Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      Shoprite ranks cybersecurity as its number one risk - Pieter Engelbrecht

      Shoprite ranks cybersecurity as its number one risk

      9 October 2026
      Standard Bank to take up to $200-million stake in OPay - Sim Tshabalala

      Standard Bank to take up to $200-million stake in OPay

      9 October 2026
      Shoprite takes on the banking apps with airtime on Sixty60

      Shoprite takes on the banking apps with airtime on Sixty60

      9 October 2026
      How to tell telemarketers to get lost - officially

      How to tell telemarketers to get lost – officially

      9 October 2026
      Data centres are the new front line in the Russia-Ukraine war

      Data centres are the new front line in the Russia-Ukraine war

      9 October 2026
    • World
      SpaceX takes aim at US wireless carriers with spectrum acquisition

      Starlink is coming for your mobile operator

      9 October 2026
      The AI PC is finally here. It's just very expensive - Jensen Huang, Satya Nadella

      The AI PC is finally here. It’s just very expensive

      8 October 2026
      The memory crunch is making Samsung fabulously rich

      The memory crunch is making Samsung fabulously rich

      8 October 2026
      SpaceX to borrow $40-billion to buy Nvidia chips

      SpaceX to borrow $40-billion to buy Nvidia chips

      7 October 2026
      South Pole neutrino hunter wins Nobel Prize in Physics - Francis Halzen

      South Pole neutrino hunter wins Nobel Prize in Physics

      7 October 2026
    • In-depth

      10 days that changed the course of AI

      21 September 2026
      Meta to the AI industry: slow down without us - Mark Zuckerberg

      Meta to the AI industry: slow down without us

      16 September 2026
      Google DeepMind CEO Demis Hassabis. Image: John Sears

      The plan to stop AI from breaking the world

      16 July 2026
      The internet has a Strait of Hormuz problem

      The internet has a Strait of Hormuz problem

      15 July 2026
      AI boom sparks rally, frenzy and fear

      AI boom sparks rally, frenzy and fear

      11 June 2026
    • TCS
      W&W | LDV's Gerhard Moolman on electric bakkies, fleet orders and 'school fees'

      W&W | LDV’s Gerhard Moolman on electric bakkies and fleets

      9 October 2026
      TCS | Frogfoot sees bigger fibre deals coming - TechCentral Show guests Abraham van der Merwe and Shane Chorley

      TCS | Frogfoot sees bigger fibre deals coming

      8 October 2026
      Meet the CIO | Vodacom's Mohamed Sami on the agentic future

      Meet the CIO | Vodacom’s Mohamed Sami on the agentic future

      5 October 2026
      Lexi Novitske, general partner at Norrsken22, on the TechCentral Show

      TCS | Norrsken22’s Lexi Novitske on how China is winning African tech

      1 October 2026
      TCS | Dominic White and Adam Ely on AI agents going rogue

      TCS | Dominic White and Adam Ely on AI agents going rogue

      29 September 2026
    • Opinion
      When a machine can choose, who does it become? Fanie van Rooyen

      When a machine can choose, who does it become?

      9 October 2026
      Let South Africans jailbreak their way to digital sovereignty - Dirk de Vos

      Let South Africans jailbreak their way to digital sovereignty

      5 October 2026
      South Africa's next energy crisis is in the accounts department - Craig Holmes

      South Africa’s next energy crisis is in the accounts department

      29 September 2026
      The steam engine lesson AI doomsayers keep missing - Sam Clarke

      The steam engine lesson AI doomsayers keep missing

      28 September 2026
      Let South Africans jailbreak their way to digital sovereignty - Dirk de Vos

      Regulating AI: apply the laws we have first

      21 September 2026
    • Company News
      • 1Stream
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • Ascent Technology
      • AvertITD
      • BBD
      • Braintree
      • CallMiner
      • CambriLearn
      • CM.com
      • Contactable
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • HOSTAFRICA
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • Kaspersky
      • LSD Open
      • Mitel
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Publishared
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Telviva
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Vox
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • HealthTech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Policy and regulation
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
      • Watts & Wheels
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Sections » Information security » NEWORDER brings Lasso’s AI agent controls to South Africa

    NEWORDER brings Lasso’s AI agent controls to South Africa

    Promoted | South Africa has no AI law and is not getting one soon. Four instruments already on the books reach AI agents anyway.
    By NEWORDER1 September 2026
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    Get breaking news on WhatsApp

    NEWORDER brings Lasso's AI agent controls to South Africa - Bennie Barnard
    Bennie Barnard, chief commercial officer at NEWORDER

    NEWORDER has partnered with Lasso Security, a Tel Aviv-based AI security company, to bring agentic AI protection to South Africa. The platform lets NEWORDER run continuous adversarial testing against a client’s AI agents — attacking them the way an outsider would, to find where they give way.

