Marsh Africa: South Africa AI Cyber Risk Surges, Employees Outpace Orgs
Legal News

Marsh Africa: South Africa AI Cyber Risk Surges, Employees Outpace Orgs

South Africa·Briefly Analysis⏱️ 6 min read

Summary

  • Marsh Africa reports a significant increase in short-term AI and cybersecurity risks in South Africa, with employees adopting AI faster than organizations can respond.
  • AI-enabled phishing attacks are becoming more sophisticated, while ransomware remains the largest cyber insurance claim, with a median demand of R6.9 million and recovery costs exceeding R17 million.
  • Southern Africa is the most targeted region on the continent, accounting for 92% of ransomware detections and 70% of business email compromise detections in Africa, according to the Interpol African Cyberthreat Assessment Report 2026.
  • Attackers are leveraging AI more rapidly than organizations can adapt, leading to highly personalized phishing schemes that bypass traditional detection methods.
  • The growing reliance on AI in the workplace without adequate security frameworks necessitates urgent reassessment of cyber resilience strategies by legal and compliance professionals.

Escalating Cyber Threats in South Africa

This disparity creates significant challenges for legal and compliance professionals, who must navigate the complexities of ensuring data protection and regulatory adherence in an environment where AI-driven threats are constantly evolving and traditional defenses are becoming obsolete.

A recent analysis by Marsh Africa reveals a significant surge in short-term risks associated with artificial intelligence (AI) and cybersecurity, particularly within South Africa. This assessment, presented by Marsh Africa, a division of Marsh Group and sister company to global management consultancy Oliver Wyman, highlights a critical disparity: South African employees are integrating AI into their work routines at a pace that far outstrips their organizations' ability to adapt and respond to the associated challenges. The findings stem from the Oliver Wyman Forum’s extensive 300,000 Voices study, a five-year global research initiative spanning 20 countries, complemented by a global consumer survey covering South Africa from 2023 to 2026, which collectively examined AI's influence across various sectors including finance, health, and technology.

Ben Wilmot-Sitwell, the cyber growth leader at Marsh South Africa, noted a direct correlation between the expanding cyber threat landscape and investments in insurance, which in turn impacts cyber claims. While the precise number of claims was not disclosed, Marsh Africa confirmed their substantial volume. Wilmot-Sitwell emphasized the paramount importance of resilience, preparedness, and strategic risk management in an increasingly globalized and interconnected world. He further indicated a notable shift in top concerns, with AI now surpassing climate change as the primary worry, predicting a sharp increase in short-term cyber risks over the next one to two years.

Spiros Fatouros, CEO of Marsh McLennan Africa, echoed these concerns, observing that business leaders are increasingly apprehensive about the potential ramifications of AI-related risks. He also pointed out a growing anxiety among C-suite executives regarding their clients' capacity to effectively detect, respond to, manage, and contain cyber incidents. This underscores a broader challenge for South African legal and compliance professionals, who must urgently reassess and strengthen their clients' cyber resilience strategies to mitigate escalating legal liabilities and regulatory non-compliance risks.

The Sophistication of AI-Driven Attacks

Among the most pressing South Africa AI cybersecurity threats identified by Marsh Africa executives is the evolution of phishing campaigns, which have become significantly more sophisticated due to the widespread adoption of generative and agentic AI. These advanced AI-enabled phishing attacks ZA pose a heightened risk, making traditional detection methods less effective. However, ransomware continues to represent the largest category of cyber insurance claims within the market, signaling a persistent and costly challenge for businesses.

According to the Sophos State of Ransomware in South Africa 2026 report, a concerning 58% of organizations that experienced ransomware attacks paid the ransom to recover their data, a decrease from 71% in 2025. The median ransom demand stood at R6.9 million, while the average cost of recovering from such an attack, excluding the ransom payment itself, exceeded R17 million, down from R21 million in 2025. Marsh Africa anticipates that future ransomware attacks will become even more targeted, aiming to access critical business assets, often referred to as 'crown jewels,' and crypto systems to demand even larger ransoms.

Wilmot-Sitwell described ransomware as a massive industry, noting the prevalence of 'ransomware as a service' models. He characterized it as a multi-billion-dollar enterprise frequently operated by well-funded nation-state attackers. This complex and financially driven ecosystem of cybercrime necessitates a robust and proactive approach to cybersecurity, particularly for legal and compliance teams advising on risk mitigation and financial loss prevention.

Regional Vulnerabilities and Eroding Defenses

The regional impact of these advanced threats is particularly stark, as highlighted by Riaz Moola, founder and CEO of HyperionDev. Citing Interpol’s African Cyberthreat Assessment Report 2026, Moola revealed that AI was implicated in over half of the cybercrime cases recorded across Africa in 2025. Southern Africa emerged as the continent's most targeted region, accounting for a staggering 92% of Africa's ransomware detections and 70% of its business e-mail compromise detections. This data underscores the critical vulnerability of the region to sophisticated cyberattacks.

Moola further explained that attackers have adopted AI at a faster rate than most organizations have developed the capacity to recognize AI-driven threats. He pointed out that traditional phishing emails, once identifiable by poor spelling or generic greetings, can now be crafted by AI to include highly personalized details, such as a manager's name or specific expected invoices. This evolution means that many of the warning signs staff were previously trained to identify are rapidly disappearing, leaving non-technical teams in finance, HR, and customer service increasingly exposed.

Marsh Africa executives also noted AI’s profound impact on the workplace, observing that its adoption among South Africans continues to outpace organizational alignment. The 300,000 Voices study indicated that daily AI use at work increased from 22% in 2023, signaling a growing reliance on AI tools without commensurate security frameworks. This disparity creates significant challenges for legal and compliance professionals, who must navigate the complexities of ensuring data protection and regulatory adherence in an environment where AI-driven threats are constantly evolving and traditional defenses are becoming obsolete.

Practical Implications

This report signals a critical need for South African legal and compliance professionals to urgently reassess and strengthen their clients' cyber resilience strategies, particularly concerning AI-driven phishing and ransomware, to mitigate escalating legal liabilities, regulatory non-compliance risks, and significant financial losses from increasingly sophisticated attacks.

Source

Source: Original reporting via Marsh Africa and Oliver Wyman research

Get Deeper AI analysis

How does this affect you?

Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.

Finish Reading the Full Story and the Expert Analysis.

Get the latest legal & regulatory intelligence in South Africa

Instant access to full analysis, cited statutes & expert commentary
Customize your dashboard to track what matters to your business operations

Already have an account? Log in

Wansom is AI and can make mistakes.

Marsh Africa: South Africa AI Cyber Risk Surges, Employees Outpace Orgs | Briefly