Attacks on critical infrastructure: South Africa
South Africa's power, water and transport systems are already under strain, which makes their deliberate disruption a particularly acute threat: an economy dependent on a stretched national grid and on ageing water and rail infrastructure has little margin to absorb a coordinated attack. The systems that keep mines, ports and cities running are exposed from the network, the ground and increasingly the air.
Little margin in a stretched national system
Power generation, bulk water supply and the freight rail that moves the country's minerals are interdependent and heavily loaded, so an adversary who can darken a substation, contaminate a supply or halt a corridor imposes national consequence quickly. Infrastructure hardening reduces the attack surface of the supervisory control systems that run these utilities, so an intruder cannot force a shutdown or defeat a safety interlock. Many of those control networks predate the current threat and were never designed to be attacked.
Where sabotage, theft and cyber intrusion converge
A distinctive South African dimension is that physical sabotage (cable theft, vandalism of pylons and pumping stations) already degrades these systems daily, so a deliberate attack hides easily inside a high background of criminal damage. Defensive cybersecurity provides continuous monitoring and incident response around the control networks, while Counter-UAS addresses the drone threat to physical plant such as substations and reservoirs. All three come from independent, non-aligned makers, so the protection of essential services is accountable to the national operator with no foreign disclosure over the vulnerabilities the country depends on.
How engagement works in South Africa
Unstrat engages South Africa as an independent, non-aligned prime vendor: one accountable team, end-use certified, sustained in-region rather than a distribution arrangement. A programme typically begins with an assessment of the highest-consequence sites, hardens their control systems and defends the surrounding networks, then broadens into a resilient posture the operators run themselves. The non-aligned position matters because the defence of a country's essential services should answer to national institutions alone.
Protecting continuity where the margin is thinnest
Work against a deliberate attack on essential services begins with a briefing that identifies the highest-consequence power, water and freight-rail sites, since a stretched national system has little slack to absorb a coordinated strike. Export-control and end-use confirmation precedes any representation, so the hardening and cyber-defence layers answer to the national operator alone. Capability is matched to real conditions: control networks that predate the current threat, and a high background of cable theft and vandalism inside which a deliberate attack can hide. From there a programme hardens control systems, wraps continuous monitoring around them and adds counter-drone cover for exposed plant, sustained in-region so operators run it themselves. Localisation arrangements are scoped per programme, subject to export controls and end-use approvals. The advantage protected is continuity, and the mission is a resilient posture no external supplier can see into.
Relevant capability

Critical infrastructure resilience
Capability page →
Monitoring and incident response
Capability page →
Layered defence against the drone threat
Capability page →Adjacent priorities in South Africa
South Africa runs a large, interconnected set of government systems (civil registry, revenue and payment platforms, provincial and municipal networks) that carry the machinery of a complex state and are under continuous probing from criminal and state-linked actors. A successful intrusion can corrupt a national record, expose citizens' data or paralyse a department at a critical moment.
Problem pageCheap unmanned aircraft now threaten airports, energy sites, borders and public events in every region. Layered counter-UAS, combining detection radar tuned to small slow targets, passive sensing and defeat systems, is the affordable answer recent conflicts demand.
Problem pageTapping, bunkering and sabotage of oil infrastructure drain national revenue and cause environmental damage. Persistent overhead surveillance detects illegal connections and vessel movements, while control-system hardening protects the pipeline network itself.
Problem pageRelevant solutions
Power, water, transport and port systems assessed, hardened and watched continuously, by a team with no foreign government to report the findings to.
Solution page →Layered defence against hostile unmanned aircraft: detection, tracking and defeat priced for the mass threat rather than a missile economy that empties the magazine first.
Solution page →South Africa: security context
South Africa's priorities span sea, infrastructure and networks: maritime domain awareness across busy waters, protection of critical infrastructure, and defence of a financial sector exposed to cyber threats. It is an environment where economic weight raises the stakes of every domain.
One accountable, non-aligned partner gives South Africa a coherent counterpart for that capability: maritime domain awareness, infrastructure protection and financial-sector cyber defence through a single channel, with transparent export-control handling. A security agency gains end-use certified equipment and localisation arrangements scoped per programme rather than promised in advance.
About this challenge
Power grids, water systems and transport networks face both physical and cyber attack. Hardening the control systems behind them, defending the networks around them and countering the drone threat above them keeps essential services running under pressure.
Frequently asked questions
How does infrastructure protection fit South Africa's grid and water pressures?
An already-stretched grid and ageing water systems have little margin to absorb a deliberate attack, so hardening the control layer and defending the surrounding networks protects continuity where it is thinnest. Counter-drone cover adds protection for exposed physical plant. We would be glad to brief your team on prioritising the highest-consequence sites first.
Can this distinguish a deliberate attack from everyday cable theft and vandalism?
That is exactly why continuous monitoring matters. Defensive cybersecurity watches the control networks around the clock, so an intrusion is caught and contained rather than lost in the background of routine criminal damage, separating a coordinated attack from ordinary sabotage.
Who controls the security of these systems once deployed?
The national operator does. Because the hardening, cyber defence and counter-UAS layers come from independent, non-aligned makers, the protection, and knowledge of the vulnerabilities, stays accountable to South African institutions rather than a foreign supplier.
