Response to 2026 Data Breach Investigations Report
The 2026 Data Breach Investigations Report highlights the evolving threat landscape. Here’s our take on the findings and what they mean for South African businesses.
By Jacques Oostenbrink Published on June 28, 2026Introduction
Cybersecurity threats are growing fast in South Africa. Small and medium businesses (SMBs) are and ongoing major targets for hackers. In fact, a recent report reveals that a single cyber attack can cost a business about 7% of its yearly revenue. This is a massive loss that no business owner can afford to ignore.
Key finding form the new report
The newest 2026 Data Breach Investigations Report (DBIR) shared some worrying facts:
- More attacks on weak systems: Hackers are taking advantage of system weaknesses much more often. We have seen a 55% jump in these types of attacks compared to last year.
- Slower fix times: It takes organisations a median of 43 days to patch these critical weaknesses. This long delay leaves businesses open to attacks for more than a month.
Our Response
We did not wait for this report to make a move. We constantly watch global threat feeds. In the midst of the trend, we took action right away. We set up much stricter rules for patching software across our clients' IT assets.
The new report confirms that our forward-thinking strategy was correct. We must keep up this strong defence, especially when it comes to websites and online portals that are open to the public.
How We Plan to Protect Your Business
Every business needs to keep running, even when cyber threats are high. We want to help you handle the risk of a sudden shutdown. To do this, we discuss your goals and budget. Together, we can decide what is acceptable for your operations.
We use five clear metrics to help you make safety decisions.
Click to expand: The Five Key Metrics We Track
- Mean Time To Detect (MTTD): This is the time allowed to spot a threat before we act.
- Mean Time to Contain (MTTC): This is the time allowed to stop a threat from spreading further.
- Mean Time to Clean Recovery (MTCR): This is the time we allow to double-check that a system is clean before we turn it back on.
- Recovery Point Objective (RPO): This is the maximum amount of data your business can safely afford to lose.
- Maximum Tolerable Downtime (MTD): This is the absolute longest time your business can be offline.
These metrics are very easy to talk about in your management meetings. Once we agree on these numbers, we know exactly how to protect your business. We do not need to have long, confusing IT meetings. These numbers help us spot the weak points in your current setup. From there, we build a solid plan to meet your standards. If the cost of a solution is too high, we simply adjust the targets to fit your budget.
How We Spot the Weak Points
How do we actually find these weak points? We use a helpful guide called the CIS Control Implementation Group 1. You can read more about it on the CIS Security Website.
In short, this framework gives us a list of 18 best practices to guard your business.
How Our CIS Audit Works
As your MSP we calobrate with you and look at key safety points to see where you stand. For every point, we ask three simple questions:
- Do you have a clear rule or policy for this?
- Is the rule in use and being followed?
- Do you check and measure if it is working?
This gives us a clear picture of your security. We compare what you want with what is actually happening in your business.
Once we find the gaps, we work with you as your trusted IT partner. We take ownership of the journey to bring your business up to standard.
This process also helps you comply with South African laws, like the Protection of Personal Information Act (POPIA). It also helps you meet global standards like ISO 27001 and ISO 27002. Together, we make sure you have the right security rules and clear proof that they are actually working.