South Africa can lead Africa in governing wireless as critical infrastructure, but first we need to face up to harsh facts: 83% is the staggering number of SA organisations that have experienced a wireless security incident in the past year alone.

This is the view of Charmaine Houvet, senior director of Government Strategy and Policy at Cisco Africa, who says that for the last two decades, wireless was treated as a convenience layer in South African organisations and today, wireless networks carry the workloads, devices, and applications on which the most consequential systems in our economy depend.

The technology has shifted faster than most governance conversations anticipated, and we now have the opportunity to bring the two back into alignment.

However, she says, this is a shared catch-up. Regulators are working with frameworks designed for an earlier generation of infrastructure – and boards in the private sector have been slow to bring wireless on to their agendas alongside cyber and data.

The 2022 TransUnion breach, which exposed the data of millions of South Africans, made clear that the digital layer underneath our financial and consumer systems is already a national exposure point. The World Economic Forum’s 2025 Global Cybersecurity Outlook describes a widening cyber inequity globally, with infrastructure and adversaries scaling faster than defences. South Africa is not exempt, and the wireless layer is where much of that exposure now lives.

“The staggering number of 83% of local organisations that have experienced a wireless security incident in the past 12 months was derived from our recent survey of 105 South African organisations,” Houvet says. “Interestingly, 46% of those affected faced regulatory penalties or compliance consequences as a direct result, and 34% experienced loss of customer trust. Wireless is no longer just an IT risk. It is already producing regulatory and reputational exposure on the ground here – and the case for naming it explicitly as critical infrastructure is becoming difficult to ignore.”

Alongside this, Houvet adds, the report identifies what it calls the “Wireless AI Paradox”: the layer driving competitive advantage through AI is the layer through which AI-generated attacks are scaling faster than defences can adapt.

“To me, this is the central governance challenge of the next five years,” says Houvet. “The systems we are building the future on are being deployed faster than the rules meant to govern them, and 79% of South African organisations believe they are doing enough to protect their wireless networks while 78% simultaneously expect security failures to increase over the next two years. Both cannot be true. One of them describes a governance gap, and it is one the private sector owns as much as anyone else.”

Looking back, she adds, the technical foundation has matured over time. Wired, wireless, and security are converging into integrated platforms – a shift recognised in recent analyst assessments including Gartner’s 2026 Magic Quadrant for Enterprise Wired and Wireless Infrastructure. The governance scaffolding that should sit alongside it is where attention now needs to shift.

South Africa already governs the systems we treat as critical. POPIA covers personal information. The Prudential Authority shapes operational resilience in financial services. The Critical Infrastructure Protection Act of 2019 designates physical critical infrastructure, but it does not yet explicitly extend to the wireless networks now carrying most of what those physical assets depend on. A bank’s branch network, a hospital’s connected clinical devices, a retailer’s point-of-sale systems, and a manufacturer’s production-line sensors all sit on wireless. When that layer is compromised, the consequences flow directly into operational resilience, customer trust, and regulatory exposure.

South Africa has done this kind of work before, Houvet says. POPIA did not only protect South African citizens, but became the template that Mauritius, Kenya, Nigeria and others drew from when writing their own data protection laws. The same continental ripple is available on wireless governance, but the window is narrow. The European Union’s Digital Operational Resilience Act came into force in January 2025, and the NIS2 Directive, which explicitly covers digital infrastructure including wireless networks, is now in effect across the EU.

These standards will become the default that African markets adopt by inertia unless someone on the continent moves first. South Africa is the natural candidate.

The practical starting points are not new legislation. They are extending these existing frameworks to explicitly include wireless, asking regulated sectors to apply the same standards of visibility and incident reporting on wireless that they already apply elsewhere, and treating wireless as part of the same board-level risk conversation as cyber and data.

The African Union’s Continental AI Strategy, adopted in 2024, calls for infrastructure readiness, but does not yet specify the wireless layer that AI applications, agents, and connected systems depend on. South African leadership on naming and governing that layer would feed directly into a continental agenda that is already being written, Houvet says.

South Africa has the chance to lead Africa in setting this standard.

“Doing so would protect the systems we already depend on, give boards the clarity they need to invest with confidence, and prepare the ground for the next wave of AI and connected infrastructure to be built on properly governed terrain,” Houvet says.