamental aspect of national security, economic stability, and individual privacy. The summit's focus on the ZAF context is particularly significant, given the region's growing digital economy and the corresponding rise in cyber threats. Discussions at this event will likely shape regional strategies for threat detection, incident response, and resilience against sophisticated cyberattacks.
The gathering in Johannesburg provides a unique opportunity for stakeholders to engage directly with the challenges and opportunities specific to the African continent. It allows for the exchange of best practices and the development of localized solutions that are crucial for building robust cyber defenses. The insights shared here can influence policy decisions and investment in cybersecurity infrastructure across ZAF and potentially beyond.
How to prepare
Attendees should prepare by familiarizing themselves with the current cybersecurity landscape in ZAF, including recent threat reports and regulatory developments. Understanding the specific challenges faced by organizations and governments in the region will enable more productive engagement and networking. Reviewing lessons such as "what-is-stakeholder-mapping" can provide a foundation for understanding the various actors involved in cybersecurity governance and their interdependencies.
To maximize the benefits of participation, consider how your expertise or organizational goals align with the summit's themes. Prepare to articulate your perspectives on key cybersecurity issues and be ready to engage in discussions on collaborative strategies. Lessons on "hidden-stakeholders" can be particularly useful for identifying and understanding the less obvious but influential parties in the cybersecurity ecosystem, enhancing your ability to form impactful partnerships.
Country perspectives
Where the most-relevant 1 countries stand on the core issues in play. Click through for the full country profile.
Topics & background
The background behind each topic and the actors that shape it.
Cybersecurity Governance
Key players
South AfricaHost state implementing the Cybercrimes Act and National Cybersecurity Policy Framework
United StatesLeading proponent of the multistakeholder model and applicability of existing international law to cyberspace
ChinaAdvocates state-led cyber sovereignty and a new binding UN cybercrime convention
RussiaCo-sponsor of the UN Cybercrime Convention and proponent of state-centric ICT governance
United KingdomKey driver of the OEWG outcomes and Commonwealth cyber capacity building
EstoniaReference state for national cyber governance and host of NATO CCDCOE
AI-Driven Security Operations
Key players
United StatesHome to dominant AI security vendors and issuer of the NIST AI RMF
ChinaMajor investor in AI-enabled defensive and offensive cyber capability
United KingdomConvenor of the AI Safety Summit process and AI Safety Institute
IsraelSignificant exporter of AI-driven cyber defense and offense tooling
South AfricaAdopter market shaping AU-level AI and cyber policy positions
Cloud Security
Key players
United StatesHome to the dominant hyperscale cloud providers and the CLOUD Act jurisdiction
IrelandEU base for major cloud providers and frontline data-protection regulator
GermanyDriver of EU cloud sovereignty initiatives such as Gaia-X
ChinaOperator of alternative cloud ecosystem (Alibaba, Tencent, Huawei Cloud)
South AfricaRegional cloud hub for sub-Saharan Africa with POPIA-driven localization
Cyber Resilience
Key players
United StatesSets resilience baselines through CISA and SEC disclosure rules
GermanyLeading EU voice on DORA and the Cyber Resilience Act implementation
United KingdomOperates the NCSC and Cyber Essentials assurance scheme
South AfricaRecovering from major incidents affecting Transnet, DPSA and Eskom-adjacent systems
SingaporeOperates the OT-CCE and a mature critical-sector resilience regime
Critical Infrastructure Protection
Key players
United StatesLead target and respondent to Volt Typhoon and similar OT-focused intrusions
UkraineMost active real-world laboratory for grid and infrastructure attacks
RussiaAttributed actor in multiple infrastructure intrusion campaigns
ChinaAttributed actor in pre-positioning campaigns against critical networks
South AfricaOperator of regionally significant grid, ports and telecoms infrastructure under cyber pressure
IsraelFrequently targeted in water and energy sector intrusions
Zero Trust Architecture
Key players
United StatesOriginator of the policy mandate via EO 14028 and NIST SP 800-207
United KingdomNCSC publisher of widely referenced Zero Trust design principles
SingaporeGovernment-wide adopter via the GovTech Zero Trust strategy
AustraliaImplementer through the Essential Eight and federal Zero Trust roadmap
South AfricaAdopting market in financial services and government modernization
Identity and Access Management
Key players
United StatesHome to dominant IAM vendors and CISA-led federal identity guidance
IndiaOperator of Aadhaar, the world's largest biometric identity system
EstoniaReference model for national digital identity and e-residency
South AfricaModernizing national identity and rolling out digital ID under POPIA
GermanyLead EU state shaping eIDAS 2.0 and the EU Digital Identity Wallet
POPIA Compliance
Key players
South AfricaEnacting jurisdiction with the Information Regulator as enforcement authority
United StatesHome to major cloud and platform processors handling South African personal data
IrelandEU lead supervisory authority for many multinationals processing POPIA-covered data
United KingdomAdequacy reference jurisdiction and significant cross-border data partner
NigeriaContinental peer regulator under the NDPA shaping AU data-protection alignment
Resources
News, lessons, and country profiles to prep for Cyber Security Summit South Africa β 38th Edition.
Recent reporting to ground your prep
Lessons
Bite-sized lessons to build the basics
Courses
Guided courses that go deeper on the topic
The states in play, with the data that shapes their stance
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier
Country dossier