New IT and cyber incident reporting template now in effect

Posted on Leave a comment

Financial institutions face a 24-hour reporting clock once an information technology or cyber incident is classified as material, under a prescribed regulatory process that took effect on 1 September 2026.

The Financial Sector Conduct Authority and the Prudential Authority announced the process in Joint Communication 5 of 2026.

The requirements are contained in Joint Notice 2 of 2026: Determination of the Notification Template for Joint Standard 1 of 2023 – Information Technology (IT) Governance and Risk Management Requirements for Financial Institutions and Joint Standard 2 of 2024 – Cybersecurity and Cyber Resilience Requirements, read with the Reporting of Material IT and/or Cyber Incident Template.

The underlying notification obligations are not new. Issued under the Financial Sector Regulation Act (FSRA), the determination prescribes the form, manner, and period for reporting material incidents under two Joint Standards already in force.

The process begins with an initial notification within 24 hours of classification, followed by an update within 14 calendar days and a final investigation report within a period agreed with the Authority responsible for the financial-sector law under which the institution is licensed or registered.

The standards behind the new reporting process

Joint Standard 1 of 2023: Information Technology (IT) Governance and Risk Management Requirements for Financial Institutions, which took effect on 15 November 2024, provides the broader governance and risk-management framework for IT. It covers areas including IT strategy, risk management, operations, the handling of sensitive information, resilience, business continuity, and assurance.

Joint Standard 2 of 2024: Cybersecurity and Cyber Resilience Requirements, in effect since 1 June 2025, focuses specifically on the controls and capabilities required to identify, protect against, detect, respond to, and recover from cyber incidents.

Joint Standard 2 also has a wider institutional scope. In addition to the categories covered by Joint Standard 1, Joint Standard 2 applies to certain Category I FSPs providing investment fund administration services, pension funds, section 13B administrators, over-the-counter derivative providers, and registered credit rating agencies.

Where an incident falls under both standards, the Authorities said one notification referring to both will be acceptable.

What makes an incident material?

The determination defines a “material incident” as a disruption of a business activity, process, or function that has, or is likely to have, a severe and widespread impact on the institution’s operations, services to its customers, or the broader financial system and economy.

Because the definition lists the institution’s operations, services to customers, and the broader financial system and economy as alternative areas of impact, an incident may qualify without threatening the broader financial system. Its impact on the institution’s operations or customer services would still have to be severe and widespread.

According to the Comments Report, industry stakeholders asked the Authorities to provide more objective criteria for determining materiality. ITLawCo proposed thresholds based on the number of customers affected, financial losses, or the duration of downtime, while Absa suggested predetermined criteria or a severity matrix to promote more consistent classification. The Institute of Retirement Funds Africa (IRFA) also sought greater clarity or sector-specific guidance for pension funds.

The Authorities declined to prescribe uniform thresholds. They said the Joint Standards are principles-based, and materiality must be assessed according to the institution’s nature, size, complexity, and risk profile. They expressly noted that what may be material to one institution may not be material to another.

The responsibility for classifying an incident rests with the financial institution. It must assess the impact and severity in the context of its operations and business practices and decide whether the reporting requirement has been triggered.

The Reporting of Material IT and/or Cyber Incident Template requires the institution to describe the criteria it used to assess materiality. During consultation, the Authorities said institutions should provide as much detail as possible about the criteria that influenced the assessment. The template does not prescribe a standard methodology for this assessment. Instead, it provides a free-text field in which the institution must describe the criteria it used, making the basis for its judgement part of the regulatory submission.

The Authorities also rejected calls for smaller financial institutions to receive more time or follow a simplified reporting pathway. They said an incident affecting a smaller institution may not have systemic or contagion effects but may still materially harm its customers or members and create conduct risk.

The clock starts at classification

The reporting template distinguishes between the detection of an incident and its classification as material. It requires the institution to record the detection date and time, but it states that the initial notification must be submitted within 24 hours after the incident is classified as material.

The Authorities clarified during consultation that these are 24 ordinary hours, not business hours. The deadline applies over weekends and public holidays, although an institution may report sooner if the relevant information is available.

The Association for Savings and Investment South Africa, the Banking Association South Africa (BASA), OUTsurance, and IRFA were among those that questioned whether the timeframe was realistic. They said the early stages of a serious incident would generally be devoted to establishing what happened, containing the incident, preventing further harm, and assessing materiality. The available information might be sparse, unverified, or subsequently shown to be incorrect.

Some commentators proposed extending the deadline to 48 hours or calculating it in business hours. The Authorities rejected these proposals, saying early visibility of incidents is critical for timely regulatory engagement.

They also said the people responsible for reporting should not be the same people responsible for containing the incident. In the Authorities’ view, this segregation of duties would enable reporting to proceed without hindering containment efforts.

