According to IT-Online, South Africa's critical infrastructure is running on unpatched systems—a condition attackers are aware of and positioned to exploit. This assessment arrives against a concrete precedent: in April 2025, attackers gained remote control of a dam in Western Norway and opened a valve for four hours. No fatalities resulted from that incident, but it closed a critical gap in conventional threat assessment. The distance between a successful cyberattack on operational technology (OT) systems and measurable physical and economic consequences is no longer a scenario—it's demonstrated fact.
Why this matters: Critical infrastructure in most developed economies relies on aging operational technology networks designed before modern cyber threats emerged. Unpatched systems create known, exploitable vulnerabilities. Attackers don't need theoretical access; they need confirmed gaps. When IT-Online reports that South African infrastructure meets that condition, it signals a specific and actionable vulnerability profile.
The Norway dam incident carries weight because it wasn't a simulation, penetration test, or academic proof-of-concept. Attackers achieved remote access, executed commands, and maintained control long enough to demonstrate capability—all without triggering immediate intervention. The fact that no casualties occurred doesn't reduce the significance; it demonstrates that attackers can operate inside critical infrastructure systems with some degree of operational freedom.
For preparedness, this represents a systemic risk indicator. When critical infrastructure operators confirm unpatched systems are in place and threat actors have demonstrated ability to breach similar systems, the gap between exposure and incident narrows. The cascading risk is real: a dam valve, a water treatment control, a substation relay—each represents a potential triggering point for broader service disruption.
What to monitor: Watch for any statements from South African infrastructure operators acknowledging patching timelines or remediation schedules. Timeline pressure and resource constraints often delay mitigation. The longer the unpatched window remains open, the higher the probability of exploitation.

