preloader

ABSOLUTE DATA EXCELLENCE

Ascent Technology Logo
Ascent Technology Logo

ABSOLUTE DATA EXCELLENCE

Ascent Technology Logo
VENDOR RELATIONSHIPS
FROM THE DESK OF THE MD
Your Last SQL Server End-of-Support Deadline

Your Last SQL Server End-of-Support Deadline

Every SQL Server deadline buys the same thing: a project that delivers nothing new. There is a version of that project you only ever run once.Key Takeaways The standstill project - Much of what passes for modernisation is a project that delivers nothing new: months of...

Support Ended for SQL Server 2016. So Did the Microsoft Subsidy.

For three end-of-support cycles, Microsoft made waiting free. This time it did not – and that, not the deadline, is the story.Key Takeaways The subsidy on waiting has been withdrawn - for three end-of-support cycles Microsoft made deferral effectively free on Azure,...

Copilot Is Ready. Is Your Data?

Copilot is ready the day you switch it on. Whether it delivers depends on something Microsoft cannot ship you: a governed data estate underneath it.Key Takeaways Adoption is outrunning readiness - enterprise Copilot rollouts are accelerating, but what varies from one...

Your Last SQL Server End-of-Support Deadline

Your Last SQL Server End-of-Support Deadline

Every SQL Server deadline buys the same thing: a project that delivers nothing new. There is a version of that project you only ever run once.Key Takeaways The standstill project - Much of what passes for modernisation is a project that delivers nothing new: months of...

Support Ended for SQL Server 2016. So Did the Microsoft Subsidy.

Support Ended for SQL Server 2016. So Did the Microsoft Subsidy.

For three end-of-support cycles, Microsoft made waiting free. This time it did not – and that, not the deadline, is the story.Key Takeaways The subsidy on waiting has been withdrawn - for three end-of-support cycles Microsoft made deferral effectively free on Azure,...

Copilot Is Ready. Is Your Data?

Copilot is ready the day you switch it on. Whether it delivers depends on something Microsoft cannot ship you: a governed data estate underneath it.Key Takeaways Adoption is outrunning readiness - enterprise Copilot rollouts are accelerating, but what varies from one...

AI Readiness Is Data Readiness 

Enterprise AI has moved from pilots to full-workforce rollouts - and the question few are asking is whether their data is governed enough to let an AI read it.Key Takeaways Speed is the wrong question - enterprise AI has jumped to full-workforce Copilot rollouts and...

CAMPAIGNS
Azure by Credit Card vs CSP: Why Finance and IT Prefer CSP

Azure by Credit Card vs CSP: Why Finance and IT Prefer CSP

Still paying Microsoft for Azure by credit card? Discover why finance and IT leaders prefer the CSP model for predictable billing, built-in partner support, cost optimisation, and long-term value.Key Takeways Credit card billing creates risk - Failed or expired...

Prepare for SQL Server 2014 End of Support

On July 9, 2024, support for SQL Server 2014 ended. That means the end of regular security updates. Don't let your infrastructure and applications go unprotected. We're here to help you migrate to current versions for greater security, performance and innovation.We've...

Prepare for SQL Server 2012 End of Support

On July 12, 2022, support for SQL Server 2012 ended. That means the end of regular security updates. Don't let your infrastructure and applications go unprotected. We're here to help you migrate to current versions for greater security, performance and...

Azure by Credit Card vs CSP: Why Finance and IT Prefer CSP

Azure by Credit Card vs CSP: Why Finance and IT Prefer CSP

Still paying Microsoft for Azure by credit card? Discover why finance and IT leaders prefer the CSP model for predictable billing, built-in partner support, cost optimisation, and long-term value.Key Takeways Credit card billing creates risk - Failed or expired...

Prepare for SQL Server 2014 End of Support

Prepare for SQL Server 2014 End of Support

On July 9, 2024, support for SQL Server 2014 ended. That means the end of regular security updates. Don't let your infrastructure and applications go unprotected. We're here to help you migrate to current versions for greater security, performance and innovation.We've...

Prepare for Windows Server 2012 End of Support

On October 10, 2023, support for Windows Server 2012 and 2012 R2 ended. That means the end of regular security updates. Don't let your infrastructure and applications go unprotected. We're here to help you migrate to current versions for greater security, performance...

Prepare for SQL Server 2008 End of Support

On July 9, 2019, support for SQL Server 2008 and 2008 R2 will end. That means the end of regular security updates. Don't let your infrastructure and applications go unprotected. We're here to help you migrate to current versions for greater security, performance and...

