Skip to content
Under attack?Get emergency help now
All articles
1 September 2026F1 IT Solutions

F1 IT Solutions partners with Panorays to bring world-leading third-party cyber risk management to South Africa

Third-Party RiskPanoraysCybersecuritySupply Chain SecurityMSSP
F1 IT Solutions and Panorays official partnership announcement

Your security is only as strong as your weakest supplier. From today, we can measure exactly how strong that is, for every vendor you work with, every day.

F1 IT Solutions has signed a partnership agreement with Panorays, a global provider of third-party cybersecurity management software. We deliver the platform as an approved Panorays MSSP partner across South Africa, the United Kingdom and Europe, and we run it for clients as a fully managed service.

This is a big moment for us, and a bigger one for our clients. Here is why.

The regulator moved first

South African companies are now accountable in law for the security of their suppliers.

Joint Standard 2 of 2024, issued by the Prudential Authority and the FSCA, has been in force since 1 June 2025. It applies to banks, insurers, retirement funds and their administrators, collective investment scheme managers and many financial services providers. It makes governing bodies ultimately responsible for cyber resilience, requires third parties that manage your assets to protect them to the same standard you would, and requires material cyber incidents to be reported to the authorities, with the regulators' draft reporting framework asking for a first notification within 24 hours. The FSCA has already started onsite visits and desktop audits.

The Prudential Authority's 2025/26 Annual Report shows where supervision is heading: the PA says it "continues to engage the sector on cyber resilience maturity and preparedness for emerging risks", and it has issued new guidance on cloud computing and data offshoring. Its appetite for enforcement is not theoretical either: the latest report records R115 million in administrative penalties against banks and insurers that fell short on required controls.

POPIA applies to everyone else. The Information Regulator can fine companies up to R10 million, and ignoring its enforcement notices is a criminal offence carrying up to 10 years imprisonment. It has fined the Department of Justice R5 million, and it issued enforcement notices to Dis-Chem and TransUnion after breaches that began with third-party access. Security compromise reports are running at roughly 284 per month this year, up 40% on last year. We set out how to manage the vendors you already work with earlier this year.

The message from both regulators is the same. You cannot outsource a function and outsource the responsibility with it.

The numbers behind the pressure

The risk is not theoretical. IBM's Cost of a Data Breach research put the average South African breach at R44.1 million in 2025, and found that third-party vendor and supply chain compromise was the most common way in, at 17% of local incidents, ahead of phishing and stolen credentials. IBM's 2026 update shows South African breach costs climbing another 22%, the largest increase of any country in the study.

Globally, Verizon's 2026 Data Breach Investigations Report puts third-party involvement at 48% of breaches, up from 30% the year before, an increase Verizon itself calls 60%, after the figure had already doubled the previous year.

Nearly half of breaches now start in someone else's network. Almost no company inspects that network more than once a year, if at all.

What Panorays does

Panorays solves this with continuous, evidence-based monitoring of your entire supplier ecosystem:

  • Every vendor gets a continuously updated cyber posture rating that reflects the real risk they pose to your business, not a generic industry score.
  • Panorays maps and tests each supplier's internet-facing assets from the outside, the way an attacker would, with nothing to install.
  • AI-powered security questionnaires complete in days instead of weeks, validated against what the technology actually shows.
  • Continuous monitoring alerts you the moment a supplier's posture drops or a breach touches your supply chain, not at next year's review.

The platform is trusted by organisations like TSMC, Puma and Markerstudy Group, and it is certified to ISO 27001, SOC 2 Type II and ISO/IEC 42001, the world's first international standard for AI governance, so the way it applies AI is independently certified rather than self-declared.

What F1 IT Solutions adds

A platform alone does not make you compliant. Someone has to run it, interpret it, chase your vendors to fix what it finds, and stand in front of your board or your regulator with the evidence.

