A calm, structured response can reduce harm and support better decision-making.
Data breaches are no longer rare events reserved for large multinationals. They affect public bodies, private companies, professional firms, healthcare providers, schools, financial institutions and suppliers. When sensitive information is exposed, stolen or accessed unlawfully, the first few hours are critical. Management is often required to make decisions while facts are incomplete, pressure is increasing and stakeholders want answers.
The most common mistake is to treat the incident as an IT problem only. A data breach can quickly become a legal, operational, reputational, insurance and governance matter. The role of management is not to know every technical detail, but to ensure that the response is controlled, evidence is preserved, the right specialists are involved and decisions are properly documented.
Why this matters
In South Africa, security compromises may trigger notification and accountability considerations under POPIA. Even where the legal position still needs to be assessed, the organisation should be able to show that it acted responsibly, contained the issue, considered affected parties and reviewed the control weaknesses that allowed the compromise to occur.
What management should consider
- Activate the incident response process and appoint a clear decision owner.
- Confirm what is known, what is suspected and what still requires investigation.
- Preserve logs, emails, backups and affected systems before making unnecessary changes.
- Engage legal, cyber insurance and forensic support where appropriate.
- Assess whether personal information, client information or confidential business information was affected.
- Communicate carefully and avoid speculative statements before the facts are verified.
- Recover safely, not merely quickly, and validate systems before returning them to normal use.
Common pitfalls to avoid
Treating the matter as an IT-only issue.; Changing affected systems before evidence is preserved.; Communicating before the facts are sufficiently understood..
Key takeaway
A breach response should be disciplined, evidenced and coordinated. The organisation should be able to explain what happened, what was affected, what was done and how the weakness will be addressed.
Practical first step
Start by confirming the incident response contacts, escalation path and decision log template before an incident occurs. These simple items reduce confusion when pressure is high.
How Nexia SAB&T can assist
Nexia SAB&T can assist with incident response readiness reviews, POPIA security safeguard reviews, cyber governance assessments and executive tabletop simulations.
Author details: Rob Galetti | IT Audit and Cybersecurity | Nexia SAB&T
Date: 8 July 2026













