Financial sector faces pressure to meet FSCA Cyber Resilience Standards
The FSCA’s Joint Standard on Cybersecurity and Cyber Resilience is set to commence in June 2025, putting pressure on South African financial institutions to align with the stringent requirements established by the Financial Sector Conduct Authority (FSCA) in collaboration with the South African Reserve Bank (SARB).
With South Africa’s financial sector being one of the country’s most targeted industries, the Joint Standard is designed to mitigate the growing risks posed by cyber threats, protecting both the institutions themselves and the broader financial system from disruptive cyber events. This will affect organisations including, but not limited to, banks, mutual banks, insurers, retirement funds and fund administrators, and collective investment scheme managers.
Troye, a leading IT solutions provider and Arctic Wolf partner, is committed to helping financial institutions and any other organisation required to comply to meet these demanding cybersecurity standards. Through their collaboration with Arctic Wolf, Troye offers a range of tailored solutions to not only meet FSCA compliance requirements but also improve institutions’ overall cybersecurity resilience against evolving threats.
According to Troye CEO Helen Kruger, the Joint Standard details several essential cybersecurity requirements that institutions must meet. “A foundational requirement is for organisations to develop a comprehensive cybersecurity strategy tailored to their specific risk profile, size, and complexity.”
“This strategy must undergo regular review and updates to ensure continued effectiveness, and robust governance structures with clearly defined roles must be established, making management responsible for collaborating with other stakeholders to ensure cyber resilience.” she explains.
In addition to the strategy and operational aspect of cyber security, financial institutions will be required to implement stringent identity and access management protocols, application and system security policies, network security measures, security awareness training programs, incident response capabilities and more.
Regular testing of cyber resilience is another critical mandate, with institutions required to conduct ongoing vulnerability assessments, penetration testing, and cyber incident simulations to assess their readiness against potential threats. Significant cybersecurity incidents must be promptly reported to relevant authorities, ensuring transparency and enabling swift regulatory responses.
With the deadline approaching, Kruger cautions that institutions must act decisively to achieve compliance and avoid serious regulatory consequences.
Troye’s partnership with Arctic Wolf offers financial institutions and partners that may also need to comply, a seamless path to meet the FSCA’s rigorous standards. Leveraging Arctic Wolf’s cutting-edge cybersecurity operations and Troye’s local expertise on cyber security solutions and red teaming exercises, institutions can transition smoothly into compliance while enhancing their cyber resilience.
Cyber Resilience Assessment (CRA)
Arctic Wolf provides all customers with a comprehensive CRA, which enables financial institutions to assess their cybersecurity readiness against industry standards such as NIST and CIS, identifying gaps to ensure regulatory compliance.
Managed Detection and Response (MDR)
Troye offers 24/7 MDR services that monitor network, endpoint, and cloud environments in real-time. This proactive threat detection and response capability helps financial institutions mitigate potential cyber threats before they escalate, ultimately covering a large portion of the FSCA requirements from protection to detection, to response and recovery.
Continuous Vulnerability Management
Troye also provides continuous vulnerability management, which identifies and addresses security gaps before they can be exploited. “Our services cover identity infrastructure monitoring and data loss prevention, aligning with FSCA requirements for robust access management and asset protection,” Kruger adds.
Arctic Wolf’s Incident Response services provide quick action in the event of a cyber incident, minimising disruption and damage. Customers collaborate with Arctic Wolf’s Concierge Security Team to develop pre-incident plans, ensuring that institutions are well-prepared for any cyber event.
“With Arctic Wolf’s Security Journey, Troye provides continuous compliance support to help institutions maintain alignment with the FSCA’s Joint Standard,” Kruger concludes. “This ongoing partnership ensures that businesses not only meet regulatory requirements but also stay ahead of emerging cyber threats through regular updates and best practices.”
As the FSCA’s Joint Standard on Cybersecurity and Cyber Resilience comes into force in 2025, financial institutions must prioritise compliance.