South Africa finished the 2024/25 financial year with a rare glimmer of progress: several violent-crime categories fell year-on-year in the most recent quarter. For risk leaders, the temptation is to relax. The data, read carefully, rewards a more disciplined response — because the headline rarely describes the threat your particular organisation faces.
Aggregate statistics are a starting point, not a conclusion. They tell you something about the national mood and almost nothing about your exposure. The work of a risk function is to translate the national picture into an organisation-specific one, and the gap between the two is where most surprises live.
Aggregate down, specific threats up
Headline declines mask shifts beneath the surface. Even where street crime eases, cyber-enabled fraud, extortion targeting businesses, and offences against critical infrastructure continue to rise. The enterprise threat profile is moving online and upstream — away from the kinds of crime that dominate the public conversation and towards the kinds that quietly drain balance sheets and disrupt operations.
This divergence matters because boards calibrate to headlines. A reported fall in violent crime can lull an organisation into reducing exactly the controls — fraud monitoring, third-party assurance, infrastructure protection — that the underlying trend says it should be strengthening.
The threats that are growing
Across the engagements we run, a consistent set of threats is climbing regardless of the national averages. They are not exotic; they are the predictable consequence of an economy digitising faster than its defences.
- Business extortion and protection rackets concentrated in key provinces and sectors
- Cyber-enabled fraud, business email compromise and credential theft
- Critical-infrastructure and supply-chain disruption with operational impact
- Geographic and sectoral concentration that national averages obscure entirely
The average hides your risk
A national figure is an average of wildly different realities. A logistics operator on a contested corridor, a bank with a dense branch footprint, a mine in a remote district and a fintech processing sensitive data do not share a risk profile, and no national statistic describes any of them. The number that matters is the one built from your own sites, sectors, data and dependencies.
A national average is a poor guide to a specific risk. Your exposure is local, sectoral and increasingly digital.
What boards should actually do
The right response is neither optimism nor alarm — it is a current, organisation-specific risk picture, refreshed often enough to drive decisions. That means treating the SAPS statistics as one input among many: useful for trend, useless for precision. It means investing where the underlying threat is moving, even when the headline says otherwise. And it means measuring exposure in terms the board can act on — by site, by sector, by system — rather than by reference to a national mood.
The firms that thrive in this environment are not the ones that read the headline and relaxed, nor the ones that read it and panicked. They are the ones that built their own picture, kept it current, and let it — rather than the news cycle — set the agenda.