NEWSFLASHES
SQL Server 2016 Support Has Ended – and the Rules Have Changed

SQL Server 2016 Support Has Ended – and the Rules Have Changed

Extended support for SQL Server 2016 ended on 14 July 2026. Without ESUs there are no more security updates – and this cycle, Microsoft has repriced the exit routes.The facts On 14 July 2026, SQL Server 2016 reached end of support. Mainstream support ended in July...

Season’s Greetings from the Ascent Technology Team

As the year draws to a close, we would like to express our appreciation to our clients, partners, and colleagues for the trust and collaboration that have defined the year. We wish you and your teams a restful festive season and a successful year ahead, and we look...

Ascent’s SQL Server 2025 Blog Post Series

Microsoft SQL Server 2025 marks an important shift in how organisations modernise, optimise, and protect their data platforms. As data estates become more hybrid, more intelligent, and more tightly governed, SQL Server 2025 is no longer just another upgrade cycle. It...

SQL Server 2016 Support Has Ended – and the Rules Have Changed

SQL Server 2016 Support Has Ended – and the Rules Have Changed

Extended support for SQL Server 2016 ended on 14 July 2026. Without ESUs there are no more security updates – and this cycle, Microsoft has repriced the exit routes.The facts On 14 July 2026, SQL Server 2016 reached end of support. Mainstream support ended in July...

Season’s Greetings from the Ascent Technology Team

Season’s Greetings from the Ascent Technology Team

As the year draws to a close, we would like to express our appreciation to our clients, partners, and colleagues for the trust and collaboration that have defined the year. We wish you and your teams a restful festive season and a successful year ahead, and we look...

Microsoft Tiered EA/MPSA Pricing Ends – Explore the CSP Advantage

Standardised pricing will replace Microsoft’s long-standing tiered discount model - prompting many organisations to review the CSP programme for its cost savings, licensing flexibility, and simplified management.Microsoft Tiered EA/MPSA Pricing Ends Microsoft will...

Season’s Greetings from the Ascent Technology Team

As we wrap up the year, we’d like to extend our sincere thanks to our clients, colleagues, and partners for your continued trust and support. We hope the festive season brings you the chance to slow down, recharge, and enjoy time with family and friends. Warm wishes...

CLIENT CASE STUDIES
DB Administration, Security and Compliance for First Distribution

DB Administration, Security and Compliance for First Distribution

First Distribution’s Database Administration, Security and Compliance needs lead it to trusted advisor, Ascent Technology. For any large organisation, Database Administration (DBA) is a vital part of maintaining their Data Platform Operations effectively. As it has...

Ascent Technology helps Bidfood SA migrate to Microsoft Azure

When Bidfood SA chose to modernise and migrate its data platform to Microsoft Azure, it turned to Ascent Technology for help. In a world that is digitally transforming, it is more vital than ever to an organisation’s success to utilise the latest platforms to drive...

Ascent Technology helps migrate Phumelela Gaming to Azure

A Windows Server and SQL Server consolidation, optimisation and migration to Microsoft Azure enables the company to reduce costs, modernise its data platform and boost its innovation capabilities. As an operator running two distinct betting businesses, Phumelela...

DB Administration, Security and Compliance for First Distribution

DB Administration, Security and Compliance for First Distribution

First Distribution’s Database Administration, Security and Compliance needs lead it to trusted advisor, Ascent Technology. For any large organisation, Database Administration (DBA) is a vital part of maintaining their Data Platform Operations effectively. As it has...

Ascent Technology helps Bidfood SA migrate to Microsoft Azure

Ascent Technology helps Bidfood SA migrate to Microsoft Azure

When Bidfood SA chose to modernise and migrate its data platform to Microsoft Azure, it turned to Ascent Technology for help. In a world that is digitally transforming, it is more vital than ever to an organisation’s success to utilise the latest platforms to drive...

Ascent helps migrate Compatible Automotive to Azure

Microsoft Azure Data Platform Services not only boosts the company’s DR facilities, it also helps them deliver value-added services and innovative strategic solutions to its customers. In a digitising world, it comes as no surprise to learn that Compatible Automotive...

