preloader

ABSOLUTE DATA EXCELLENCE

Ascent Technology Logo
Ascent Technology Logo

ABSOLUTE DATA EXCELLENCE

Ascent Technology Logo
VENDOR RELATIONSHIPS
FROM THE DESK OF THE MD
Four Microsoft Dates Before February. The Cost Is in the Calendar.

Four Microsoft Dates Before February. The Cost Is in the Calendar.

Four Microsoft dates between July and February decide what your estate will cost next year. None of them will say so on the invoice. The calendar is public – the question is who is reading yours.Key Takeaways Nothing will say price increase - Between July and...

The Board Now Owns the Database

King V's Principle 10 has made the board accountable for an estate most boards have never seen. The paragraph in next year's report will not be the answer.Key Takeaways The word is accountable - Principle 10 does not ask the board to receive reports on data. It makes...

Your Last SQL Server End-of-Support Deadline

Every SQL Server deadline buys the same thing: a project that delivers nothing new. There is a version of that project you only ever run once.Key Takeaways The standstill project - Much of what passes for modernisation is a project that delivers nothing new: months of...

Four Microsoft Dates Before February. The Cost Is in the Calendar.

Four Microsoft Dates Before February. The Cost Is in the Calendar.

Four Microsoft dates between July and February decide what your estate will cost next year. None of them will say so on the invoice. The calendar is public – the question is who is reading yours.Key Takeaways Nothing will say price increase - Between July and...

The Board Now Owns the Database

The Board Now Owns the Database

King V's Principle 10 has made the board accountable for an estate most boards have never seen. The paragraph in next year's report will not be the answer.Key Takeaways The word is accountable - Principle 10 does not ask the board to receive reports on data. It makes...

Your Last SQL Server End-of-Support Deadline

Every SQL Server deadline buys the same thing: a project that delivers nothing new. There is a version of that project you only ever run once.Key Takeaways The standstill project - Much of what passes for modernisation is a project that delivers nothing new: months of...

Support Ended for SQL Server 2016. So Did the Microsoft Subsidy.

For three end-of-support cycles, Microsoft made waiting free. This time it did not – and that, not the deadline, is the story.Key Takeaways The subsidy on waiting has been withdrawn - for three end-of-support cycles Microsoft made deferral effectively free on Azure,...

CAMPAIGNS
Azure by Credit Card vs CSP: Why Finance and IT Prefer CSP

Azure by Credit Card vs CSP: Why Finance and IT Prefer CSP

Still paying Microsoft for Azure by credit card? Discover why finance and IT leaders prefer the CSP model for predictable billing, built-in partner support, cost optimisation, and long-term value.Key Takeways Credit card billing creates risk - Failed or expired...

Prepare for SQL Server 2014 End of Support

On July 9, 2024, support for SQL Server 2014 ended. That means the end of regular security updates. Don't let your infrastructure and applications go unprotected. We're here to help you migrate to current versions for greater security, performance and innovation.We've...

Prepare for SQL Server 2012 End of Support

On July 12, 2022, support for SQL Server 2012 ended. That means the end of regular security updates. Don't let your infrastructure and applications go unprotected. We're here to help you migrate to current versions for greater security, performance and...

Azure by Credit Card vs CSP: Why Finance and IT Prefer CSP

Azure by Credit Card vs CSP: Why Finance and IT Prefer CSP

Still paying Microsoft for Azure by credit card? Discover why finance and IT leaders prefer the CSP model for predictable billing, built-in partner support, cost optimisation, and long-term value.Key Takeways Credit card billing creates risk - Failed or expired...

Prepare for SQL Server 2014 End of Support

Prepare for SQL Server 2014 End of Support

On July 9, 2024, support for SQL Server 2014 ended. That means the end of regular security updates. Don't let your infrastructure and applications go unprotected. We're here to help you migrate to current versions for greater security, performance and innovation.We've...

Prepare for Windows Server 2012 End of Support

On October 10, 2023, support for Windows Server 2012 and 2012 R2 ended. That means the end of regular security updates. Don't let your infrastructure and applications go unprotected. We're here to help you migrate to current versions for greater security, performance...

Prepare for SQL Server 2008 End of Support

On July 9, 2019, support for SQL Server 2008 and 2008 R2 will end. That means the end of regular security updates. Don't let your infrastructure and applications go unprotected. We're here to help you migrate to current versions for greater security, performance and...

NEWSFLASHES
SQL Server 2016 Support Has Ended – and the Rules Have Changed

SQL Server 2016 Support Has Ended – and the Rules Have Changed

Extended support for SQL Server 2016 ended on 14 July 2026. Without ESUs there are no more security updates – and this cycle, Microsoft has repriced the exit routes.The facts On 14 July 2026, SQL Server 2016 reached end of support. Mainstream support ended in July...

