In an increasingly digitised world, where critical infrastructure and essential services rely heavily on interconnected networks, the threat of cyberattacks looms large. This menace has become a pressing concern in SA’s energy sector, underpinned by high-profile incidents that have created the urgent need for enhanced cyber resilience strategies.
As these attacks intensify in scale and sophistication the implementation of robust cyberattack mitigation strategies is poised to become not only a best practice but also a potential legal requirement in SA.
Rising threats: lessons from past attacks
Two significant cyberattacks stand out as cautionary tales for SA's energy sector. In July 2019 City Power fell victim to a ransomware attack that incapacitated its databases, applications and network systems. This attack caused widespread disruption. It disabled the utility’s website and prevented its customers from being able to purchase electricity, which potentially affected up to a quarter of a million customers. In addition, the attack affected City Power’s ability to efficiently detect faults in the distribution system, which caused delays in responding to localised blackouts and leaving several suburbs in the dark.
Similarly, in March 2022 Eskom suffered a ransomware attack that exposed critical information on the dark web, underscoring the perilous vulnerability of even the most central energy infrastructure. A matter of particular concern is the vulnerability of generation and distribution assets in SA to cyber security threats. While there have been no publicised direct cyberattacks on Eskom’s power stations, or on a private renewable energy company's generating assets, the threat of this cannot be discounted as many such attacks have been observed overseas.
One example is the cyberattack suffered by a European wind turbine manufacturer, whose satellite connection, remote monitoring and control of its wind turbines was disrupted. The disruption affected about 5,800 wind turbines, or the equivalent of 11GW of installed capacity. Fortunately, power supply stability could be maintained as the affected wind turbines switched to automatic mode, thus allowing them to operate despite the disruption. However, it took several months to restore connection with all of the affected wind turbines and this led to lengthy and costly upgrades to the company’s hardware and software.
These examples represent, among other threats, an attack on a company’s ability to generate revenue and maintain the functioning of its critical infrastructure. It is a data breach of sensitive information and a disruption of communication between a company and its generating assets. Increasingly, cyberattacks also represent a hybrid threat to both a company’s cyber space (an online payment system, for instance) as well as its physical assets (with the operation of generating assets, for example).
Embracing cyber resilience as a strategic imperative
In the face of such mounting challenges cyber resilience emerges as a guiding principle for safeguarding critical infrastructure, both of a digital and physical nature. Cyber resilience encompasses a proactive and adaptive approach to cyber threat management aimed at preventing attacks, swiftly mitigating their impact, and ensuring a rapid recovery to normal operations.
At its core, cyber resilience requires a multifaceted strategy, involving the implementation of advanced technical measures, fostering a cybersecurity culture within the organisation, establishing response protocols and continually refining strategies based on evolving threats and lessons learnt from past incidents. Upon the occurrence of an attack, to establish or activate a response team, identify the breadth and depth of the risk, to contain it and, once the initial threat vector has been established, recover and build back stronger from the cyberattack. Given the ever-evolving nature of cyber threats, an effective cyber resilience strategy is a dynamic, ongoing effort.
Navigating statutory and contractual landscapes
We believe the development, implementation and monitoring of a cyber resilience strategy may become both a contractual and/or statutory obligation in the SA energy sector. The Critical Infrastructure Protection Act of 2019 (Cipa), effective since April 2022, has introduced the notion of securing “critical infrastructure”. This legislation mandates that entities that own the critical infrastructure take prescribed security measures to safeguard it. While no infrastructure has been officially designated as “critical” under Cipa yet, the act’s provisions highlight the potential legal obligations on the horizon.
However, waiting for regulatory shifts might not be the most prudent course of action. As the stakes continue to rise, industry players are recognising the value of contractual obligations to bolster cyber resilience. Unlike statutory requirements, contractual obligations can be swiftly adopted and tailored to the unique needs of organisations. This flexibility empowers entities to proactively address cyber risks and build resilience without waiting for legislative processes to unfold.
The rapidly evolving threat landscape demands that SA’s energy sector takes proactive steps to safeguard critical infrastructure. As demonstrated by the City Power and Eskom incidents, the potential repercussions of inadequate cyber resilience are severe.
The imperative to institutionalise cyberattack mitigation strategies, driven by the practicalities of maintaining operations, the exigencies of public safety and the emerging legal landscape, offers the energy sector a transformative opportunity. By embracing cyber resilience as a strategic imperative, organisations can navigate the complexities of cyber threats and protect the foundational systems that power SA’s development and growth.
As pioneers of this paradigm shift, energy sector players have the potential to not only avert crises but also set a precedent for national cyber resilience in an increasingly interconnected and vulnerable world.
• The authors are with Herbert Smith Freehills.







Would you like to comment on this article?
Sign up (it's quick and free) or sign in now.
Please read our Comment Policy before commenting.