On the Record
Directors will not answer Principle 10 themselves. They will ask. The question travels down the table – to the chief information officer, to the head of data, to whoever runs the databases – and for the first time it arrives with the weight of the Code behind it. In practice it is three questions, and a fourth the Code asks in the board’s own name.
Where does the sensitive data sit? Not the systems list from the asset register – the tables, the columns, the copies in the reporting layer, the extracts on the file share. Practice 103 asks for identification and classification, and classification presupposes a count. Most estates have never had an inventory a director would recognise as complete.
Who holds standing access to it? Sophos’s 2026 ransomware study, which includes South African organisations, found that 79 percent of attacks began with a compromised identity – and that where the way in was a stolen credential, multi-factor authentication had already been deployed in 97 percent of cases. The control was present; its coverage was not.
Coverage is only half of the access question. The other half is what a credential can reach once inside – in most estates I see, service accounts with DBA privileges granted for a project and never withdrawn, and rights accumulated over years and never reduced.
A board accountable for confidentiality is accountable for that list.
Which of the engines holding it are still supported? SQL Server 2016 left support on 14 July; Windows Server 2016 follows on 12 January; SQL Server 2017 has thirteen months left. An unsupported engine under personal information is a resilience finding under Practice 108. It is also, on the Regulator’s own reasoning about lapsed security tooling, a position that section 19 of POPIA will require the organisation to defend.
And the fourth: who else touches this data? The outsourced DBA, the hosting provider, the reporting tool with a database connection, the payroll bureau. Practice 103 names third parties “including across jurisdictions”.
For financial institutions the twelve-month implementation period the regulators allowed for Joint Standard 2 ended in June – 24-hour reporting of material incidents and the management of third-party cyber risk, no longer a runway. Every material supplier to a bank, an insurer or a retirement fund now sits inside that institution’s cyber-risk perimeter, whether or not it has been told.
This is the layer where, as I argued in April, South Africa’s breaches actually happen. King V has now put a director’s name against it.