About
Subscribe

The board now owns the database

By Johan Lamberts, MD, Ascent Technology
Johannesburg, 05 Oct 2026
Johan Lamberts is MD of Ascent Technology.
Johan Lamberts is MD of Ascent Technology.

King V’s Principle 10 has made the board accountable for an estate most boards have never seen. The paragraph in next year’s report will not be the answer.

Key takeaways

  • The word is accountable – Principle 10 does not ask the board to receive reports on data. It makes the governing body accountable for how data is acquired, used, disseminated and disposed of.
  • A paragraph is not an answer – Most boards will meet the principle with a delegated committee, an approved policy and a paragraph in the 2027 report. None of those can say where the sensitive data sits, who can reach it or which engines holding it are still supported.
  • The question moves down the table – Directors will not answer Principle 10 themselves. It lands on the CIO, the head of data and whoever runs the databases – asked, for the first time, on the record.
  • Third parties are now the board’s problem – The code names outsourced services and suppliers “including across jurisdictions”. Every hosting provider, outsourced DBA and reporting tool that touches personal information sits inside that accountability.
  • Evidence has to pre-date the question – Enforcement, the financial sector’s cyber standard and an attacker dwell time of 18 days all point the same way: assurance is what already exists when someone asks.

South African boards are entering the first financial year governed by King V – the calendar-year boards are already two-thirds of the way through it. Most met its arrival the way boards meet every new code – a briefing from the company secretary, a gap analysis from the auditors, a committee charter amended – and the year carried on.

The data and technology chapter is where the code changed most; the IoDSA says so itself. And it is being read as a disclosure obligation – a paragraph to be written in 2027 about a year already being lived. It is not that. Principle 10 makes the board accountable for the data estate now, and the people who will write the paragraph cannot answer the question it raises

Principle 10

The wording is worth reading slowly, because it was chosen slowly. Principle 10 says the governing body “governs data, information and technology in a way that enables the organisation to sustain and optimise its strategy and objectives”. The first practice beneath it says the board should “be accountable for the effective, compliant and ethical management and control (including acquisition, creation, use, dissemination and disposal) of data and information”.

Accountable. Not informed, not briefed, not satisfied that management has it in hand.

The practices that follow name what the board must see to: sensitive data identified and classified, its confidentiality, integrity and availability secured, its quality maintained, and the risks of “outsourced services, suppliers and third parties, including across jurisdictions” managed. Practice 104 adds the part most boards will skip past – periodic assurance on all of it.

King IV covered technology and information in one principle. King V separates them, treats data as a governed asset in its own right, and says in its own background note that this is where the code “has undergone the most substantial changes”. It is written for any juristic person “regardless of its manner or form of incorporation”, and apply-and-explain now ends with a statement on whether the code “realised value for the organisation”.

That last requirement is the trap. It invites narrative, and narrative is what a paragraph is made of.

The paragraph

Here is how Principle 10 will be applied in most organisations, because it is how every principle is applied. The board delegates its data and technology responsibilities to the risk committee, which the code permits. Management drafts a data governance policy, which the committee approves.

The policy is referenced in the integrated report, with a sentence on the value realised. Apply, explain, file.

None of that is wrong. It is simply not an answer. A policy states intent about data; it does not say where the data is. The evidence that the gap is real is not hard to find.

The Information Regulator logged 788 security-compromise notifications in the first quarter of this year, most of them human error rather than attack. Its first enforcement notice of 2026 went to a college whose acting chief financial officer e-mailed staff a folder of finance policies that also held employees’ criminal-record and qualification checks.

The finding: an “absence of file segregation between personal data and finance policies”. A governance failure at the level of a folder, now carrying orders with 31-day clocks on them.

The international picture matches at scale. In Redgate’s June survey of 2 150 IT professionals, 77% of organisations had no formal data governance or quality framework, and 44% had invested more than $100 000 in database AI over the past year. Money is flowing to the top of the estate while nobody holds the map of it.

A board that has approved a policy has done what the paragraph requires. It has not done what the principle requires.

