As a retirement fund trustee, you have a legal duty to protect fund members’ assets — including their savings and personal information — from cyber threats. The Joint Standard on Cybersecurity and Cyber Resilience, which comes into effect on 1 June, outlines the minimum cybersecurity requirements that retirement funds must meet.
While trustees are not expected to be cybersecurity experts, they are ultimately accountable for ensuring that their fund complies with the standard. This means playing a strong oversight role in its implementation.
Trustees should be engaging proactively with all service providers to assess cybersecurity readiness. Ask tough questions: What controls are in place to prevent cyberattacks? How often are systems tested or audited? Are there clear plans for responding to a breach?
If any gaps are identified, trustees must follow up until those shortcomings are addressed. Compliance is not optional — and trustees remain responsible, even if the technical implementation is outsourced.
To support your understanding, this infographic breaks down common types of cyberattacks that funds may face.
To learn more about cybercrime, check out the Cybercrime Learning Lab. Or if you would like more in-depth knowledge, Atleha-edu and the ASISA Academy offer workshops for South African trustees and members of retirement funds on cybersecurity and other themes.


