Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      South Africa's right-to-repair guidelines target software locks on spare parts

      Right to repair comes to South African electronics

      5 October 2026
      Luno says crypto draft may clash with South Africa's IMF commitments - Marius Reitz

      Luno says crypto draft may clash with SA’s IMF commitments

      5 October 2026
      Let South Africans jailbreak their way to digital sovereignty

      Let South Africans jailbreak their way to digital sovereignty

      5 October 2026
      Ransomware gang threatens to dump more South African client data

      Ransomware gang threatens to dump more South African client data

      5 October 2026
      Banks top AI spending as telcos struggle to show returns

      Banks top AI spending as telcos struggle to show returns

      5 October 2026
    • World
      BMW restructuring plan bets on AI and new models

      BMW restructuring plan bets on AI and new models

      1 October 2026
      OpenAI's rogue agent problem keeps getting bigger - Sam Altman

      OpenAI’s rogue agent problem keeps getting bigger

      28 September 2026
      The new battle over the desktop

      The new battle over the desktop

      23 September 2026
      AMD is now worth a trillion dollars - Lisa Su

      AMD is now worth a trillion dollars

      22 September 2026
      Anthropic weighs new model launch to blunt OpenAI's Astra surge - Anthropic CEO Dario Amodei and OpenAI CEO Sam Altman

      Anthropic weighs new model launch to blunt OpenAI’s Astra surge

      21 September 2026
    • In-depth

      10 days that changed the course of AI

      21 September 2026
      Meta to the AI industry: slow down without us - Mark Zuckerberg

      Meta to the AI industry: slow down without us

      16 September 2026
      Google DeepMind CEO Demis Hassabis. Image: John Sears

      The plan to stop AI from breaking the world

      16 July 2026
      The internet has a Strait of Hormuz problem

      The internet has a Strait of Hormuz problem

      15 July 2026
      AI boom sparks rally, frenzy and fear

      AI boom sparks rally, frenzy and fear

      11 June 2026
    • TCS
      Lexi Novitske, general partner at Norrsken22, on the TechCentral Show

      TCS | Norrsken22’s Lexi Novitske on how China is winning African tech

      1 October 2026
      TCS | Dominic White and Adam Ely on AI agents going rogue

      TCS | Dominic White and Adam Ely on AI agents going rogue

      29 September 2026
      TCS | Octotel's Trevor van Zyl on the fibre merger question

      TCS | Octotel’s Trevor van Zyl on the MetroFibre merger question

      16 September 2026
      Meet the CIO | Shoprite's Chris Shortt on what a supermarket becomes

      Meet the CIO | Shoprite’s Chris Shortt on what a supermarket becomes

      9 September 2026
      Rubicon's EV charging network is profitable - and growing fast - Watts & Wheels

      W&W | Rubicon’s EV charging network is profitable – and growing fast

      8 September 2026
    • Opinion
      South Africa's next energy crisis is in the accounts department - Craig Holmes

      South Africa’s next energy crisis is in the accounts department

      29 September 2026
      The steam engine lesson AI doomsayers keep missing - Sam Clarke

      The steam engine lesson AI doomsayers keep missing

      28 September 2026
      The author, Dirk de Vos

      Regulating AI: apply the laws we have first

      21 September 2026
      What Revolut can and cannot take from South Africa's banks - Pambos Soteriades

      What Revolut can and cannot take from South Africa’s banks

      15 September 2026
      The end is nigh, and the shares go on sale in October - Duncan McLeod

      The end is nigh, and the shares go on sale in October

      14 September 2026
    • Company Hubs
      • 1Stream
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • Ascent Technology
      • AvertITD
      • BBD
      • Braintree
      • CallMiner
      • CambriLearn
      • CM.com
      • Contactable
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • HOSTAFRICA
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • Kaspersky
      • LSD Open
      • Mitel
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Publishared
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Telviva
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Vox
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • HealthTech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Policy and regulation
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
      • Watts & Wheels
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Sections » IT services » The board now owns the database

    The board now owns the database

    Promoted | King V’s Principle 10 has made the board accountable for an estate most boards have never seen. The paragraph in next year’s report will not be the answer.
    By Ascent Technology5 October 2026
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    Get breaking news on WhatsApp

    The board now owns the database - Ascent Technology, Johan Lamberts

    Key takeaways

    • The word is accountable – Principle 10 does not ask the board to receive reports on data. It makes the governing body accountable for how data is acquired, used, disseminated and disposed of.
    • A paragraph is not an answer – Most boards will meet the principle with a delegated committee, an approved policy and a paragraph in the 2027 report. None of those can say where the sensitive data sits, who can reach it or which engines holding it are still supported.
    • The question moves down the table – Directors will not answer Principle 10 themselves. It lands on the CIO, the head of data and whoever runs the databases – asked, for the first time, on the record.
    • Third parties are now the board’s problem – The Code names outsourced services and suppliers “including across jurisdictions”. Every hosting provider, outsourced DBA and reporting tool that touches personal information sits inside that accountability.
    • Evidence has to pre-date the question – Enforcement, the financial sector’s cyber standard and an attacker dwell time of eighteen days all point the same way: assurance is what already exists when someone asks.