On the record

Directors will not answer Principle 10 themselves. They will ask. The question travels down the table – to the chief information officer, to the head of data, to whoever runs the databases – and for the first time it arrives with the weight of the code behind it. In practice it is three questions, and a fourth the code asks in the board’s own name.

Where does the sensitive data sit? Not the systems list from the asset register – the tables, the columns, the copies in the reporting layer, the extracts on the file share. Practice 103 asks for identification and classification, and classification presupposes a count. Most estates have never had an inventory a director would recognise as complete.

Who holds standing access to it? Sophos’s 2026 ransomware study, which includes South African organisations, found that 79% of attacks began with a compromised identity – and that where the way in was a stolen credential, multi-factor authentication had already been deployed in 97% of cases. The control was present; its coverage was not.

Coverage is only half of the access question. The other half is what a credential can reach once inside – in most estates I see, service accounts with DBA privileges granted for a project and never withdrawn, and rights accumulated over years and never reduced.

A board accountable for confidentiality is accountable for that list.

Which of the engines holding it are still supported? SQL Server 2016 left support on 14 July; Windows Server 2016 follows on 12 January; SQL Server 2017 has 13 months left. An unsupported engine under personal information is a resilience finding under Practice 108. It is also, on the Regulator’s own reasoning about lapsed security tooling, a position that section 19 of POPIA will require the organisation to defend.

And the fourth: who else touches this data? The outsourced DBA, the hosting provider, the reporting tool with a database connection, the payroll bureau. Practice 103 names third parties “including across jurisdictions”.

For financial institutions, the 12-month implementation period the regulators allowed for Joint Standard 2 ended in June – 24-hour reporting of material incidents and the management of third-party cyber risk, no longer a runway. Every material supplier to a bank, an insurer or a retirement fund now sits inside that institution’s cyber-risk perimeter, whether or not it has been told.

This is the layer where, as I argued in April, South Africa’s breaches actually happen. King V has now put a director’s name against it.

What it buys

Principle 10 has a second half that will get less attention, and should not. Practice 105 makes the board accountable for the “acquisition, development, use and distribution of technology”, and Practice 108 asks it to see that technology investment returns “commensurate benefits”. The board is accountable for what the organisation buys as well as what it holds.

For many South African enterprises, the largest recurring technology purchase is the Microsoft estate – licences, subscriptions, cloud consumption – renewed on a calendar few directors have seen. A renewal signed on the wrong billing terms, a commitment that can no longer be exchanged, a currency adjustment that lands once a year: none of these is a security incident, and every one is a Principle 10 matter. The cost of the estate is part of the estate.

Before the Incident

Practice 104 asks the board to “consider periodic assurance” on all of this. Assurance is where the paragraph and the principle finally part company.

Assurance on data is not a policy attestation. It is an inventory that is current, an access review that has been done and minuted, a support-status register for every engine holding personal information, a recovery test that was actually run, and an activity record that would show what happened if something did. It exists before anyone asks. That is the whole point of it.

The reason it has to exist beforehand is arithmetic. Cyanre’s South African incident data puts attacker dwell time at 18 days in 2025, down from 117 the year before, with data rather than systems now the target. Eighteen days is shorter than a quarterly reporting cycle. “We would have noticed” was a weak defence when attackers sat in estates for months. It is no defence now.

By the time the first King V reports are written next year, the year they describe will already have been lived – in the estate, not in the boardroom. Some boards will answer those questions because the answers existed all along. Others will discover, in front of an auditor, an insurer or the Regulator, that a paragraph was all they had.

The last word

I sit on a board as well, and I know how easily a principle becomes a paragraph. The papers arrive, the policy is sound, the committee has it covered and the meeting moves on. I also know what the question sounds like from the other side of the table, because for 23 years, the people who have to answer it have been the ones Ascent works alongside.

Principle 10 does not change what a database estate is. It changes who is accountable for it. The organisations that will be comfortable in 2027 are the ones where that accountability found its way down to the data layer this year – and came back up with an answer.

Share

Editorial contacts

Johan Lamberts
Ascent Technology
(+27) 11 745 1340
johan.lamberts@ascent.co.za