The reporting clock does not start when the incident is first detected, but once the institution has classified it as material. The Authorities’ responses also contemplate that this decision, and the initial report that follows it, may have to be made before the investigation has produced complete or verified information.

Preliminary information must be reported on a best-efforts basis

The staged process allows institutions to provide further information after the initial 24-hour notification.

The initial notification requires contact details and key information about the incident. A material cyber or information-security incident requires additional preliminary information about matters such as the origin and cause of the threat, the type of attack, possible third-party involvement, and the vulnerabilities or weaknesses exploited.

Industry participants asked for some of these technical questions to be moved to the 14-day reporting stage because reliable answers may not be available during the initial response.

The Authorities declined. They said the information should be supplied on a best-efforts basis and could be updated later.

The initial notification must be followed within 14 calendar days by the “Impact of the incident” section of the template. This expands the report to encompass the root cause, operational and customer consequences, data compromise, service disruption, the institution’s response and recovery, governance escalation, financial losses, and measures to prevent a recurrence.

Within a period agreed with the responsible Authority, the institution must submit all completed tabs together with its final investigation report. The Authorities have not prescribed a standard format for that investigation report.

The consultation responses indicate that institutions may provide further information as their understanding develops. The Authorities discouraged changes to the initial submission, saying that institutions would have opportunities to provide updates during subsequent reporting stages. For submissions through the PA’s Umoja Portal, they said additional versions of the same spreadsheet should be uploaded where updates are required.

Accountability cannot be outsourced

The Authorities also clarified that outsourcing IT or cybersecurity functions does not transfer the regulated institution’s reporting responsibility to the service provider.

IRFA pointed out that many pension funds do not operate their own IT systems and rely on appointed administrators. It proposed that an administrator’s notification should suffice for an affected fund where suitable contractual and governance arrangements were in place.

The Authorities rejected this proposal. They said responsibility for outsourced activities cannot be delegated to an administrator or another service provider. The governing body remains ultimately responsible for ensuring compliance with the Joint Standards.

The Authorities said contractual arrangements with service providers must be clear about the requirements of the Joint Standards and the reporting of incidents to the financial institution.

It follows that, where an incident at an administrator or technology provider affects several regulated institutions, each institution would have to consider whether the incident is material in its own circumstances. An affected institution that classifies it as material must notify the responsible Authority.

The same principle applies to financial groups with several licensed entities. The Authorities said every affected financial institution must notify the Authority responsible for the legislation under which it is licensed or registered. A group-level report does not, by itself, discharge the notification obligation of each affected regulated institution.

Separate portals and separate regulatory obligations

There is no single joint submission platform. Banks, mutual banks, insurers, and their relevant controlling companies must submit through the PA’s Umoja Portal. The other institutions covered by the determination must use the FSCA’s Joint Standards Submission Portal.

Although the PA and FSCA use separate submission platforms, they said they would share information with each other where necessary.

The new process also does not replace obligations to notify other regulators.

An incident involving the unauthorised access or acquisition of personal information may also trigger notification requirements under the Protection of Personal Information Act. Institutions operating in the national payment system may have separate reporting obligations to the South African Reserve Bank’s National Payment System Department.

The Authorities said regulators operate independently and their reporting requirements may not seek substantially the same information. Institutions must therefore comply with each applicable regulatory regime.

Information already provided to another regulator may assist an institution in completing the template where it contains substantially similar information, but the prescribed template must still be submitted. The template asks whether another regulatory authority, such as the Information Regulator or the National Payment System Department, has been notified.

Why customer consequences matter

The reporting process extends beyond establishing the technical cause of an incident and restoring the affected systems.

The template seeks information about the impact on customers, including service disruption, compromised data, communication, support, claims, and financial losses. BASA questioned whether some customer-related fields belonged in an IT and cyber incident report.

The FSCA said operational incidents cannot be considered separately from their conduct-risk implications. An incident may trigger supervisory action, and information about customer communication, support, and continuity of service enables the regulator to assess the impact on customers and the institution’s response.

The FSCA’s response indicates that restoring the affected technology is not the regulator’s only concern. It also wants information about the institution’s communication with affected customers, continuity of service, and the support made available to them.

Banks also objected to providing sensitive technical information, including details about exploited vulnerabilities, control weaknesses, entry vectors, and compromised information. They argued that disclosing this information could create security and legal risks.

The Authorities retained the requirements. They said the information was necessary to assess risks to customer protection and financial stability and would be handled in accordance with the confidentiality provisions of the FRSA.

The PA will also initiate the process of withdrawing Directive 2 of 2019, which governs the reporting of material IT and cyber incidents by banks. The Joint Communication records an intention to start that process; it does not state that the directive was withdrawn when the new determination took effect.

Leave a Reply

Your email address will not be published. Required fields are marked *