Season’s Greetings from the Ascent Technology Team

As the year draws to a close, we would like to express our appreciation to our clients, partners, and colleagues for the trust and collaboration that have defined the year. We wish you and your teams a restful festive season and a successful year ahead, and we look...

Ascent’s SQL Server 2025 Blog Post Series

Microsoft SQL Server 2025 marks an important shift in how organisations modernise, optimise, and protect their data platforms. As data estates become more hybrid, more intelligent, and more tightly governed, SQL Server 2025 is no longer just another upgrade cycle. It...

SQL Server 2016 Support Has Ended – and the Rules Have Changed

SQL Server 2016 Support Has Ended – and the Rules Have Changed

Extended support for SQL Server 2016 ended on 14 July 2026. Without ESUs there are no more security updates – and this cycle, Microsoft has repriced the exit routes.The facts On 14 July 2026, SQL Server 2016 reached end of support. Mainstream support ended in July...

Season’s Greetings from the Ascent Technology Team

Season’s Greetings from the Ascent Technology Team

As the year draws to a close, we would like to express our appreciation to our clients, partners, and colleagues for the trust and collaboration that have defined the year. We wish you and your teams a restful festive season and a successful year ahead, and we look...

Microsoft Tiered EA/MPSA Pricing Ends – Explore the CSP Advantage

Standardised pricing will replace Microsoft’s long-standing tiered discount model - prompting many organisations to review the CSP programme for its cost savings, licensing flexibility, and simplified management.Microsoft Tiered EA/MPSA Pricing Ends Microsoft will...

Season’s Greetings from the Ascent Technology Team

As we wrap up the year, we’d like to extend our sincere thanks to our clients, colleagues, and partners for your continued trust and support. We hope the festive season brings you the chance to slow down, recharge, and enjoy time with family and friends. Warm wishes...

CLIENT CASE STUDIES
DB Administration, Security and Compliance for First Distribution

DB Administration, Security and Compliance for First Distribution

First Distribution’s Database Administration, Security and Compliance needs lead it to trusted advisor, Ascent Technology. For any large organisation, Database Administration (DBA) is a vital part of maintaining their Data Platform Operations effectively. As it has...

Ascent Technology helps Bidfood SA migrate to Microsoft Azure

When Bidfood SA chose to modernise and migrate its data platform to Microsoft Azure, it turned to Ascent Technology for help. In a world that is digitally transforming, it is more vital than ever to an organisation’s success to utilise the latest platforms to drive...

Ascent Technology helps migrate Phumelela Gaming to Azure

A Windows Server and SQL Server consolidation, optimisation and migration to Microsoft Azure enables the company to reduce costs, modernise its data platform and boost its innovation capabilities. As an operator running two distinct betting businesses, Phumelela...

DB Administration, Security and Compliance for First Distribution

DB Administration, Security and Compliance for First Distribution

First Distribution’s Database Administration, Security and Compliance needs lead it to trusted advisor, Ascent Technology. For any large organisation, Database Administration (DBA) is a vital part of maintaining their Data Platform Operations effectively. As it has...

Ascent Technology helps Bidfood SA migrate to Microsoft Azure

Ascent Technology helps Bidfood SA migrate to Microsoft Azure

When Bidfood SA chose to modernise and migrate its data platform to Microsoft Azure, it turned to Ascent Technology for help. In a world that is digitally transforming, it is more vital than ever to an organisation’s success to utilise the latest platforms to drive...

Ascent helps migrate Compatible Automotive to Azure

Microsoft Azure Data Platform Services not only boosts the company’s DR facilities, it also helps them deliver value-added services and innovative strategic solutions to its customers. In a digitising world, it comes as no surprise to learn that Compatible Automotive...

AWARDS AND ACCOLADES
Microsoft Data and Analytics Partner of the Year Finalist

Microsoft Data and Analytics Partner of the Year Finalist

Ascent Technology continues its strong showing in the Microsoft Partner of the Year awards, as a finalist in the Data and Analytics Partner of the Year award.Finalist Data and Analytics Partner of the Year "It is always gratifying to be recognised by Microsoft as one...

Microsoft Data and Analytics Partner of the Year Finalist

Microsoft Data and Analytics Partner of the Year Finalist

Ascent Technology continues its strong showing in the Microsoft Partner of the Year awards, as a finalist in the Data and Analytics Partner of the Year award.Finalist Data and Analytics Partner of the Year "It is always gratifying to be recognised by Microsoft as one...

Microsoft Data and Analytics Partner of the Year Finalist

Microsoft Data and Analytics Partner of the Year Finalist

Ascent Technology continues its strong showing in the Microsoft Partner of the Year awards, as a finalist in the Data and Analytics Partner of the Year award.Finalist Data and Analytics Partner of the Year "It is always gratifying to be recognised by Microsoft as one...

