In full
Large numbers stop being useful at a certain size. An estimated R141.96bn a year, roughly 1.81% of GDP, is easy to read past. The per-incident figure is harder to ignore: reporting puts the average cost of a single South African data breach at R44.1m.
You cannot act on an average, but you can act on your own surface. In order: list what of yours is reachable from the public internet, including the assets nobody remembers owning; check whether your domains can be spoofed in email; find the stale and shared privileged accounts; and rehearse who does what in the first hour of an incident. Each of those is inexpensive set against the reported average, and each addresses a category the reporting says most incidents begin in.
The reported picture
The R141.96bn estimate is built from 3,219 reported breaches during the 2025/26 financial year. Volume appears to be climbing rather than levelling: confirmed attacks rose 140% in the first half of 2026, and in June 2026 South African organisations were hit by 8,850 cyberattacks, around 2,065 a week. On the same reporting, South Africa was the fourth most attacked country in Africa.
These are published estimates from industry and press reporting rather than figures we have measured ourselves, and breach-cost methodologies vary a good deal between sources. We would not build a business case on the exact rand value. The direction and the order of magnitude are consistent enough to act on.
Government is in the target set
March 2026 illustrated the point. The XP95 group breached three government entities, the Gauteng Provincial Government, the Gauteng City Region Academy, and Statistics South Africa. Reporting has government, manufacturing, healthcare, education and financial services all being actively targeted, which is close to a list of the sectors that hold the most personal information.
A breach every three hours is not a run of bad luck. It is a rate, and rates respond to changes in the conditions that produce them.
The uncomfortable, useful finding
The most actionable figure in the reporting is also the least flattering. Up to 95% of South African breaches are attributed to avoidable human error, and around 90% are classed as preventable.
Preventable is doing a lot of work in that sentence, and it deserves scepticism: it is easy to call an incident preventable after you know how it happened. Even discounted heavily, though, it points somewhere specific. If most incidents begin with something ordinary, a credential reused across services, a forgotten subdomain still resolving, an expired certificate, a mailbox rule nobody set, then the highest-return work is not exotic.
Where the money goes further
- Know what you actually expose. Most organisations cannot list their own internet-facing assets. The forgotten ones are not defended, because nobody remembers to defend them.
- Fix the email surface. Spoofing resistance and mailbox rule abuse are cheap to check and are involved in a large share of business email compromise.
- Close the identity gaps. Reused credentials and stale privileged accounts are the most common way in and among the least expensive to address.
- Rehearse the response. A large share of breach cost is dwell time and disorder. An organisation that has practised detects sooner and spends less.
- Track it to closed. A finding that is known and open is not materially better than one nobody found.
What the numbers argue for
Set an average incident at R44.1m against the cost of knowing your external exposure and closing what it finds, and the arithmetic is not close. That is true even if the published averages are generous, because the comparison survives a large discount.
We would still be careful about how the figure is used. An average breach cost is not a prediction for your business, and no amount of preventive work reduces the risk to zero. The honest claim is narrower and still worth making: a meaningful share of these incidents begin with something visible from the outside, and things visible from the outside can be found and closed before somebody else finds them.
Reported figures put South African breach costs at around R141.96bn a year, an average incident at R44.1m, and confirmed attacks up 140% in the first half of 2026. Treat the exact values as estimates. The consistent finding across sources is that most incidents start with something ordinary and visible, which is also the cheapest category of problem to find and fix.