AWARDS AND ACCOLADES
Microsoft Data and Analytics Partner of the Year Finalist

Microsoft Data and Analytics Partner of the Year Finalist

Ascent Technology continues its strong showing in the Microsoft Partner of the Year awards, as a finalist in the Data and Analytics Partner of the Year award.Finalist Data and Analytics Partner of the Year "It is always gratifying to be recognised by Microsoft as one...

Microsoft Data and Analytics Partner of the Year Finalist

Microsoft Data and Analytics Partner of the Year Finalist

Ascent Technology continues its strong showing in the Microsoft Partner of the Year awards, as a finalist in the Data and Analytics Partner of the Year award.Finalist Data and Analytics Partner of the Year "It is always gratifying to be recognised by Microsoft as one...

Microsoft Data and Analytics Partner of the Year Finalist

Microsoft Data and Analytics Partner of the Year Finalist

Ascent Technology continues its strong showing in the Microsoft Partner of the Year awards, as a finalist in the Data and Analytics Partner of the Year award.Finalist Data and Analytics Partner of the Year "It is always gratifying to be recognised by Microsoft as one...

From the Desk of the MD

The Board Now Owns the Database

King V’s Principle 10 has made the board accountable for an estate most boards have never seen. The paragraph in next year’s report will not be the answer.

Key Takeaways

  • The word is accountable – Principle 10 does not ask the board to receive reports on data. It makes the governing body accountable for how data is acquired, used, disseminated and disposed of.
  • A paragraph is not an answer – Most boards will meet the principle with a delegated committee, an approved policy and a paragraph in the 2027 report. None of those can say where the sensitive data sits, who can reach it, or which engines holding it are still supported.
  • The question moves down the table – Directors will not answer Principle 10 themselves. It lands on the CIO, the head of data and whoever runs the databases – asked, for the first time, on the record.
  • Third parties are now the board’s problem – The Code names outsourced services and suppliers “including across jurisdictions”. Every hosting provider, outsourced DBA and reporting tool that touches personal information sits inside that accountability.
  • Evidence has to pre-date the question – Enforcement, the financial sector’s cyber standard and an attacker dwell time of eighteen days all point the same way: assurance is what already exists when someone asks.
South African boards are entering the first financial year governed by King V – the calendar-year boards are already two-thirds of the way through it. Most met its arrival the way boards meet every new code – a briefing from the company secretary, a gap analysis from the auditors, a committee charter amended – and the year carried on.

The data and technology chapter is where the Code changed most; the IoDSA says so itself. And it is being read as a disclosure obligation – a paragraph to be written in 2027 about a year already being lived. It is not that. Principle 10 makes the board accountable for the data estate now, and the people who will write the paragraph cannot answer the question it raises.

Principle 10

The wording is worth reading slowly, because it was chosen slowly. Principle 10 says the governing body “governs data, information and technology in a way that enables the organisation to sustain and optimise its strategy and objectives”. The first practice beneath it says the board should “be accountable for the effective, compliant and ethical management and control (including acquisition, creation, use, dissemination and disposal) of data and information”.

Accountable. Not informed, not briefed, not satisfied that management has it in hand.

The practices that follow name what the board must see to: sensitive data identified and classified, its confidentiality, integrity and availability secured, its quality maintained, and the risks of “outsourced services, suppliers and third parties, including across jurisdictions” managed. Practice 104 adds the part most boards will skip past – periodic assurance on all of it.

King IV covered technology and information in one principle. King V separates them, treats data as a governed asset in its own right, and says in its own background note that this is where the Code “has undergone the most substantial changes”. It is written for any juristic person “regardless of its manner or form of incorporation”, and apply-and-explain now ends with a statement on whether the Code “realised value for the organisation”.

That last requirement is the trap. It invites narrative, and narrative is what a paragraph is made of.

The Paragraph

Here is how Principle 10 will be applied in most organisations, because it is how every principle is applied. The board delegates its data and technology responsibilities to the risk committee, which the Code permits. Management drafts a data governance policy, which the committee approves. The policy is referenced in the integrated report, with a sentence on the value realised. Apply, explain, file.

None of that is wrong. It is simply not an answer. A policy states intent about data; it does not say where the data is. The evidence that the gap is real is not hard to find.

The Information Regulator logged 788 security-compromise notifications in the first quarter of this year, most of them human error rather than attack. Its first enforcement notice of 2026 went to a college whose acting chief financial officer emailed staff a folder of finance policies that also held employees’ criminal-record and qualification checks.

The finding: an “absence of file segregation between personal data and finance policies”. A governance failure at the level of a folder, now carrying orders with 31-day clocks on them.