From the Desk of the MD

Data Sovereignty in South Africa Is Not an Address

The country is debating where its data should live. The organisations inside it are losing control of theirs one copy at a time – mostly to suppliers down the road.

Key Takeaways

  • Residency answers where. Sovereignty answers who – A data centre inside the border settles the first question and says nothing about the second: who holds the keys, who can reach the data, who patches the engine beneath it, and whether you could take all of it back.
  • Control leaks through copies, not borders – Every extract, staging database, spreadsheet and supplier feed is another place the data lives, with its own permissions, its own patch state and its own jurisdiction. Most estates have never counted them.
  • September’s breaches needed no foreign border – Institutions whose own systems were never touched wrote to their customers anyway, because a copy of those customers’ identities sat with a supplier. Residency was never the problem.
  • The sovereignty decisions are being taken by administrators – A tenant setting that sends AI prompts to another continent is switched on in an afternoon because a dashboard needed the feature. Nobody minutes it.
  • Residency can be bought. Control cannot – In-country regions and customer-held keys are here; in-country AI processing is arriving, on the vendors’ timetable. What no vendor can supply is the organisation’s own knowledge of where its copies are and who can reach them.
South Africa spent September talking about digital sovereignty. GovTech ran in Durban under the banner “architect of its digital destiny”, the Minister set out a national sovereignty agenda, and the President had told a hyperscaler’s summit in July that sovereignty is now measured by “a nation’s ability to secure its data”.

Nearly all of it turns on one question: where – where the data centre stands, which border the bytes rest inside. For most enterprises that is already answered: their data is in South Africa. The harder question is whether it is theirs. Residency answers where. Sovereignty answers who.

Where

The where question is being answered for us, and answered well. Microsoft has run Azure regions in Johannesburg and Cape Town since 2019 and has committed a further R5.4 billion to South African cloud and AI infrastructure by the end of 2027. Google and Amazon have regions of their own. Even in-country processing for Microsoft 365 Copilot – prompts and responses handled inside the border – was promised to South Africa for 2026 last November; an April revision kept the 2026 date for five other countries and gave South Africa none.

Policy has gone the same way, deliberately. The National Policy on Data and Cloud that Cabinet approved in 2024 requires only government data touching national security to be stored inside the country, states that it imposes “no further data localisation requirements”, and leaves cross-border transfers to POPIA. PwC’s latest Africa cloud survey has 45 percent of organisations saying geopolitics now shapes their infrastructure decisions – and the adjustment, in most conversations I hear, is a question to the vendor about where the region is.

If sovereignty were an address, then, we would be close to done.

It is not. In July last year Microsoft’s legal director in France told a Senate inquiry, under oath, that he could not guarantee that data held for French public bodies would never be handed to the United States authorities without French consent – adding that it had never happened, and that the company is contractually bound to resist unfounded requests. It was an honest answer, and it was not Microsoft’s to change: the statute behind it is American law, not company policy, and every American provider that holds the data would have to give the same reply.

The response since has been engineering rather than promises: data boundaries, in-country processing, customer-held encryption keys. One analyst put the shift plainly this April: sovereignty in the cloud “is no longer simply about where data resides, it is about managing risks”.

Who

Strip the flags off the phrase and data sovereignty comes down to four questions a South African organisation can put to itself.

Who holds the keys? All three hyperscalers now let a customer encrypt its own data with keys it holds in its own vault. In my experience few South African enterprises have taken up the option, which means the answer, in practice, is “the vendor, on our behalf”.

Who can reach it? Sophos’s 2026 ransomware study, drawing on 135 South African organisations attacked in the past year, found that in 85 percent of cases the ransomware and the organisation’s most serious identity compromise were the same event – against 67 percent globally. The route into South African data is a credential that already had access. Sovereignty is a question about that credential.

Who patches the engine beneath it? A database inside the border on an unsupported version is not sovereign; it is exposed with a local address. SQL Server 2017 has twelve months of support left. Windows Server 2016 has three months.

And who else holds a copy? King V’s Principle 10 asks the board to manage the risks of “outsourced services, suppliers and third parties, including across jurisdictions”. It is this last question that September answered, loudly.

The Copies

Here is what I see in most estates, and I see it without looking hard.

A finance extract that runs every night from the ERP to a reporting server, because reporting was slowing production down in 2017. The server was never added to the backup schedule, its database engine is two versions behind the source, and its data is readable by a group called Everyone.

A customer table that exists once in the core system and then again in the CRM, the marketing platform, the loyalty programme, the identity-verification vendor’s platform, and a warehouse that was built to consolidate all of them and became a seventh copy instead.

