South African financial institutions have entered a new phase of technology supervision. Over the past two years, the FSCA and Prudential Authority have moved from broad expectations to formal requirements around IT governance, cyber resilience, cloud computing, and data offshoring.
Joint Standard 1 of 2023 on IT Governance and Risk Management came into effect on 15 November 2024, followed by Joint Standard 2 of 2024 on Cybersecurity and Cyber Resilience Requirements, which came into effect on 1 June 2025. Joint Communication 2 of 2025 has brought cloud computing and data offshoring into sharper regulatory focus.
For banks, insurers, retirement funds, asset managers, payment firms, and other financial services providers, this changes the nature of technology oversight. Resilience is now part of regulatory accountability. Firms need to show that critical services can remain available, data can be protected, and recovery can happen quickly when technology fails, a supplier is disrupted, or a cyber incident occurs.
South Africa is part of a wider regulatory shift. Europe’s Digital Operational Resilience Act (DORA), the UK’s incident reporting reforms, and global regulatory efforts on third-party technology risk are all pointing in the same direction. Financial institutions are being asked to demonstrate resilience across the full operating environment, including the technology providers and cloud platforms that support critical services.
That global context is important for local institutions because many operate across borders, rely on multinational providers, or benchmark their risk practices against global standards. Treating each framework as a separate compliance exercise risks repeatedly solving the same problem.
The risk of depending on too few platforms
For financial institutions, concentration risk now extends to whether they can continue operating if a platform, region, network, supplier, or internal environment becomes unavailable, and whether workloads and data can move when costs, regulations, service availability, or risk appetite change.
Most institutions already have governance frameworks, supplier agreements, and recovery procedures in place. The challenge is whether those measures hold up when they’re needed. Moving a workload, restoring a critical service, or shifting data between environments sounds straightforward on paper. In practice, it depends on how the infrastructure was designed. Institutions that build portability, consistency, and operational flexibility into their environments are generally in a stronger position when business conditions, regulatory requirements, or technology risks change.
Recovery must be proven
Regulators increasingly expect institutions to show that they can detect, contain, respond to, and recover from disruption. Joint Standard 2 of 2024 requires effective cyber resilience capabilities, including monitoring, incident response, and periodic evaluation through testing and audits.
Many institutions still operate environments in which meaningful testing is difficult. Validating failover, restoring applications, testing backups, and simulating incidents can create operational risk when the infrastructure was not designed for that discipline.
This is where infrastructure decisions start to matter. Recovery cannot be treated as an annual exercise that only surfaces during an audit. It needs to be part of day-to-day operations. Institutions that can automate recovery processes, test regularly without major disruption, and maintain clear separation between production systems and recovery environments are often better prepared when an incident occurs. Just as importantly, they are able to demonstrate those capabilities when regulators ask for evidence.
Visibility is often the weak point
Incident reporting and cyber resilience requirements are difficult to meet when operational visibility is fragmented. Many financial institutions have strong visibility inside specific systems, but a weaker view across the full estate.
During a cyber incident or technology failure, leadership needs to know which services are affected, which customers may be impacted, where critical data sits, and which recovery path is available. Security, operations, and risk teams need containment options, reliable recovery processes, and evidence for governance and reporting obligations.
The line between cybersecurity and operational resilience has become increasingly blurred. Protecting systems from attack remains essential, but institutions are also expected to show how they will continue operating if preventative controls fail. That has shifted attention towards capabilities such as network segmentation, stronger identity controls, protected backup environments, and faster recovery processes. These are no longer viewed solely as security measures. They are becoming part of the broader resilience strategy that regulators and boards expect to see.
Evidence becomes the real test
Regulators want proof that technology risk is governed, third-party dependencies are understood, data is protected, and critical services can continue under pressure. Infrastructure decisions made now will shape how easily institutions can produce that evidence and whether future requirements become manageable adjustments or expensive remediation projects.
At Nutanix, we see this increasingly through the lens of hybrid multicloud operations. South African financial institutions will continue to run workloads across private infrastructure, public cloud, edge environments, and third-party platforms because different systems have different operational and regulatory requirements. The priority is to manage that mix without losing visibility, portability, or recoverability.
A platform approach can simplify operations across environments, strengthen governance, and provide institutions with more consistent ways to protect data, test recovery, and move workloads as circumstances change. No infrastructure platform can replace governance, processes, and accountability, but resilient infrastructure provides financial institutions with a stronger foundation for demonstrating control.
Financial institutions that treat resilience as an architectural discipline will be better positioned to meet that test. The evidence regulators increasingly expect will come from systems that can be tested, moved, isolated, recovered and governed across the environments where real work happens.