That is what we do. F1 IT Solutions has spent 16 years managing IT and security for businesses in South Africa and abroad. We have sat on both sides of the vendor security questionnaire: we have answered them for banks by hand, and we have assessed suppliers for our clients. We know exactly how painful this process is, because we have lived it. That is why we went looking for the best platform in the world to automate it.

We also hold ourselves to the bar we set for others. F1 has begun its own ISO/IEC 27001 certification programme, targeting the first quarter of 2027, and we run our own vendor base through the same platform we manage for clients. When we ask your suppliers for evidence, we are asking for nothing we do not produce ourselves.

As a Panorays managed security partner, we offer Third-Party Risk Management as a fully managed service: we onboard your vendors, run the assessments, monitor continuously, drive remediation and deliver board-ready and regulator-ready reporting. Your team gets the outcome without the headcount.

"Every week a South African company discovers that its data walked out through a supplier's door. The regulators have made it clear that the excuse era is over. We partnered with Panorays because it is the best in the world at this, and we back it with a local team that takes full ownership. Our clients can now see, score and fix their supply chain risk continuously, and prove it to any board or regulator who asks."

Reza Marvasti, Founder and CEO, F1 IT Solutions

"South Africa's regulators have put third-party cyber risk on every board agenda, and F1 IT Solutions is exactly the partner to help companies act on it. Their hands-on security pedigree and local trust, combined with the Panorays platform, gives businesses in the region a complete answer to supply chain risk."

Matthew Pearson, VP of Channels EMEA, Panorays

See your supply chain the way an attacker does

We will show you the platform live, on real data, and walk you through what a managed third-party risk programme looks like for your business.

Book a demo: email info@f1itsolutions.co.za or visit f1itsolutions.co.za.

You can also read the full joint announcement.


Sources

  1. Joint Standard 2 of 2024: Cybersecurity and Cyber Resilience Requirements (full text)
  2. ITLawCo: Joint Standard 2 of 2024, what financial institutions need to know
  3. Clyde & Co: material incident reporting framework (draft Joint Communication 3 of 2025)
  4. Compli-Serve: FSCA onsite visits and desktop audits under Joint Standard 2
  5. Prudential Authority Annual Report 2025/26, policy and regulatory initiatives chapter
  6. IOL: Prudential Authority imposes R115 million in penalties on banks and insurers
  7. MJ Kotze Inc: POPIA fines and penalties
  8. Michalsons: Information Regulator fines Department of Justice R5 million
  9. Information Regulator media statement: enforcement notice issued to Dis-Chem
  10. BusinessTech: Information Regulator enforcement notice to TransUnion
  11. The Citizen: SA data breaches surge 40% (Information Regulator statistics)
  12. iAfrica: IBM Cost of a Data Breach 2025, South Africa figures
  13. ASIS Security Management: IBM Cost of a Data Breach 2026 findings
  14. Verizon 2026 Data Breach Investigations Report, p.19
  15. Panorays: ISO/IEC 42001 certification announcement

About F1 IT Solutions: F1 IT Solutions is a managed IT and security services provider headquartered in Cape Town, South Africa, serving clients across South Africa, the United Kingdom, Europe and North America for over 16 years. F1 delivers managed IT, cybersecurity and third-party risk management services, partners with world-class technology vendors including Panorays, Sophos, Barracuda, ESET, Acronis, Microsoft and Dell Technologies, and is pursuing ISO/IEC 27001 certification. Learn more at f1itsolutions.co.za.

About Panorays: Panorays is a global provider of third-party cybersecurity management software. Adopted by leading financial, healthcare, and enterprise organizations worldwide, Panorays helps businesses optimize defenses and proactively manage third-party cyber risk. Headquartered in New York and Israel, Panorays is backed by Aleph VC, Oak HC/FT, Greenfield Partners, and StepStone Group. Learn more at panorays.com.

Want this handled for you?

Talk to the F1 team about cybersecurity, AI and managed IT for your business.