IT & Cyber Audit
Cyber Incident Trend
The shape of an entity's incident history reveals whether its cyber defences and response capability are improving or falling behind the threat.
Why Tracking Incidents Matters
Public bodies hold sensitive personal and financial data and are squarely within scope of POPIA's security-safeguard condition and the AGSA's growing focus on cyber risk. Tracking incident volume, severity and resolution time over time turns reactive firefighting into a governable risk picture for the audit committee and information officer. AuditPro Core trends cyber incidents so deteriorating response times or rising severity are evident before they become a breach with reporting obligations.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Incidents (12m)
147
▲ 11% YoY
Critical incidents
8
Mean time to resolve
9.4 hrs
▼ 2.1 hrs
Phishing share
44%
Incidents by month
Incidents by category
| Category | Count | Critical | MTTR (hrs) |
|---|---|---|---|
| Phishing | 65 | 2 | 6 |
| Malware | 31 | 3 | 14 |
| Unauthorised access | 22 | 2 | 11 |
| Data loss | 14 | 1 | 18 |
| DoS | 15 | 0 | 5 |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Volume, severity and time
Three dimensions matter together: how many incidents occur, how serious they are, and how long they take to resolve. A drop in volume means little if the few remaining incidents are severe and slow to close.
Mean time to resolve
Resolution time is a direct measure of response capability and limits the window of harm. Lengthening resolution times are an early indicator that the security function is under-resourced.
POPIA breach threshold
Some incidents cross into reportable security compromises that trigger POPIA notification duties to the Regulator and data subjects. Distinguishing these from routine incidents is essential for compliance.
How AuditPro Core Bridges the Gap
- Continuous monitoring: incidents are trended by volume, severity and resolution time across the period.
- Exception workflow: incidents crossing the POPIA reportable threshold escalate for notification handling.
- Traceability to source: each incident links to its log, classification and resolution record.
- Audit-ready export: the incident history exports for the security-safeguards and cyber-risk assessment.
Key Takeaways
- Read volume, severity and resolution time together, not in isolation.
- Rising resolution times often signal an under-resourced security function.
- Flag reportable security compromises early to meet POPIA notification duties.
- An incident trend is governance evidence, not just an operational log.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