    South African boards are entering the first financial year governed by King V – the calendar-year boards are already three-quarters of the way through it. Most met its arrival the way boards meet every new Code – a briefing from the company secretary, a gap analysis from the auditors, a committee charter amended – and the year carried on.

    The data and technology chapter is where the Code changed most; the IoDSA says so itself. And it is being read as a disclosure obligation – a paragraph to be written in 2027 about a year already being lived. It is not that. Principle 10 makes the board accountable for the data estate now, and the people who will write the paragraph cannot answer the question it raises.

    Principle 10

    The wording is worth reading slowly, because it was chosen slowly. Principle 10 says the governing body “governs data, information and technology in a way that enables the organisation to sustain and optimise its strategy and objectives”. The first practice beneath it says the board should “be accountable for the effective, compliant and ethical management and control (including acquisition, creation, use, dissemination and disposal) of data and information”.

    Accountable. Not informed, not briefed, not satisfied that management has it in hand.

    The practices that follow name what the board must see to: sensitive data identified and classified, its confidentiality, integrity and availability secured, its quality maintained and the risks of “outsourced services, suppliers and third parties, including across jurisdictions” managed. Practice 104 adds the part most boards will skip past – periodic assurance on all of it.

    King IV covered technology and information in one principle. King V separates them, treats data as a governed asset in its own right and says in its own background note that this is where the Code “has undergone the most substantial changes”. It is written for any juristic person “regardless of its manner or form of incorporation”, and apply-and-explain now ends with a statement on whether the Code “realised value for the organisation”.

    That last requirement is the trap. It invites narrative, and narrative is what a paragraph is made of.

    The paragraph

    Here is how Principle 10 will be applied in most organisations, because it is how every principle is applied. The board delegates its data and technology responsibilities to the risk committee, which the Code permits. Management drafts a data governance policy, which the committee approves. The policy is referenced in the integrated report, with a sentence on the value realised. Apply, explain, file.

    None of that is wrong. It is simply not an answer. A policy states intent about data; it does not say where the data is. The evidence that the gap is real is not hard to find.

    The Information Regulator logged 788 security-compromise notifications in the first quarter of this year, most of them human error rather than attack. Its first enforcement notice of 2026 went to a college whose acting chief financial officer emailed staff a folder of finance policies that also held employees’ criminal-record and qualification checks.

    The finding: an “absence of file segregation between personal data and finance policies”. A governance failure at the level of a folder, now carrying orders with 31-day clocks on them.

    The international picture matches at scale. In Redgate’s June survey of 2 150 IT professionals, 77 percent of organisations had no formal data governance or quality framework, and 44 percent had invested more than US$100 000 in database AI over the past year. Money is flowing to the top of the estate while nobody holds the map of it.

    A board that has approved a policy has done what the paragraph requires. It has not done what the principle requires.

    On the record

    Directors will not answer Principle 10 themselves. They will ask. The question travels down the table – to the chief information officer, to the head of data, to whoever runs the databases – and for the first time it arrives with the weight of the Code behind it. In practice it is three questions, and a fourth the Code asks in the board’s own name.

    Where does the sensitive data sit? Not the systems list from the asset register – the tables, the columns, the copies in the reporting layer, the extracts on the file share. Practice 103 asks for identification and classification, and classification presupposes a count. Most estates have never had an inventory a director would recognise as complete.

    Who holds standing access to it? Sophos’s 2026 ransomware study, which includes South African organisations, found that 79 percent of attacks began with a compromised identity – and that where the way in was a stolen credential, multi-factor authentication had already been deployed in 97 percent of cases. The control was present; its coverage was not.

    Coverage is only half of the access question. The other half is what a credential can reach once inside – in most estates I see, service accounts with DBA privileges granted for a project and never withdrawn, and rights accumulated over years and never reduced.

    A board accountable for confidentiality is accountable for that list.

    Which of the engines holding it are still supported? SQL Server 2016 left support on 14 July; Windows Server 2016 follows on 12 January; SQL Server 2017 has about a year left. An unsupported engine under personal information is a resilience finding under Practice 108. It is also, on the Regulator’s own reasoning about lapsed security tooling, a position that section 19 of Popia will require the organisation to defend.

    And the fourth: who else touches this data? The outsourced DBA, the hosting provider, the reporting tool with a database connection, the payroll bureau. Practice 103 names third parties “including across jurisdictions”.

    For financial institutions the twelve-month implementation period the regulators allowed for Joint Standard 2 ended in June – 24-hour reporting of material incidents and the management of third-party cyber risk, no longer a runway. Every material supplier to a bank, an insurer or a retirement fund now sits inside that institution’s cyber-risk perimeter, whether or not it has been told.

