
← Priviso Live6 sep · 16 min
Episode 98: Joint Communication 5 of 2026
⏱️ The twenty four hour clock has started. Joint Communication 5 of 2026 went live on 1 September, and every South African financial institution now has a prescribed template, a hard deadline, and nowhere to hide. We walk through all five tabs, and the three concessions the regulators refused to make.📈 Eight thousand data breaches, and counting. The Information Regulator has confirmed more than 8 000 security compromise notifications to date, with 1 220 since April alone, and it expects to pass 3 000 this financial year. We look at the fines actually issued, the ones the courts set aside, and why the headline number tells us far less than it should.🤖 Ransomware crews have found a use for artificial intelligence, and it is not what anyone expected. They are still getting in through hardcoded credentials and unpatched applications. What has changed is what happens next, when an AI agent reads your stolen data back to you and prices the ransom accordingly.⚖️ And the question we close on. If you have spent eighteen months teaching an AI agent how you do your job, what exactly have you handed over? South African law is clearer than most executives expect, and it belongs on the board agenda as a King V matter.Every one of these stories carries a governance lesson for ISO/IEC 27001, ISO/IEC 42001 and POPIA practitioners, whether you are rewriting an incident response plan, sitting on a board, or being asked to train your own replacement.🎧 Watch or listen to the full episode now, wherever you get your podcasts.💬 Could your team complete a regulator's incident template within twenty four hours, on a Sunday? Let us know in the comments.