Evaluating South Africa’s Cyber Commissioner Bill: Necessity, Challenges, and the Path Forward

cyber commission bill

The proposed Cyber Commissioner Bill, officially known as the Constitution Twentieth Amendment Bill, has sparked debate regarding its feasibility and necessity in South Africa’s evolving cybersecurity landscape.

Legislative Background

Introduced to Parliament in 2023 by Glynnis Breytenbach, a former National Prosecuting Authority (NPA) prosecutor and a Democratic Alliance (DA) Member of Parliament, the Bill aims to amend the Constitution to establish a Cyber Commissioner as an independent Chapter 9 institution.

The Cyber Commissioner’s primary role would be to safeguard fundamental human rights as outlined in the Constitution. Over time, this office could assume the responsibilities currently managed by the Information Regulator, particularly in areas concerning cybersecurity oversight and data protection.

The Bill underscores that South African government departments and critical infrastructure remain vulnerable to cyber threats, with insufficient mechanisms in place to protect sensitive public information from breaches and cyberattacks. The current legal framework, according to the Bill, is either inadequate or reactive, addressing the consequences rather than proactively preventing cyber incidents.

Industry and Government Perspectives

During recent parliamentary hearings, the Department of Justice and Constitutional Development (DOJ&CD) raised concerns about the financial and logistical feasibility of establishing a Cyber Commissioner. Department spokesperson Kgalalelo Masibi questioned whether the national budget could sustain an institution with extensive powers and responsibilities.

Masibi highlighted existing cybersecurity measures, including the enactment of the Cyber Crimes Act (Act No. 19 of 2020) and the establishment of the Cyber Security Hub under the Department of Communications and Digital Technologies (DCDT). The Cyber Security Hub, serving as South Africa’s Security Incident Response Team, is already operational, while the State Security Agency is working on cybersecurity legislation.

“The question remains whether the creation of a new constitutional entity would resolve current cybersecurity challenges, particularly given resource constraints and overlapping mandates,” Masibi noted.

The Information Regulator’s Concerns

The Information Regulator, an independent body established under the Protection of Personal Information Act (POPIA), has also expressed reservations about the Bill. According to spokesperson Nomzamo Zondi, the Cyber Commissioner would not fully align with the broader mandate of processing personal information, as it focuses specifically on cybersecurity and IT infrastructure-related data processing.

Zondi suggested an alternative approach—expanding the Information Regulator’s mandate to encompass all aspects of cybersecurity rather than establishing a separate entity. “The regulator is already empowered by law to handle elements of cybersecurity; its role should be broadened rather than duplicated,” she stated.

Legal Perspectives on Overlapping Jurisdictions

Legal experts have noted significant potential for jurisdictional overlaps between the proposed Cyber Commissioner and existing institutions. Lucien Pierce, a partner at Phukubje Pierce Masithela Attorneys, pointed out that the Bill explicitly states that the Cyber Commissioner is intended to eventually replace the Information Regulator.

Pierce differentiated the Cyber Commissioner’s proactive mandate from the Cyber Crimes Act, which primarily defines cyber offenses and outlines enforcement responsibilities for agencies such as the South African Police Service (SAPS). While he acknowledged the value of consolidating cybersecurity responsibilities under a single entity, he questioned whether this necessitated a constitutional amendment.

“South Africa currently has multiple laws addressing cybersecurity, privacy, and critical infrastructure protection. A more strategic use of resources might be to empower and consolidate existing institutions rather than create new ones,” Pierce explained.

The Path Forward

Advocate Dirontsho Mohale of Baakedi Professional Practice emphasized that cybersecurity extends beyond personal information protection to fundamental rights such as dignity. While she recognized the need for enhanced cybersecurity governance, she suggested that expanding the Information Regulator’s mandate could achieve similar outcomes without the cost and complexity of establishing a new Chapter 9 institution.

Mohale also pointed out that the Cyber Commissioner Bill does not explicitly detail cybercrime-related regulations, implying that its proposed powers could be integrated into existing legislative frameworks such as POPIA, PAIA, and the Cyber Crimes Act.

