Editor's Note
Last issue we asked who has access to your systems right now. The response told us something. People know the answer matters. Very few are confident they could produce it on demand.

This issue takes that one step further, and outward. Not who has access to your systems, but who is asking you to prove it. Across South Africa, larger organisations are turning cybersecurity into a procurement condition. Not a preference. A condition. If you supply anything to a bigger business and you touch their data, that shift is heading toward your next contract renewal.

The reason is legal, and it is worth understanding properly, because it explains why the questions have suddenly become so specific. Here is what you need to know.

Your Biggest Client Is Checking Your Security

The law that makes your client answerable for you

South African enterprises have started asking their suppliers hard questions about security. This is not procurement being difficult. It is the law working exactly as designed.

POPIA splits every data relationship into two roles. The responsible party is the business that decides why and how personal information is used. The operator is the supplier that processes that information on their behalf. If you hold client data — payroll files, customer records, invoices, medical information — you are an operator.

Section 21 of POPIA requires the responsible party to have a written contract with every operator. That contract must oblige the operator to maintain the security measures set out in Section 19: appropriate, reasonable technical and organisational steps to prevent loss, damage, or unlawful access to personal information.

Now the part that changes commercial behaviour. When the supplier is breached, the responsible party still answers to the Information Regulator. Liability does not travel down the chain. It stays at the top.

The mistake: treating the questionnaire as paperwork

Most SMEs treat a client's security questions as an administrative hurdle. The form arrives. Someone fills it in from memory. The contract renews.

That approach is running out of road, because enterprises have seen what happens when a supplier gets it wrong.

In April and May 2022, Grapevine Interactive was hit by a brute force attack — an attacker cracking a password by trying combinations until one works. Grapevine ran an e-statement service for Dis-Chem. Around 3.6 million customer records were accessed.

Grapevine was breached. Dis-Chem received the enforcement notice. The Information Regulator found that Dis-Chem had not entered into an operator agreement with Grapevine, had not ensured Grapevine's security measures were adequate, and had not put measures in place to detect unlawful access to its environment. Failure to comply with that notice carried exposure of up to R10 million, imprisonment, or both.

Every procurement team in the country read that outcome.

The consequence is commercial before it is legal

In 2025, 17% of data breach incidents traced back to a third-party supplier or the wider supply chain, at an average cost of R29.6 million.

Your client's exposure is real and they know it. So the questions are getting sharper, and they are moving out of the questionnaire and into the contract itself. Security posture is becoming a condition of doing business.

For an SME, this rarely arrives as a dramatic moment. It arrives as a renewal that stalls. A tender that scores you down on a section you did not know existed. A request for evidence you cannot produce inside the deadline.

You do not lose the contract because you were breached. You lose it because you could not prove you were not going to be.

What your client is actually asking for

They are not asking whether you feel secure. They are asking for evidence.

Six things answer almost every supplier security questionnaire in circulation. A signed operator agreement with each client whose data you hold, and with each of your own suppliers who touch that data. A current list of your systems and who has access to them. Proof that you scan for vulnerabilities and fix what you find, with dates attached. Evidence that your staff are tested against phishing, showing results rather than attendance. An incident response plan that names who does what in the first 24 hours. And a named Information Officer, registered with the Information Regulator.

None of this requires new software. It requires the record to exist before someone asks for it.

The Bottom Line

Your client is legally answerable for a breach that starts with you. That makes your security their commercial risk, and it is why the questions have changed. The businesses that keep these contracts are not the ones with the best tools. They are the ones that can produce the evidence on the day it is asked for.

See how the evidence trail gets built

Aigeus Cyber works with South African SMEs to turn assumed protection into documented proof.

Aigeus Cyber Briefing