You hire a cybersecurity company to protect your organisation. You give its team access to your networks, systems, security architecture and, in some cases, highly sensitive information. You may even give them permission to deliberately try to break into your systems to find vulnerabilities before criminals do. But who determines whether the people you have trusted to do this are actually competent? And when something goes wrong, who holds them accountable?
These questions are becoming increasingly important as African governments, businesses, banks, telecommunications operators and other organisations rely more heavily on private cybersecurity service providers (CSSPs).
Cybersecurity is no longer simply an IT support function. These companies can find themselves inside some of the most sensitive parts of an organisation’s digital environment.
So perhaps it is time we asked: who secures the securers?
At CyberM8 Initiative NPC, we don’t believe there is a simple yes-or-no answer to whether cybersecurity service providers should be regulated.
There is a strong argument for greater accountability. But there is also a very real danger that poorly designed regulation could make it harder for emerging cybersecurity companies to participate in the industry.
And that is a conversation Africa needs to have.
There is a public-interest question
The Private Security Industry Regulatory Authority (PSiRA) believes there is a case for appropriate oversight, but cautions against simply applying traditional private security regulation to cybersecurity.
PSiRA says: “Cybersecurity service providers are increasingly entrusted with access to sensitive information, critical systems and digital infrastructure. This creates a strong public-interest case for appropriate oversight, particularly in relation to competence, ethical conduct, accountability, vetting and minimum professional standards. However, regulation should not simply replicate traditional private security requirements in a highly specialised and rapidly evolving sector. An effective framework should be risk-based, proportionate and technology-neutral, recognise existing professional and international standards, and avoid unnecessary duplication between regulators. It should protect consumers, organisations and national interests while enabling innovation, skills development and investment. PSiRA’s position is that the development of such a framework requires continued consultation with government, cybersecurity professionals, industry, regulators and technical experts to determine the appropriate regulatory model and clearly define institutional roles and responsibilities.”
That last point matters. The conversation shouldn’t simply be about whether we regulate. It should also be about how we regulate, what we regulate and who should be responsible for that regulation. Cybersecurity is a highly specialised and fast-moving industry. The rules governing it need to recognise that reality.
Are our existing laws enough?
South Africa already has legislation and regulatory frameworks dealing with cybersecurity, cybercrime and data protection. But do they go far enough when it comes to the companies actually providing cybersecurity services? Cyber-law expert Prof Sizwe Snail ka Mtuze of Snail Attorneys believes there is still a gap.
He says: “South Africa’s current framework does not sufficiently regulate Cybersecurity Service Providers (CSPs) as a distinct profession. The National Cybersecurity Policy Framework (NCPF), now approximately 15 years old, requires modernisation to respond to today’s rapidly evolving cyber threat and technology landscape. While the Cybercrimes Act addresses unlawful conduct and POPIA establishes data-protection and security obligations, neither sets minimum competency requirements for CSPs. The Joint Standard on Cybersecurity and Cyber Resilience provides more specific requirements for financial institutions, but comparable sector-wide professional assurance remains limited. A dedicated, risk-based and proportionate framework is therefore needed, particularly for high-risk services such as penetration testing, incident response and managed security operations. Such regulation should establish competency requirements, minimum professional standards, a statutory duty of care, incident-reporting obligations, appropriate liability and effective oversight, while avoiding unnecessary barriers for SMMEs. For critical sectors, the gap between cybersecurity liability and professional assurance is increasingly untenable.”
The reference to small, medium and micro enterprises is especially important to us at CyberM8.
What happens to the small cybersecurity company?
Part of CyberM8’s work focuses on developing cybersecurity SMMEs and helping emerging businesses participate in the digital economy. That experience makes us particularly interested in what regulation could mean for smaller cybersecurity companies.
Africa needs more home-grown cybersecurity businesses. We need young cybersecurity professionals building companies. We need local intellectual property, locally developed solutions and African companies capable of securing African institutions. But a small cybersecurity company does not have the same legal, compliance and financial resources as a multinational technology company.
Imagine an emerging cybersecurity business employing five highly skilled young professionals. They have the technical capability to deliver penetration testing, vulnerability assessments or managed security services, but suddenly need to navigate expensive licensing, multiple regulatory registrations, complex compliance requirements and recurring fees before they can compete.

