When an organization hires a cybersecurity company, it grants that team access to networks, systems, security architecture, and potentially highly confidential information. Sometimes they are even permitted to intentionally attempt to hack systems to find vulnerabilities before criminals do. However, the question arises: who determines the competence of these trusted individuals? And who is responsible if something goes wrong?
These questions are becoming increasingly relevant as governments, enterprises, banks, telecommunications operators, and other organizations in Africa rely more heavily on private cybersecurity service providers (CSSPs).
Cybersecurity is no longer just an IT support function; these companies can be present in the most sensitive parts of an organization's digital environment. This raises the question: who ensures the security of those who provide security?
In CyberM8 Initiative NPC's view, there is no single answer regarding the necessity of regulating CSSPs. There is a strong argument for increasing accountability, but there is also a real danger that poorly designed regulation could hinder the participation of new cybersecurity companies in the industry. This needs to be discussed in Africa.
There is a matter of public interest
The Private Security Industry Regulatory Authority (PSiRA) believes that proper oversight is necessary but cautions against simply applying traditional private security regulations to cybersecurity. PSiRA argues that because CSSPs are increasingly gaining access to critical systems, digital infrastructure, and confidential information, this creates a strong public interest in proper control, especially concerning competence, ethical conduct, accountability, vetting, and minimum professional standards.
Furthermore, according to PSiRA, regulation should not merely duplicate the requirements of traditional private security in such a highly specialized and rapidly evolving sector. The framework must be risk-based, proportionate, and technologically neutral, recognize existing international and professional standards, and avoid unnecessary duplication between regulators. It must protect consumers, organizations, and national interests while fostering innovation, skill development, and investment. PSiRA believes that developing such a framework requires continuous consultation with government, cybersecurity experts, the industry, regulators, and technical experts to determine the appropriate regulatory model and clearly define institutional roles and responsibilities.
The latter point is crucial. The discussion must address not only the question of regulation but also how to regulate, what to regulate, and who should be responsible for that regulation. Cybersecurity is a highly specialized and fast-changing industry, and its governing rules must reflect this reality.
Are our existing laws sufficient?
South Africa already has legislation and regulatory frameworks concerning cybersecurity, cybercrime, and data protection. But are they sufficient regarding companies that actually provide cybersecurity services? Cyber law expert Professor Sizwe Snail ka Mtuze from Snail Attorneys believes a gap still exists.
He notes: "South Africa's current structure does not adequately regulate cybersecurity service providers (CSPs) as a distinct profession. The National Cybersecurity Policy Framework (NCPF), which is about 15 years old, requires modernization to respond to today's rapidly changing landscape of cyber threats and technologies. While the Cybercrimes Act regulates illegal behavior, and POPIA establishes data protection and security obligations, neither sets minimum competency requirements for CSPs. The Cybersecurity and Cyber Resilience Common Standard provides more specific requirements for financial institutions, but comparable industry professional assurance remains limited. Therefore, a dedicated, risk-based, and proportionate framework is needed, especially for high-risk services such as penetration testing, incident response, and managed security operations. Such regulation should establish competency requirements, minimum professional standards, a legal duty of care, incident reporting obligations, appropriate liability, and effective oversight, while avoiding unnecessary barriers for SMEs. For critical sectors, the gap between cybersecurity accountability and professional assurance is becoming increasingly unacceptable."
Reference to small, medium, and micro-enterprises is particularly important to us at CyberM8.
What will happen to a small cybersecurity company?
Part of CyberM8's work focuses on developing cybersecurity SMEs and assisting startups in participating in the digital economy. This experience makes us particularly interested in what regulation might mean for small cybersecurity companies.
Africa needs more domestic cybersecurity businesses. We need young cybersecurity specialists creating companies. We need local intellectual property, locally developed solutions, and African companies capable of securing African institutions. But a small cybersecurity company does not possess the same legal, compliance, and financial resources as a multinational technology corporation.
Imagine a nascent cybersecurity firm hiring five highly skilled young professionals. They have the technical capability to perform penetration testing, vulnerability assessments, or managed security services, but suddenly they must navigate expensive licensing, multiple regulatory registrations, complex compliance requirements, and regular fees before they can compete.
