Mapungubwe opened South Africa's trade routes 800 years ago – it can still teach us about securing supply chains

A small gold rhinoceros was buried on a hilltop above the Limpopo River more than 800 years ago. Around it lay glass beads from Persia and shards of porcelain from Chinese kilns, payment for the ivory and gold that the Kingdom of Mapungubwe sent north to the Indian Ocean coast.

24455924 wide

Nobody at Mapungubwe ever saw the ships that carried those goods on to Arabia and beyond, and they didn't need to. A trade route runs on trust between people who never meet, and Mapungubwe understood that centuries before South Africa even existed as an idea.

Modern ports rely on digital networks connecting operational technology (OT), logistics platforms and customs systems to achieve the same goals nearly 800 years later. Those connections drive efficiency but also expand the attack surface of critical national infrastructure. A disruption at a port is more than a cybersecurity incident. It can delay exports, affect manufacturing schedules, disrupt supply chains and create broader economic consequences.

One South African port in Durban alone reportedly handles around six of every ten containers entering the country. The OT and IoT technology used across port infrastructure, facilities and vessels has in a very literal way become as attractive a criminal target as the cargo passing through them.

Fortinet's global 2026 State of Operational Technology and Cybersecurity Report, drawing on insights from more than 700 industrial security professionals worldwide, found phishing and ransomware are still the two most-reported ways attackers get into OT environments, at 76% and 50% respectively. Short attacks are levelling off, while the kind that sits inside a network for weeks or months before doing damage is what's rising – a much harder problem for infrastructure that cannot simply be switched off to check.

Equipment is also being refreshed faster than security is maturing to match it, according to the same research findings. Two years ago, one in five global organisations reported industrial control systems younger than five years old. This year it's two in five. Ports and freight operators are modernising cranes, gate systems and terminal software fast, while cybersecurity investment lags behind. Nearly 90% of organisations surveyed now expect new OT-specific regulation within five years, up from two-thirds twelve months ago. Compliance issues have officially become a ‘now’ problem for anyone running a terminal.

Regardless of when new requirements arrive, operators of critical infrastructure are already facing greater scrutiny from boards, regulators and business partners. For ports and logistics providers, cybersecurity is no longer solely an IT issue. It has become a business resilience issue, with direct implications for operational continuity, safety and trade. As expectations increase, accountability is moving higher within organisations. Cybersecurity oversight for operational environments is increasingly becoming a board-level concern rather than a purely technical responsibility.

In 2022, only 16% of organisations gave their chief information security officer (CISO) direct responsibility for OT. This year it's 53%. That's a sensible move, but data shows that change is outpacing the readiness of the programmes being inherited: the share of organisations rating themselves at the highest maturity level fell sharply once newly accountable executives took an honest look at what they had taken on. A CISO who takes on port or rail security risk without first auditing what is running on those networks becomes accountable for problems nobody has found yet.]

The International Maritime Organisation picked its theme for the 2026/27 observance as "From policy to practice: powering maritime excellence". It's built around safety and environmental regulation rather than cybersecurity, but the logic is nonetheless transferable. 

A port authority can adopt every clause the International Ship and Port Facility Security Code recommends and still leave itself exposed if patching schedules slip, if remote access into terminal systems isn't segmented, or if nobody has properly mapped which OT assets sit on which network. Policy only earns the name once the crane keeps running on the day someone tries to stop it.

For mining, agriculture and manufacturing exporters who depend on Durban, Ngqura and the rail corridors feeding them, the impact of a disruption is no longer measured in months or years, but in hours and days. Mapungubwe had years to feel its trade routes drying up. A modern terminal finds out in hours, with losses that show up the same week.

Mapungubwe's success depended on maintaining trusted connections with the wider world. Today's trade networks are built on digital connections as much as physical ones, creating new opportunities but also new risks – protecting the systems underpinning our key trade networks is as important as building them.

 

martin

By Martin Fernandes, Business Development Manager, Operational Technology (Africa) at Fortinet