    An AI agent is not a chatbot that answers questions. It is software that reads a document, decides what it means and then acts: pulls a record, sends a message, updates a system, calls another piece of software. It holds credentials, and it reads whatever it is pointed at. The usual comparison is a junior employee with system access, no training and no judgement — except this one works at machine speed at 3am, with nobody watching.

    That same agent takes instructions from anyone who can get text in front of it. A serious flaw found in a major corporate AI assistant last year allowed company data to leave the business through an instruction hidden inside an ordinary incoming e-mail. Nobody clicked anything. Nobody made a mistake.

    “Your AI agents take orders from strangers.”

    South African organisations have spent two years deploying these agents, and many still cannot say who the agents answer to. “In NEWORDER’s experience, few organisations can produce a list of the agents running in their estate,” says Bennie Barnard, chief commercial officer at NEWORDER. “They arrive through assistant rollouts, developer tools, vendor integrations and ordinary human beings solving real problems with whatever works.”

    One contract, one team

    NEWORDER, the Pretoria-based tactical managed cybersecurity firm, is Lasso Security’s official partner in South Africa. Local organisations can now reach the platform through NEWORDER: one contract, one commercial relationship, one team doing the deployment.

    The platform sits between a company’s AI agents and every business system they touch. It identifies the agents an organisation is running, including the ones nobody registered. It reads each instruction before the agent acts on it and stops the ones that break the rules. It also flags when an agent starts behaving out of pattern.

    Lasso Security was founded in Tel Aviv in 2023, is certified to ISO 27001 and SOC 2, and has customers across Europe, the US and Israel.

    “We are excited about this partnership,” says Elad Schulman, chief executive and co-founder of Lasso Security. “It strengthens our in-country presence and capabilities in a region moving quickly on AI adoption, and it pairs our research with a team that can act on it locally. Research on its own secures nothing. It has to reach an organisation through people with the expertise to apply it, and that is exactly what NEWORDER brings.”

    No AI law – the accountability arrived anyway

    In April 2026, the department of communications & digital technologies gazetted a draft national AI policy, then withdrew it 16 days later after journalists found that several of its 67 references were fabricated. The state got to pull the document and start again. A board does not get that option.

    “There is no official AI law in South Africa, and there will not be one soon, and that changes nothing,” says Barnard. “King V made the board accountable this financial year. Joint Standard 2 already requires evidence of testing. Popia never stopped applying. The question is not whether you have an AI policy. It is whether you can show, on a date, that somebody tested this and somebody independent checked the result.”

    Four instruments already reach these agents. None of them mentions artificial intelligence by name, because none of them needs to.

    • King V, the corporate governance code applying to financial years beginning on or after 1 January 2026, holds the governing body accountable for how technology is acquired, developed, used and distributed. It expects human oversight proportionate to risk, and periodic assurance. It is an apply-and-explain code rather than legislation, but it is binding on JSE-listed companies through the listings requirements and is the benchmark against which directors’ duties are read. An organisation that cannot show who oversees an agent, who can stop it and who last checked it does not have a governance story.
    • Joint Standard 2 of 2024, the cybersecurity and cyber resilience standard issued by the Prudential Authority and the Financial Sector Conduct Authority, took effect on 1 June 2025 for banks, insurers, asset managers, retirement funds and a wide range of financial service providers. It requires documented evidence of control testing on a maintained calendar, including simulated incidents, and third-party controls equivalent to the institution’s own. An agent that calls tools is a system, and nothing exempts it from the testing calendar.
    • Popia did not pause for AI. Section 19 requires safeguards. Sections 20 and 21 cover parties who process on a company’s behalf, and using one does not transfer liability. Section 71 restricts decisions taken solely by automated processing where they significantly affect a person — which is exactly what an agent making a credit or claims decision does.
    • The Cybercrimes Act 19 of 2020, section 2, deals with unlawful access. An agent tricked into reaching data outside its authority is that access, whoever or whatever typed the instruction.