We could unintentionally create a market where only large corporations can afford to be a cybersecurity company. This outcome should not happen. But the alternative—a completely open environment where almost anyone can start a company, call themselves a cybersecurity expert, and gain access to sensitive systems—is also unacceptable. Somewhere between these two extremes lies the conversation that needs to take place.
Perhaps the level of oversight should depend on the level of risk. Should someone conducting cybersecurity awareness training face the same requirements as a company performing penetration testing on critical infrastructure? Should a Security Operations Center monitoring government systems be treated the same as a small consulting firm conducting basic cyber risk assessments? CyberM8 does not believe these are questions to be answered in isolation; they require industry-wide participation.
Mozambique is already using a different approach
This is not just a South African discussion. Across the border, Mozambique is developing a much more explicit regulatory framework for cybersecurity providers. Mozambique's Instituto Nacional de Tecnologias de Informação e Comunicação (INTIC) explains: "Mozambique is developing its legal and regulatory framework to build trust in the country's cyberspace. Recently, the Cybersecurity Act, the Cybercrime Act, Data Centre Regulation, and Cloud Computing Regulation were published. The Cybersecurity Act introduces registration and licensing for cybersecurity service providers and designates INTIC as the National Cybersecurity Authority responsible for auditing and overseeing cybersecurity service providers, both national and international. INTIC's role includes creating frameworks for the accreditation and certification of cybersecurity specialists, as well as for cybersecurity technical standards."
INTIC also points to the importance of cross-border cooperation: "Through the National CSIRT, INTIC participates in international CSIRT networks such as the SADC CSIRT Committee, ANCA, and AfricaCERT at the continental level, as well as FIRST and the UN Cybersecurity Mechanism globally, aiming to study and promote better cooperation and collaboration in providing cross-border cybersecurity services, including harmonizing minimum standards and professional competency requirements."
This raises an even larger question for Africa: what happens when cybersecurity crosses borders? Imagine a cybersecurity company based in Johannesburg that manages infrastructure for clients in Mozambique, Botswana, and Kenya from a single security operations center. Which country's requirements apply? What happens if a provider is licensed in one country but not recognized in another? And what if 20 African countries ultimately develop 20 completely different licensing regimes?
Cybersecurity services are becoming increasingly borderless, while regulation remains predominantly national. This tension is becoming harder and harder to ignore. Perhaps Africa does not need identical cybersecurity regulation in every country. But there may be value in discussing common minimum standards, professional competence, mutual recognition, and cooperation among regulators.
This discussion becomes even more vital as African nations strive for greater digital sovereignty while building a more interconnected continental digital economy. This is why we created the Africa Cybersecurity Indaba.
CyberM8's position is deliberately balanced. We understand why governments, regulators, and organizations responsible for critical systems want greater assurance in the people and companies entrusted with their protection. We also understand the entrepreneur trying to build a cybersecurity company with limited capital, compete for contracts, hire youth, and gain market trust where entry barriers are already significant. Both viewpoints are important. This is one reason we created the Africa Cybersecurity Indaba.
The Indaba is intended to be a platform where governments, regulators, cybersecurity companies, SMEs, tech companies, academia, lawyers, critical infrastructure operators, and cybersecurity specialists can come together at one table to have these complex conversations.
Africa Cybersecurity Indaba 2026
At the Africa Cybersecurity Indaba 2026 event, jointly organized by CyberM8 Initiative NPC and the Department of Communications and Digital Technologies, the regulation of cybersecurity service providers will be part of this broader discussion. Over 750 leaders, politicians, regulators, cybersecurity specialists, tech executives, researchers, and other stakeholders from across Africa are expected to gather in Johannesburg in October.
We do not expect everyone in the room to agree. In fact, they probably shouldn't. The goal of the dialogue is not to arrive at a ready-made answer. Its goal is to enable those who will be affected by the answer to shape it.
Africa needs reliable cybersecurity providers. It also needs a cybersecurity industry that can grow, innovate, create jobs, and provide opportunities for young African companies to compete. How do we achieve both—this could become one of the most important discussions in cybersecurity policy. And perhaps this is where the answer to the question 'who ensures the security of those who provide security?' should begin.