    This is the layer where, as I argued in April, South Africa’s breaches actually happen. King V has now put a director’s name against it.

    What it buys

    Principle 10 has a second half that will get less attention, and should not. Practice 105 makes the board accountable for the “acquisition, development, use and distribution of technology”, and Practice 108 asks it to see that technology investment returns “commensurate benefits”. The board is accountable for what the organisation buys as well as what it holds.

    For many South African enterprises the largest recurring technology purchase is the Microsoft estate – licences, subscriptions, cloud consumption – renewed on a calendar few directors have seen. A renewal signed on the wrong billing terms, a commitment that can no longer be exchanged, a currency adjustment that lands once a year: none of these is a security incident, and every one is a Principle 10 matter. The cost of the estate is part of the estate.

    Before the incident

    Practice 104 asks the board to “consider periodic assurance” on all of this. Assurance is where the paragraph and the principle finally part company.

    Assurance on data is not a policy attestation. It is an inventory that is current, an access review that has been done and minuted, a support-status register for every engine holding personal information, a recovery test that was actually run and an activity record that would show what happened if something did. It exists before anyone asks. That is the whole point of it.

    The reason it has to exist beforehand is arithmetic. Cyanre’s South African incident data puts attacker dwell time at eighteen days in 2025, down from 117 the year before, with data rather than systems now the target. Eighteen days is shorter than a quarterly reporting cycle. “We would have noticed” was a weak defence when attackers sat in estates for months. It is no defence now.

    By the time the first King V reports are written next year, the year they describe will already have been lived – in the estate, not in the boardroom. Some boards will answer those questions because the answers existed all along. Others will discover, in front of an auditor, an insurer or the Regulator, that a paragraph was all they had.

    The last word

    I sit on a board as well, and I know how easily a principle becomes a paragraph. The papers arrive, the policy is sound, the committee has it covered and the meeting moves on. I also know what the question sounds like from the other side of the table, because for twenty-three years the people who have to answer it have been the ones Ascent works alongside.

    Principle 10 does not change what a database estate is. It changes who is accountable for it. The organisations that will be comfortable in 2027 are the ones where that accountability found its way down to the data layer this year – and came back up with an answer.

    Also see

    > The Breach is in the Database
    > Why Database Auditing Is No Longer Optional
    > AI Readiness Is Data Readiness

    • The author, Johan Lamberts, is MD at Ascent Technology
    • Read more articles by Ascent Technology on TechCentral
    • This promoted content was paid for by the party concerned
    Add TechCentral as a preferred source on GoogleFollow TechCentral on Google NewsGet breaking news on WhatsApp


    Ascent Technology Cyanre Information Regulator Institute of Directors in South Africa Microsoft Redgate Sophos
    WhatsApp YouTube
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleRight to repair comes to South African electronics

    Related Posts

    Let South Africans jailbreak their way to digital sovereignty

    Let South Africans jailbreak their way to digital sovereignty

    5 October 2026
    Ransomware gang threatens to dump more South African client data

    Ransomware gang threatens to dump more South African client data

    5 October 2026
    AI spending now dwarfs the railway and dot-com booms

    AI spending now dwarfs the railway and dot-com booms

    4 October 2026
    Add A Comment

    Comments are closed.

    Company News
    The board now owns the database - Ascent Technology, Johan Lamberts

    The board now owns the database

    5 October 2026
    The attacker has one AI. You have 12 dashboards - Uri Levy

    The attacker has one AI. You have 12 dashboards

    5 October 2026
    Huawei sets out its vision for intelligent government at GovTech 2026

    Huawei sets out its vision for intelligent government at GovTech 2026

    2 October 2026
    Opinion
    South Africa's next energy crisis is in the accounts department - Craig Holmes

    South Africa’s next energy crisis is in the accounts department

    29 September 2026
    The steam engine lesson AI doomsayers keep missing - Sam Clarke

    The steam engine lesson AI doomsayers keep missing

    28 September 2026
    The author, Dirk de Vos

    Regulating AI: apply the laws we have first

    21 September 2026

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    The board now owns the database - Ascent Technology, Johan Lamberts

    The board now owns the database

    5 October 2026
    South Africa's right-to-repair guidelines target software locks on spare parts

    Right to repair comes to South African electronics

    5 October 2026
    Luno says crypto draft may clash with South Africa's IMF commitments - Marius Reitz

    Luno says crypto draft may clash with SA’s IMF commitments

    5 October 2026
    Let South Africans jailbreak their way to digital sovereignty

    Let South Africans jailbreak their way to digital sovereignty

    5 October 2026
    © 2009 - 2026 NewsCentral Media
    Built and maintained by Chronon
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}
    🇿🇦 Sign up to the TechCentral newsletter