Security15.06.2026

Important state-owned company can’t afford to protect South Africa from cybercrime

The State Information Technology Agency (SITA) said that initiatives to upgrade its networks to better protect them against cyberattacks depended on funding from government departments.

It said there were ongoing cyber threats targeting South Africa’s public infrastructure and government institutions, but it couldn’t address all vulnerabilities due to a lack of funds.

SITA is the South African government’s IT agency, a state-owned enterprise that coordinates public digital communication and technology resources.

Tlali Tlali, head of corporate affairs at SITA, told MyBroadband that the implementation of initiatives to strengthen critical government ICT infrastructure depended on external funding and approvals.

Those would come from the individual government departments that SITA provided services to, as the state-owned company operated on a cost-recovery basis.

This meant it earns just enough from providing services to government departments to continue operating. There are no funds to deploy its own upgrades.

“There are ongoing modernisation initiatives aimed at improving the security posture, resilience, and performance of critical government systems,” SITA said.

“The implementation of these initiatives is dependent on departmental approvals and associated funding.”

Unless individual government departments direct SITA to upgrade a network to better protect it against cyberattacks and bankroll it, SITA cannot do so.

SITA’s feedback came after South African cybersecurity researcher Joel Cedras reported for GroundUp that more than 5,000 known security flaws exist on SITA’s public-facing networks.

Within the 1,100 public systems belonging to government departments and entities, including municipalities and agencies to which SITA provides digital support, he identified 125 critical flaws.

These were flaws that typically received urgent attention because they provided an easy, low-barrier way for a cybercriminal to exploit and bypass security controls.

One particularly badly affected SITA-supported network serves the Amathole District Municipality in the Eastern Cape.

According to Cedras, one of this municipality’s servers had 353 known security vulnerabilities, of which 94 were rated “critical.”

A fair few of the worst-performing networks in terms of vulnerabilities were owned by local municipalities, including Witzenberg and Thaba Chweu.

SITA must wait for permission

Tlali Tlali, head of corporate affairs at SITA

The quickest way to address some of these vulnerabilities was through server software updates, since many public networks run on outdated, unsupported technology.

Larger-scale initiatives include systemic cybersecurity reviews, credential resets, training initiatives and hardware upgrades.

Tlali said that SITA recently conducted a security assessment across national and provincial government departments, which highlighted areas that required immediate action.

“These assessments highlight areas that require remediation to improve security posture, which government departments need to prioritise and work with SITA to address,” he said.

However, not all government ICT systems were supported by SITA, with Cedras indicating that the non-SITA government Internet comprised 516 systems, each often containing several vulnerabilities.

“Although secure connectivity and networks are provided by SITA, not all government systems and applications are hosted within SITA’s infrastructure,” said Tlali.

“Many departments host their systems in their own environments or through approved third-party service providers.”

Many of these departments, however, still make use of SITA’s network services for connectivity and secure access.

Tlali said SITA was aware that government institutions were under constant cyber threat. As a result, it remained committed to continually improving the security posture across government networks.

“We conduct continuous cybersecurity posture reviews to identify risks and improvement opportunities,” said Tlali.

“These reviews include the implementation of mitigation measures and security enhancements aimed at strengthening and securing SITA’s infrastructure against evolving cyber threats.”

Show comments

Latest news

More news

Trending news

Sign up to the MyBroadband newsletter