South Africa’s lights could be switched off from anywhere in the world — Cybersecurity company
Cybersecurity firm Fortinet has raised the alarm over mounting cyber threats to South Africa’s physical infrastructure, particularly electrical infrastructure.
Fortinet business development manager for Africa, Martin Fernandes, said the national grid had reached a level of stability that was worthy of praise.
However, he explained that the new, more complex electricity ecosystem could be exposed to mounting cybersecurity threats.
“The new rapidly expanding, complex mesh of state utilities, IPPs, municipal microgrids, and industrial self-generation projects is reshaping the foundation of the economy,” Fernandes said.
“If these assets are not legally and digitally protected as sovereign infrastructure, the systems controlling our lights can be switched off from anywhere in the world.”
Fortinet described the scenario as being one where physical infrastructure stands with one foot in cyberspace and the other in the real world.
The transition to a decentralised grid merged Eskom’s once-isolated infrastructure with connected digital systems, expanding South Africa’s cyberattack surface.
“We now have a duty to continue our work on a unified security blueprint, or else we risk trading the newly waning physical energy crisis for a systemic digital one,” Fortinet said.
“This convergence is occurring at a time when South Africa has become a primary target for global cybercrime. The danger lies in the integration,” Fortinet said.
To manage the intermittent nature of renewables and the bidirectional flow of electricity, the grid relies on a sophisticated layer of information technology and operational technology.
“If cybersecurity controls across these points are fragmented or inconsistent, a breach within a third-party private provider’s network could move laterally into national critical infrastructure,” Fortinet said.
In one example in late 2025, malicious actors gained access to Poland’s energy systems and deployed destructive tools that crippled remote terminals and wiped data.
“While power production continued, the attack effectively blinded the operators, stripping away their ability to monitor or control generation sites remotely,” Fortinet said.
“This incident serves as a global case study in the vulnerability of distributed energy resources, proving that in a modern grid, a breach at the edge can quickly lead to a total loss of operational visibility.”
Warning about Eskom’s smart meter rollout

Fortinet highlighted Eskom’s smart meter rollout project as a potential new risk. As part of its plan to eliminate load reduction, the utility plans to roll out six million of these meters in the next three years.
Smart meters can be helpful in preventing electricity theft and the use of illegal tokens, managing electricity demand, and avoiding blackouts, but they could also be new gateways into grids.
“Authorities have been working around the clock to ensure the world-class upgrades are also protected by world-class cybersecurity measures,” it said.
“The threats highlight why the implementation of the Critical Infrastructure Protection Act, which is now fully active, has become more vital than ever.”
Fortinet said the act provided the legal framework to ensure that every asset, from residential smart meters to large-scale wind farms, would be treated as a protected sovereign asset.
According to the cybersecurity firm, true operational resilience will require an integrated platform approach driven by:
- Secure networking — Connecting distributed infrastructure reliably.
- Sovereign Secure Access Service Edge (SASE) — Ensuring local data governance and cloud access.
- SecOps with OT context — Using native AI to drastically reduce threat response windows.
Fortinet said this combination would enable a Zero Trust Network Access model that would enforce continuous identity verification from residential smart meters to remote wind turbines.