The purpose of the Joint Standard: Cybersecurity and Cyber Resilience is to set best practices for financial institutions, including retirement funds, to protect against cyber threats. And it’s the board of trustees’ responsibility to implement this all-encompassing but necessary undertaking.
As custodians of members’ retirement savings trustees must safeguard the fund and its assets against cyber attacks. The Joint Standard 2 of 2024: Cybersecurity and Cyber Resilience was created to compel financial institutions to do just that.
The Joint Standard, likely to become effective in June, is a comprehensive set of guidelines on best practices to protect retirement funds from cyber threats.
While not technically a “law”, the Joint Standards were made under the authority of the Financial Sector Regulation Act of 2017. This means they carry significant weight. Retirement funds, that fall under the scope of the Act, must comply.
The Financial Sector Conduct Authority (FSCA) and the Prudential Authority (PA) will enforce these standards. They can take action against funds that fail to meet the requirements by imposing administrative penalties (fines). Ultimately the aim is to protect the funds and the broader financial system.
Retirement funds were given 12 months from the publication date (May 2024) of Joint Standard 2 to implement the necessary measures. This means retirement funds don’t have much time left to prepare. Extensions for compliance will be considered on a case-by-case basis.
How prepared is your retirement fund for implementation?
It is a time-consuming and costly enterprise, and funds are urged to start with implementation sooner rather than later.
Although the board is allowed to delegate this task to third parties, ultimately the trustees remain responsible and accountable for compliance with the Joint Standard. Either way, the roles and responsibilities of all the management functions and committees related to cybersecurity should be clearly defined.
Let’s look at the key requirements
Trustees have to develop and maintain a cybersecurity policy and strategy, and implement a cybersecurity framework, all of which should be reviewed at least annually, with the framework undergoing an independent review.
Funds must put strong security measures in place to protect against cyber attacks. This means using good cybersecurity practices and setting up reliable systems to keep their IT networks safe and running smoothly.
Funds need to make cybersecurity a key part of how they are managed. This means cyber risks should be reported directly to the board, so the trustees are always aware of potential threats. They must set clear rules on how much cyber risk they are willing to take. These rules should be checked and updated regularly.
Funds must use network security tools to protect connections to the internet and service providers, while also detecting and blocking cyber threats. If cryptography is used, proper management of encryption keys is essential to maintain data security. Ongoing cybersecurity training is critical to ensure all users and administrators understand and follow best practices.
Retirement funds must have strict security measures, including a clear access policy, strong passwords, and multi-factor authentication for critical systems. If a serious cyber attack or data breach occurs, they must report it to the FSCA and the PA immediately.
Time is of the essence. This article is only a starting point – write cybersecurity on the board meeting’s agenda today so that your fund is prepared for 1 June. Trustees must consult the full Joint Standard and legal counsel to ensure complete compliance.
This summary is for guidance only and does not substitute professional advice.
Sources
Bowmans Law: South Africa: Cybersecurity and Cyber Resilience Joint Standard – Implications for pension funds
FANews: Obligations of insurers related to cybersecurity and outsourcing; Do you have R1.5m plus for cybersecurity compliance?
Moonstone: Cybersecurity Joint Standard: Authorities announce likely commencement date
Funded by