    Then the deadline nobody legislates. The insurance market has started pricing AI risk explicitly rather than covering it by silence. From January 2026, standard-form generative AI exclusion endorsements became available for commercial general liability cover in the US, and several cyber carriers in the London market have moved towards sublimiting AI-related losses at roughly 10% of policy limits rather than excluding them outright. Neither change binds a South African insurer directly, but London wordings travel, and the renewal is the annual moment where documented AI governance stops being a policy document and becomes a number on a quote.

    Unmeasurable assurance is not assurance

    The habit in the South African market has been to buy the control and take the supplier’s report at face value. The organisation ends up holding a rating written by the party that sold it the technology.

    “We bring this platform into South Africa, and we attack what sits behind it,” Barnard says. “We hand over the attack chain, the raw result and a public standard that neither we nor Lasso controls. Your auditor can repeat every step we took. Unmeasurable assurance is not assurance. It is purely orchestrated marketing.”

    Start with the framework, not the supplier

    There is a test that costs nothing. The OWASP Top 10 for Agentic Applications 2026, published by the OWASP GenAI Security Project in December 2025, names the ten vectors an attacker can use to turn AI agents against the business running them.

    NEWORDER tests against that list rather than against its own methodology, and has documented what each of the ten means under Popia, King V and Joint Standard 2. The mapping is on NEWORDER’s website, free and without registration, at newordergroup.net/services/ai-security/owasp-agentic-top-10.

    “Benchmark your organisation against these 10 to work out which ones your estate would fail. Once you have identified them, ask your security team to confirm the organisation is covered. If they can confirm it, you have your assurance at no cost. If they can’t, you know what to do,” Barnard says.

    Lasso Security’s agentic AI protection platform is available in South Africa through NEWORDER. More on the platform is at lasso.security. Organisations wanting to talk it through can book a 30-minute conversation on the AI roadmap and where the obligations sit at newordergroup.net. No assessment takes place, and nothing is scoped. NEWORDER is a tactical managed cybersecurity firm certified to ISO/IEC 27001 and ISO 9001. This article is general information and does not constitute legal advice.

    • Read more articles by NEWORDER on TechCentral
    • This promoted content was paid for by the party concerned
    Add TechCentral as a preferred source on GoogleFollow TechCentral on Google NewsGet breaking news on WhatsApp


    Bennie Barnard Elad Schulman Lasso Security NEWORDER OWASP
    WhatsApp YouTube
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleEskom’s profit doubles even as it sells less electricity
    Next Article Digicloud recruits African partners for Google SecOps push

    Related Posts

    AI can find vulnerabilities. Humans find ways in

    21 September 2026
    Your AI agent is a privileged user. Treat it like one - Simone Santana

    Your AI agent is a privileged user. Treat it like one

    14 September 2026
    NEWORDER and ThreatNG deliver enterprise-grade protection for every business

    NEWORDER and ThreatNG: enterprise-grade protection for every business

    30 September 2025
    Add A Comment

    Comments are closed.

    Company News
    Why fintechs need an insurance partner they can trust - Hollard Insurance

    Why fintechs need an insurance partner they can trust

    8 October 2026
    Reusable KYC means the end of 'please upload your ID' - Contactable

    Reusable KYC means the end of ‘please upload your ID’

    8 October 2026
    Eliminating the 'toggle tax': how CRM integration changes customer experience - Martie de Beer

    Eliminating the ‘toggle tax’: how CRM integration changes customer experience

    8 October 2026
    Opinion
    When a machine can choose, who does it become? Fanie van Rooyen

    When a machine can choose, who does it become?

    9 October 2026
    Let South Africans jailbreak their way to digital sovereignty - Dirk de Vos

    Let South Africans jailbreak their way to digital sovereignty

    5 October 2026
    South Africa's next energy crisis is in the accounts department - Craig Holmes

    South Africa’s next energy crisis is in the accounts department

    29 September 2026

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    Shoprite ranks cybersecurity as its number one risk - Pieter Engelbrecht

    Shoprite ranks cybersecurity as its number one risk

    9 October 2026
    Standard Bank to take up to $200-million stake in OPay - Sim Tshabalala

    Standard Bank to take up to $200-million stake in OPay

    9 October 2026
    Shoprite takes on the banking apps with airtime on Sixty60

    Shoprite takes on the banking apps with airtime on Sixty60

    9 October 2026
    How to tell telemarketers to get lost - officially

    How to tell telemarketers to get lost – officially

    9 October 2026
    © 2009 - 2026 NewsCentral Media
    Built and maintained by Chronon
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}
    🇿🇦 Sign up to the TechCentral newsletter