The international picture matches at scale. In Redgate’s June survey of 2,150 IT professionals, 77 percent of organisations had no formal data governance or quality framework, and 44 percent had invested more than $100,000 in database AI over the past year. Money is flowing to the top of the estate while nobody holds the map of it.

A board that has approved a policy has done what the paragraph requires. It has not done what the principle requires.

On the Record

Directors will not answer Principle 10 themselves. They will ask. The question travels down the table – to the chief information officer, to the head of data, to whoever runs the databases – and for the first time it arrives with the weight of the Code behind it. In practice it is three questions, and a fourth the Code asks in the board’s own name.

Where does the sensitive data sit? Not the systems list from the asset register – the tables, the columns, the copies in the reporting layer, the extracts on the file share. Practice 103 asks for identification and classification, and classification presupposes a count. Most estates have never had an inventory a director would recognise as complete.

Who holds standing access to it? Sophos’s 2026 ransomware study, which includes South African organisations, found that 79 percent of attacks began with a compromised identity – and that where the way in was a stolen credential, multi-factor authentication had already been deployed in 97 percent of cases. The control was present; its coverage was not.

Coverage is only half of the access question. The other half is what a credential can reach once inside – in most estates I see, service accounts with DBA privileges granted for a project and never withdrawn, and rights accumulated over years and never reduced.

A board accountable for confidentiality is accountable for that list.

Which of the engines holding it are still supported? SQL Server 2016 left support on 14 July; Windows Server 2016 follows on 12 January; SQL Server 2017 has thirteen months left. An unsupported engine under personal information is a resilience finding under Practice 108. It is also, on the Regulator’s own reasoning about lapsed security tooling, a position that section 19 of POPIA will require the organisation to defend.

And the fourth: who else touches this data? The outsourced DBA, the hosting provider, the reporting tool with a database connection, the payroll bureau. Practice 103 names third parties “including across jurisdictions”.

For financial institutions the twelve-month implementation period the regulators allowed for Joint Standard 2 ended in June – 24-hour reporting of material incidents and the management of third-party cyber risk, no longer a runway. Every material supplier to a bank, an insurer or a retirement fund now sits inside that institution’s cyber-risk perimeter, whether or not it has been told.

This is the layer where, as I argued in April, South Africa’s breaches actually happen. King V has now put a director’s name against it.

What It Buys

Principle 10 has a second half that will get less attention, and should not. Practice 105 makes the board accountable for the “acquisition, development, use and distribution of technology”, and Practice 108 asks it to see that technology investment returns “commensurate benefits”. The board is accountable for what the organisation buys as well as what it holds.

For many South African enterprises the largest recurring technology purchase is the Microsoft estate – licences, subscriptions, cloud consumption – renewed on a calendar few directors have seen. A renewal signed on the wrong billing terms, a commitment that can no longer be exchanged, a currency adjustment that lands once a year: none of these is a security incident, and every one is a Principle 10 matter. The cost of the estate is part of the estate.

Before the Incident

Practice 104 asks the board to “consider periodic assurance” on all of this. Assurance is where the paragraph and the principle finally part company.

Assurance on data is not a policy attestation. It is an inventory that is current, an access review that has been done and minuted, a support-status register for every engine holding personal information, a recovery test that was actually run, and an activity record that would show what happened if something did. It exists before anyone asks. That is the whole point of it.

The reason it has to exist beforehand is arithmetic. Cyanre’s South African incident data puts attacker dwell time at eighteen days in 2025, down from 117 the year before, with data rather than systems now the target. Eighteen days is shorter than a quarterly reporting cycle. “We would have noticed” was a weak defence when attackers sat in estates for months. It is no defence now.

By the time the first King V reports are written next year, the year they describe will already have been lived – in the estate, not in the boardroom. Some boards will answer those questions because the answers existed all along. Others will discover, in front of an auditor, an insurer or the Regulator, that a paragraph was all they had.

The Last Word

I sit on a board as well, and I know how easily a principle becomes a paragraph. The papers arrive, the policy is sound, the committee has it covered, and the meeting moves on. I also know what the question sounds like from the other side of the table, because for twenty-three years the people who have to answer it have been the ones Ascent works alongside.

Principle 10 does not change what a database estate is. It changes who is accountable for it. The organisations that will be comfortable in 2027 are the ones where that accountability found its way down to the data layer this year – and came back up with an answer.