
The festive season is when small businesses are most exposed, because offices run on skeleton staff, approvals get rushed and transaction volumes peak. The two things that matter most are multi-factor authentication on email and a rule that banking details are never changed on the strength of an email alone. If you are breached, POPIA requires you to notify the Information Regulator and the affected people, with no minimum threshold.
December is the quietest month in most offices and the busiest month for the people trying to get into them. That is not a coincidence. Attackers know that the person who normally checks a payment is on leave, that the stand-in has half the context, and that everyone is trying to close things off before the shutdown.
You do not need an enterprise security budget to make yourself a much harder target. Most of what follows costs nothing beyond an afternoon of attention before you close.
Why the festive season is the risk window
Three things change in December and each one helps an attacker.
Your team thins out, so requests get approved by whoever is available rather than whoever normally checks them. Everything is urgent, because clients and suppliers all want things settled before the break. And if you sell to the public, your transaction volume peaks, so an unusual payment is easier to hide in the noise.
The attack does not have to be sophisticated to work in those conditions. It just has to arrive at the right moment.
The scam that actually hits small businesses
Business email compromise is the one to plan for. It usually looks like a supplier emailing to say their banking details have changed, or a message that appears to come from a director asking for an urgent payment while they are travelling.
There is no malware to detect and no obvious warning sign. The email is often sent from a real, compromised mailbox, or from a domain that differs by a single character.
The control that stops it is procedural rather than technical. Banking details are never changed on the strength of an email. Confirm any change by phoning the supplier on the number you already have on file, never a number in the email itself, and have a second person authorise payments above a set amount. Write that rule down and tell your stand-in staff it applies even when the request is urgent, because urgency is the whole technique.
What POPIA requires if you are breached
This is the part most small businesses get wrong, and it carries legal weight.
Section 22 of the Protection of Personal Information Act says that where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, you must notify both the Information Regulator and the affected data subjects.
Two details matter. There is no minimum threshold, so a compromise is reportable whatever you judge the risk to be, and a small business is not exempt. And unlike the European rules, POPIA sets no fixed 72 hour clock. The standard is as soon as reasonably possible after discovery, allowing only for what is genuinely needed to establish the scope and secure your systems.
The notice to affected people must be in writing and must say enough for them to protect themselves, which means describing the possible consequences and what you are doing about it. It can be delivered by post, by email, or by a prominent notice on your website.
Decide now who makes that call and where the Regulator’s contact details are kept, because the middle of an incident is a bad time to research it. Our POPIA compliance guide covers the wider obligations.
Lock down accounts before you close
Turn on multi-factor authentication everywhere it is offered, starting with email. Email is the master key, because it resets the password on everything else. If you do one thing on this list, do this one.
Use a password manager so that people are not reusing the same password across your accounting package, your online banking and their personal accounts. Reused passwords are how a breach somewhere else becomes a breach at your business.
Then remove access nobody should still have. Former employees, an old bookkeeper, a developer who built the site three years ago, a shared login for a tool you stopped using. Check who has administrator rights on your email, your website and your accounting system, and cut it back to the people who genuinely need it.
Payments and card data
If you take card payments, use a reputable payment provider and let them handle the card data. You should never be storing full card numbers yourself, and there is no business reason for a small operator to do so.
Check that your website has a valid certificate and that your payment pages load over HTTPS. If you use a gateway, review which staff can issue refunds, because refund fraud rises over the festive period. Our review of the top payment gateways in South Africa compares the local options.
Backups you have actually tested
A backup you have never restored is a hope, not a backup.
Keep at least one copy off site or in a separate cloud account, and make sure it is not reachable from the same login as your live system, because ransomware follows the permissions it finds. Before you close for December, restore one file from your backup and confirm it opens. That single test is what separates a bad week from a closed business.
Brief your team on the specific scams
General awareness training does very little. Naming the actual scams does a lot.
Tell your staff, and particularly anyone covering for someone on leave, exactly what to expect: a supplier changing banking details, a director asking for an urgent payment or gift card purchase, a fake delivery or courier notice, and a fake invoice for a service you do use. Give them explicit permission to slow down and check, and make clear that nobody will be in trouble for delaying a payment to verify it.
A short checklist before you close
Work through this before the shutdown rather than in January.
Multi-factor authentication on email and banking. Administrator access reviewed and old accounts removed. Software and devices updated. One backup restored and confirmed working. Payment authorisation rule agreed in writing and shared with stand-in staff. Contact numbers for your bank, your IT support and your key suppliers saved somewhere reachable when the office is closed.
Frequently asked questions
Do I have to report a data breach in South Africa?
Yes. Section 22 of POPIA requires you to notify the Information Regulator and the affected people where there are reasonable grounds to believe personal information was accessed or acquired without authorisation. There is no size exemption and no minimum threshold.
How quickly must I report it?
As soon as reasonably possible after you discover it. POPIA does not set a fixed 72 hour deadline, but the allowance for delay is limited to establishing the scope of the compromise and securing your systems.
What is the single most useful thing to do?
Turn on multi-factor authentication for email. Email resets the password on almost everything else, so protecting it protects the rest.
How do I avoid paying a fake invoice?
Never change banking details on the strength of an email. Confirm by phone using a number you already hold, and require a second person to approve payments over an agreed amount.
Is antivirus software enough?
No. The attacks that most often cost small businesses money involve no malware at all. They rely on a convincing email and a rushed approval, so your process matters more than your software.
Further reading
Originally published in December 2023. Updated September 2026 with current breach notification requirements under POPIA. Obligations can change, so confirm the current position with the Information Regulator if you are dealing with an incident.
