Axiomatic header graphic asking what the trustees' responsibilities are for reporting IT and cyber incidents

JOINT COMMUNICATION 5 OF 2026 AND JOINT NOTICE 2 OF 2026 - TRUSTEE'S RESPONSIBILITY FOR REPORTING MATERIAL IT AND CYBER INCIDENTS

Effective 1 September 2026, retirement funds are required to report material IT and cyber incidents to the Financial Sector Conduct Authority (FSCA) using the prescribed reporting template submitted through the FSCA Joint Standards Submission Portal.

A Structured Three-Stage Reporting Process

Trustees must ensure that their incident management and governance frameworks can support a three-stage reporting process for material incidents:

Table showing the FSCA's three-stage reporting process for material IT and cyber incidents: immediate notification, subsequent update, and full incident report

A critical point for trustees is that the 24-hour reporting period begins when the incident is classified as material, not when it is first detected. The requirement is measured in actual hours rather than business hours, making rapid decision-making essential.

Funds should therefore have established escalation procedures that enable key stakeholders, including the principal officer, trustees, administrators, IT and cybersecurity service providers, legal advisers, and communications teams, to assess incidents promptly and determine whether they are material.

Material Incidents Extend Beyond Technical Cyber Attacks

he reporting obligation is not limited to technology failures or malicious cyberattacks. A cyber incident may include breaches of security policies, procedures, or acceptable-use requirements, regardless of whether an external attack occurred.
For example, the unauthorised disclosure of member information by an employee could constitute a cyber incident even where no system has been compromised. In such circumstances, the retirement fund must assess whether the incident is material and therefore reportable.

Assessing Materiality

The determination of materiality remains principles-based and must be considered in the context of the fund’s size, complexity, operational environment, and risk profile.

Axiomatic’s advice is that trustees should consider whether the incident has had, or is likely to have, a severe and widespread impact on:

Importantly, trustees should not delay reporting while waiting for complete information. A reasonable assessment should be made based on the facts available at the time, with further information provided as investigations progress.

Trustees Remain Ultimately Accountable

Although many retirement funds rely extensively on administrators and external service providers for operational processing, technology infrastructure, and cybersecurity controls, regulatory accountability remains with the board of trustees.

A service provider’s notification to another regulator does not satisfy the fund’s reporting obligations to the FSCA. Consequently, funds should ensure that their agreements with administrators and other service providers clearly require them to:

Managing Incomplete Information

he FSCA recognises that complete information may not be available immediately following an incident. Where the prescribed template allows an “unknown” response, funds should provide the most accurate information available, submit the initial notification on a best-efforts basis, and supplement or correct the information during later reporting stages.

Trustees should also note that reporting to the FSCA does not eliminate any separate notification obligations that may arise under the Protection of Personal Information Act (POPIA) or other applicable legislation. Each regulatory framework must be considered independently.

Axiomatic's Key Takeaway

The new reporting requirements place significant emphasis on governance, preparedness, and timely decision-making. Retirement funds should review their incident response frameworks, reporting procedures, and service provider agreements to ensure they can identify, assess, and report material IT and cyber incidents within the prescribed timelines. Effective preparation before an incident occurs will be critical to meeting regulatory expectations and protecting members’ interests.

Not Sure Your Fund's Reporting Framework Is Ready?

Talk to Axiomatic about reviewing your incident response plan, governance structures, and service provider agreements before the FSCA comes knocking.

COOKIE POLICY

Welcome to our website.

1. Introduction

This Cookie Policy explains how we use cookies and similar technologies on our website axioconsult.com. This policy is designed to help you understand what cookies are, how we use them, and the choices you have regarding their use.

2. What Are Cookies

Cookies are small text files that are stored on your device (computer, tablet, or mobile phone) when you visit certain websites. They are widely used to enhance your online experience by remembering your preferences and actions over time. Cookies are not harmful and do not contain personal information like your name or payment details.

3. How We Use Cookies

We use cookies for various purposes, including:

    • Essential Cookies: These cookies are necessary for the basic functioning of our website. They enable you to navigate our site, use its features, and access secure areas.
    • Analytical/Performance Cookies: These cookies help us understand how visitors use our website. They provide information about which pages are visited most frequently, how long visitors stay on each page, and whether they encounter any error messages. This data helps us improve the performance and usability of our website.
    • Functionality Cookies: These cookies allow our website to remember choices you make (such as your username, language, or region) and provide enhanced, personalised features.
    • Targeting/Advertising Cookies: These cookies are used to deliver advertisements that are relevant to your interests. They may also limit the number of times you see an ad and help measure the effectiveness of ad campaigns.

 

4. Your Cookie Choices

You have the option to manage your cookie preferences. You can usually modify your browser settings to accept, reject, or delete cookies. Please note that if you choose to block or delete cookies, some features of our website may not function properly.

5. Third-Party Cookies

We may allow third-party service providers to use cookies on our website for the purposes outlined in Section 3. These providers may also collect information about your online activities over time and across different websites.

6. Updates to This Policy

We may update this Cookie Policy from time to time to reflect changes in technology, law, or our data practices. Any changes will become effective when we post the revised policy on our website.

7. Contact Us

If you have any questions about our Cookie Policy or how we use cookies on our website, please contact us at

By continuing to use our website, you consent to the use of cookies as described in this Cookie Policy.