South African companies now face an average of 1,450 cyberattacks a week, up 4% year on year, according to figures published by insurer Bryte. One in three South African small and medium enterprises has already been targeted by a cyberattack. Just 17% of them carry cyber insurance.
That gap, between how often SMEs are actually being attacked and how few have transferred any of that risk to an insurer, is the story here, and it exists for reasons that are worth working through rather than simply citing as a statistic.
Why the exposure is worse for a small business, not better
The intuitive assumption, that a small business is a less attractive target than a large corporation, is backwards. Bryte’s figures put over 70% of SMEs reporting at least one attempted cyberattack in 2024, and cite global data showing 43% of cyberattacks hit small firms specifically, with human error present in 74% of breaches. Attackers running automated, high-volume campaigns are not selecting victims by revenue; they are selecting by weak defences, and a small business is, on average, weaker-defended almost by definition. Bryte’s own numbers back this directly: 40% of SMEs rely on free antivirus software, and 27% do not back up their data at all. Over 70% of local businesses were assessed as having little or no cybersecurity awareness.
Average data breach costs for South African organisations reached R44.1 million in 2025, a figure that would end most small businesses outright rather than merely dent a balance sheet.
There is no small-business exemption in the law
The regulatory backdrop makes the insurance gap more consequential than it might otherwise be. The Protection of Personal Information Act (POPIA) applies with no size-based exemption: a one-person consultancy carries the same legal obligations as a listed bank. Every organisation that processes personal information must appoint an Information Officer, registered with the Information Regulator, typically the office manager or a director by default in a small business rather than a dedicated compliance hire. Section 22 of the Act creates a clear duty to notify both the Regulator and every affected individual as soon as reasonably possible after a breach is discovered, and a business remains liable even when the actual breach occurred at a third-party vendor it can prove was at fault, because POPIA holds the “responsible party” accountable regardless of where the compromise originated.
The penalties attached to non-compliance are not abstract. Administrative fines run up to R10 million, layered on top of legal defence costs, regulatory investigation costs and any civil claims from affected customers. For serious breaches, directors and other responsible individuals can face personal liability, up to and including imprisonment, a detail that turns a data breach from a business risk into a personal one for whoever signs as Information Officer.
What a cyber insurance policy actually buys a small business
Cyber insurance for a South African SME is not the exotic, enterprise-only product the low take-up rate might suggest. Cover in the region of R150 to R500 a month is available for policies offering up to R10 million in protection, covering the costs a breach actually generates: forensic investigation, legal fees, regulatory notification costs, and in many policies, the ransom-negotiation and business-interruption losses that follow a ransomware incident specifically. Against a R44.1 million average breach cost and a maximum POPIA fine of R10 million, a policy at that price point is closer to a rounding error than a serious expense, which makes the 17% adoption rate harder to explain as a rational cost-benefit decision and easier to explain as a simple lack of awareness of the exposure.
For an SME owner reading the 17% figure and wondering whether their own business is the exception, the more useful exercise is working backwards from POPIA’s own definition: any business that holds a customer database, a staff HR record, a supplier contract with banking details, or an e-commerce checkout is a “responsible party” under the Act, with the full weight of its notification duties and fines attached, whether or not the business ever considered itself to be “in tech.” The law does not distinguish between a business that thought about cyber risk and one that did not. An insurer’s loss ratio eventually will.


