Back to News
2bo Insights

POPIA Is a Network Problem Too: Infrastructure Controls South African Businesses Keep Missing

By 2bo Tech & Infrastructure Insights
POPIA Is a Network Problem Too: Infrastructure Controls South African Businesses Keep Missing

Most POPIA projects start in the legal department and end in a policy document. The problem is that the Act does not only govern paperwork. Section 19 requires appropriate technical measures to secure personal information, and technical measures live in your network, not your filing system.

This is a practical read for the people who actually hold the credentials: what POPIA implies for network and infrastructure design in South Africa.

R10m
Upper administrative fine under POPIA
72h
Practical target for notifying a breach once confirmed
Section 19
The clause that turns policy into network engineering

Where personal information actually sits

Before controls, get the map right. In a typical South African business, personal information is spread far wider than the CRM.

  • Shared drives and mailboxes: ID copies, payslips, medical aid forms and vetting documents accumulate in folders nobody owns.
  • CCTV and access control: Camera footage and biometric door records are personal information, and they usually sit on a flat network with default credentials.
  • Guest Wi-Fi and captive portals: If you capture a name, number or ID to grant access, you are processing personal information and you need a lawful basis and a retention limit.
  • Backups and old hardware: Decommissioned servers, retired laptops and offsite backup media routinely hold data the business believes it deleted years ago.

The network controls that satisfy Section 19

  • Segmentation: Cameras, printers, guest devices and payroll systems should not share a broadcast domain. Segmentation is the single most effective way to limit what a compromised device can reach.
  • Access control that maps to roles: Named accounts, no shared admin logins, multi-factor on remote access, and quarterly review of who still needs what.
  • Encryption in transit and at rest: Site-to-site links, remote access and backup targets all encrypted. Unencrypted backup media is one of the most common findings in a first assessment.
  • Logging you could actually produce: If you cannot show who accessed what and when, you cannot demonstrate compliance or scope a breach. Centralised logs with sensible retention are the evidence base.
  • Patch discipline on edge devices: Unpatched firewalls, VPN gateways and NVRs are the practical route into most South African incidents we see.

Operator agreements, the clause teams forget

If a third party processes personal information on your behalf, POPIA treats them as an operator and requires a written agreement covering security measures and breach notification. That includes your IT provider, your cloud backup vendor and the company monitoring your cameras. Being the responsible party means the accountability stays with you regardless.

A realistic first 90 days

  1. 1

    Map the data and the network together

    One workshop, two outputs: where personal information lives, and which network segment each of those systems sits on. Gaps become obvious immediately.

  2. 2

    Segment and lock the obvious exposures

    Isolate CCTV, building management and guest Wi-Fi. Remove shared admin accounts. Enforce multi-factor on every remote access path.

  3. 3

    Fix evidence and retention

    Turn on centralised logging, set retention periods for captive portal and camera data, and confirm backups are encrypted and restorable.

How 2bo helps

We assess the infrastructure side of POPIA readiness, segment networks properly, harden access and edge devices, and leave you with documentation your compliance team can actually use. This is engineering support for a legal obligation, not legal advice.

Is your infrastructure POPIA ready?

Book a session with the 2bo security team for a practical review of segmentation, access control, logging and edge hardening across your sites.

Found this useful?

Back to News