A spreadsheet on the file share with forty thousand identity numbers in it, exported for a project in 2022 and attached to an email twice since.

Each of those is a place the data lives. Each has its own permissions, its own patch state, its own backup and its own jurisdiction. None of them appears in the asset register, because the asset register lists systems, and copies are not systems. Redgate’s June survey of 2,150 database professionals found 77 percent of organisations with no formal data governance process. The copy count in most estates is not known because it has never been asked for.

That is where sovereignty is lost – copy by copy, inside the border.

A Domestic Address

On 9 September the Dire Wolf ransomware group claimed to have taken 200 gigabytes of data from RelyComply, a South African provider of identity-verification and anti-money-laundering checks to regulated financial firms – “production databases and Amazon S3 cloud storage”, in the attackers’ own words, some 3.57 billion rows. RelyComply confirmed an incident and an investigation.

Within days, several regulated institutions were writing to their customers – and, where the law required it, to the Information Regulator – each able to say, truthfully, that its own systems had not been breached. One of the country’s largest banks was investigating whether the identity checks it runs at account opening were in scope. A fortnight earlier the same group had hit a vehicle-tracking company with more than two million subscribers; that data was on the dark web by 8 September.

The month’s third case reached further down the chain. A policy-administration provider to the life insurers disclosed that a June intrusion – an employee’s password reused on an unrelated site, a support-ticket system the provider was decommissioning – had exposed, by its own count, some 400,000 records belonging to the customers of around forty-five insurers. The policy databases were untouched; the data left in files. A ransom was paid for a promise to destroy it, and by 7 September the first insurer was on the leak site. The regulators then said the same thing twice. Under POPIA, the Information Regulator noted, the obligation “rests on the responsible party” – the insurer, not its supplier. Under Joint Standard 2, said the Prudential Authority, “the obligation, again, lies with the insurers”: the 24-hour clock is theirs, whichever server the data left from.

Craig Rosewarne of Wolfpack calls these “digital supply chain” or “hub-and-spoke” attacks: one provider, many clients. I would put it more plainly. In the identity-verification case the institutions had a South African supplier under a South African contract. Where the copy itself sat is another matter – the supplier’s own privacy notice, quite properly, allows processing in South Africa, the United Kingdom, the European Economic Area, the United States “or other countries” – and I doubt many of its clients could have said which. What none of them had was control over a copy of their own customers’ identities, and the difference arrived as a breach notification.

One thing follows. The way in varies – a reused password, a zero-day in a supplier’s application – but what leaves is always the same: the database, or, as in the administrator’s case, a copy of it in transit – an export, a transfer file, an attachment on a support ticket. The perimeter is where the attacker starts. It is not where the data is.

A Setting, Not a Resolution

Sovereignty is also decided in smaller rooms than the boardroom.

Take a Microsoft Fabric capacity in the South Africa North region, where every Fabric workload is available and OneLake storage rests inside the border. Copilot in Fabric is switched off in that tenant by default, because the Azure OpenAI service behind it runs in United States and European data centres. Microsoft documents this in plain language and ships the setting off, which is exactly right.

To use it, a Fabric administrator enables a tenant setting called “Data sent to Azure OpenAI can be processed outside your capacity’s geographic region, compliance boundary, or national cloud instance”. From that moment, prompts and results leave the country.

That is a sovereignty decision. In most organisations it is taken by an administrator on a Tuesday afternoon, because a dashboard needed the feature, and it is recorded nowhere a director will read. Microsoft’s part is in order – the default is right and the documentation is candid. The gap is on the customer’s side of the screen: who decides, against what policy, and where is it minuted.

The Sovereign Estate

An organisation that is sovereign over its data can do five things. It can count its copies – extracts, spreadsheets and suppliers included – and say who owns each one. It holds its own keys where the platform allows. It knows which credentials can reach personal information and has reviewed them this year. It knows the support status of every engine holding that information. And it knows what each supplier holds, under what terms, in which jurisdiction – and could take it all back if it had to.

Not one of those five is about a border. All five are about control, and all five are questions a board is now accountable for asking.

The national debate will run its course and produce what such debates produce – a policy, a tracker, more data centres, all of it welcome. The question that will actually be put to South African enterprises in the year ahead, by their boards, their insurers and the Regulator, is the other one. Who has it.

The Last Word

I have spent my working life at the layer where a country’s digital destiny is actually decided – the database, and the people who run it – and I have never seen sovereignty lost at a border. I have seen it lost in a nightly extract, a shared folder and a supplier’s schema, one copy at a time.

Residency is now something you can buy, and South Africa is a good place to buy it. Control is not for sale. It has to be counted, held and reviewed, and the organisations that do that this year will be the ones with an answer when the who question arrives.