HomeAI & CloudNot applying a fix from 2022 has left SA organisations 3 times...

Not applying a fix from 2022 has left SA organisations 3 times more likely to be breached

Gartner made a specific bet in 2022. By 2026, it predicted, organisations running continuous security monitoring would be three times less likely to suffer a breach than those still relying on annual audits. This is that year, and for boards that still treat the audit as their proof of security, the timing is anything but kind.

A roadworthy certificate confirms a car’s brakes worked on the day of the test, not six months later after a season of emergency braking for potholes and a worn pad nobody’s checked since. South Africa’s cybersecurity compliance regime has largely worked the same way: a snapshot once a year, followed by eleven months of silence while the environment it certified keeps changing underneath it.

“An annual audit tells you your defences worked on the day someone checked,” says Richard Ford, Group CTO at Integrity360. “It doesn’t tell you whether they’re still working today, and today’s usually when the attack happens.”

Gartner’s own emphasis at the time is a model called Continuous Threat Exposure Management: security testing that never stops or waits for a twelve-month reset. An organisation’s attack surface, its cloud systems, employee devices and third-party software, all change daily, and a test that runs once a year can’t certify an environment that’s already moved on by month two.

Regulators and standards bodies are reaching the same conclusion from a different direction. ISO 27001, SOC 2 and the newer PCI DSS 4.0 now require organisations to produce ongoing evidence of testing, not a single report filed once and then forgotten. A continuous programme, properly logged, produces that evidence automatically. Whereas, an annual audit leaves a compliance officer signing off on eleven months they can’t actually verify. “Boards like the certainty of an annual sign-off because it’s simple to report,” says Ford. “But simple isn’t accurate, and a board that only asks ‘are we secure’ once a year is asking the right question at the wrong frequency.”

The case is even sharper in a market already short on security skills. The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 70% of chief executives across sub-Saharan Africa say their organisations lack the skills to meet their own security objectives. “Automated detection and validation doesn’t rely on analysts watching a dashboard around the clock. In a market this short of people to do that watching, that’s the whole point,” says Ford.

RELATED ARTICLES