Strengthening Cybersecurity in South Africa

The debate surrounding the Cyber Commissioner Bill highlights the urgent need for comprehensive, proactive cybersecurity strategies. Whether through a new constitutional entity or by reinforcing existing institutions, South Africa must ensure robust protections against cyber threats.

In this complex cybersecurity landscape, organizations must take proactive steps to safeguard their data, infrastructure, and compliance measures. StormWarning! offers expert cybersecurity consulting and auditing services to help businesses and government entities assess vulnerabilities, enhance security frameworks, and align with best practices.

With cyber threats evolving rapidly, relying solely on regulatory changes may not be enough. Contact StormWarning! today to conduct a cybersecurity audit and fortify your organization’s defenses against ever-growing cyber risks.

 

Designer 3Professional Summary of the Cyber Commissioner Bill

The feasibility of the Cyber Commissioner Bill, officially known as the Constitution Twentieth Amendment Bill, is under scrutiny in South Africa. Introduced in 2023 by Glynnis Breytenbach, a former prosecutor and MP for the Democratic Alliance, the Bill aims to amend the Constitution to establish a Cyber Commissioner as an independent Chapter 9 institution. This role would be pivotal in safeguarding basic human rights and could potentially replace the Information Regulator over time.

The Bill highlights the current inadequacies in protecting government departments and critical infrastructure against cyber threats. It suggests that existing legislation is either insufficient or only addresses the consequences of cyber incidents.

Key Points and Stakeholder Opinions

  • Department of Justice and Constitutional Development (DOJ&CD): Questions the financial feasibility and necessity of creating a new institution, given existing laws like the Cyber Crimes Act and the establishment of the Cyber Security Hub.
  • Information Regulator: Expresses concerns over the Bill, suggesting that its mandate could be expanded to include cyber security, thus avoiding overlap and potential regulatory conflicts.
  • Legal Experts: Opinions vary, with some advocating for the consolidation of responsibilities under a Cyber Commissioner, while others suggest enhancing the current role of the Information Regulator.

Take Action Now!

Given the increasing complexity and frequency of cyber threats, organizations must prioritize robust cybersecurity measures. StormWarning! offers comprehensive cybersecurity consulting and cybersecurity auditing services to help safeguard your critical infrastructure and sensitive information. Partner with us to ensure your organization is well-protected against evolving cyber threats.

For more information on how StormWarning! can assist your organization, contact us today and take the first step towards a secure digital future.

StormWarning! – Your Frontline Defense Against Cybercrime.

Protect. Prevent. Prevail.    PROTECT YOUR BUSINESS NOW!

 CYBER THREATS ARE ON THE RISE—ARE YOU PREPARED?

Related Articles

What is StormWarning! ?

 StormWarning! is a Cybersecurity consultancy. Our experienced team of cybersecurity experts provide cybersecurity assessments, cybersecurity training and cybersecurity solutions to organisations that have a high risk public profile. StormWarning! is your organisation's best defense against the ever growing cascade of innovative security threats raining down on all organisations with a public digital footprint.

What is Cybersecurity?

Cybersecurity is the practice of protecting critical systems and sensitive information from digital attacks. Also known as information technology (IT) security, cybersecurity measures are designed to combat threats against networked systems and applications, whether those threats originate from inside or outside of an organization. StormWarning! is constantly researching the latest cybersecurity threats and building innovative measures to prevent them.

 

NIST Audit & Targeted Cyber-Risk Training

StormWarning! offers comprehensive Cybersecurity Consulting, with a focus on its Automated Online Auditing Solutions, primarily the NIST CSF Readiness Audit. This audit is prioritized as its results directly inform the organization's needs for targeted cybersecurity training. By identifying specific gaps in risk management knowledge, they deliver precise education via Short Courses—like Cybersecurity Risk Management or Understanding Cybersecurity GRC—to ensure staff and leadership close deficiencies and maintain compliance.

Their full suite of services also includes robust Risk Management planning, development of essential Policies, impactful Cybersecurity Awareness Campaigns, and a security monitoring/incident response platform, StormFront. Additionally, we offer a resource library of Cybersecurity Books authored by our esteemed associate Dr. Zoran Mitrovic.