We could unintentionally create a market where only large companies can afford to be cybersecurity companies. That cannot be the outcome. But neither should the alternative be a completely open environment where practically anyone can establish a company, call themselves a cybersecurity expert and be given access to sensitive systems. Somewhere between those two extremes is a conversation worth having.
Perhaps the level of oversight should depend on the level of risk. Should someone delivering cybersecurity awareness training face exactly the same requirements as a company conducting penetration testing on critical infrastructure? Should a managed security operations centre responsible for monitoring government systems be treated in the same way as a small consultancy conducting basic cyber-risk assessments?
These are not questions CyberM8 believes it should answer alone. They require the industry.
Mozambique is already taking a different approach
This is not only a South African conversation. Across the border, Mozambique is developing a much more explicit regulatory framework for cybersecurity providers.
Mozambique’s Instituto Nacional de Tecnologias de Informação e Comunicação (INTIC) explains: “Mozambique is developing its legal and regulatory framework for building trust on cyberspace in the country. The Cybersecurity Law, the Cybercrime Law, the Data Center Regulation and the Cloud Computing Regulation, were recently published. The Cybersecurity Law introduces the registration and licensing of Cybersecurity Service Providers and defines INTIC as the National Cybersecurity Authority with responsibility in auditing and supervising cybersecurity service providers, both national and international. INTIC’s role includes the establishment of frameworks for accreditation and certification of cybersecurity professionals, and for the cybersecurity technical standards.”
INTIC also points to the importance of cooperation beyond national borders: “INTIC, through the National CSIRT, participate on the international CSIRT networks such as the SADC CSIRT Committee, the ANCA and AfricaCERT at the continental level, and FIRST and ‘United Nations Cybersecurity Mechanism’ at the global level, with the aim of learning and contributing for better cooperation and collaboration in cross-border cybersecurity services provision, including the alignment on minimum standards, and professional competency requirements.”
This raises an even bigger question for Africa.
What happens when cybersecurity crosses the border?
Imagine a cybersecurity company based in Johannesburg monitoring infrastructure for clients in Mozambique, Botswana and Kenya from one security operations centre.
Which country’s requirements should apply? What happens if the provider is licensed in one country but not recognised in another? And what happens if 20 African countries eventually develop 20 completely different licensing regimes?
Cybersecurity services are increasingly borderless. Regulation remains largely national. That tension is going to become harder to ignore. Perhaps Africa doesn’t need identical cybersecurity regulation in every country. But there may be value in discussing common minimum standards, professional competency, mutual recognition and cooperation between regulators.
That discussion becomes even more important as African countries push for greater digital sovereignty while simultaneously building a more connected continental digital economy.
This is exactly why we created the Africa Cybersecurity Indaba
CyberM8’s position is deliberately in the middle. We understand why government, regulators and organisations responsible for critical systems would want greater assurance about the people and companies entrusted with protecting them.
We also understand the entrepreneur trying to build a cybersecurity company with limited capital, compete for contracts, employ young people and establish credibility in a market where the barriers to entry are already significant.
Both perspectives matter. That is one of the reasons we created the Africa Cybersecurity Indaba.
The Indaba is intended to be a platform where government, regulators, cybersecurity companies, SMMEs, technology companies, academia, legal professionals, critical infrastructure operators and cybersecurity practitioners can sit around the same table and have these difficult conversations.

At the Africa Cybersecurity Indaba 2026, co-hosted by CyberM8 Initiative NPC and the department of communications & digital technologies, the regulation of cybersecurity service providers will form part of this broader conversation.
More than 750 leaders, policymakers, regulators, cybersecurity professionals, technology executives, researchers and other stakeholders from across Africa are expected to gather in Johannesburg in October.
We don’t expect everyone in the room to agree. In fact, they probably shouldn’t. The purpose of dialogue is not to arrive with the answer already written. It is to make sure that the people who will be affected by the answer have an opportunity to shape it.
Africa needs cybersecurity providers that can be trusted. It also needs a cybersecurity industry that can grow, innovate, create jobs and give emerging African companies an opportunity to compete.
How we achieve both may be one of the most important cybersecurity policy conversations we need to have. And perhaps that is where the answer to who secures the securers? should begin.
- Read more articles by CyberM8 on TechCentral
- This promoted content was paid for by the party concerned




