Board Members in South Africa: Why Cyber Risk Is Now Your Problem
Cyber risk for board members in South Africa is no longer a technical problem that stays in the IT department. It is now a governance problem that sits at the boardroom table. Regulators, shareholders and the courts are asking a clear question: who is accountable when personal information is exposed, operations are disrupted or customer trust is lost? This article is for directors, executives and senior leaders who need to understand what cyber risk means for their fiduciary duty and how to ask the right questions of management.
A recent breach raises an uncomfortable question
South Africa has seen a string of high-profile data breaches in recent years. Organisations in banking, healthcare, retail and government have lost personal information, faced ransomware demands and struggled to recover public confidence. When a breach happens, the immediate response often focuses on servers, passwords and firewalls. But the longer question is harder to answer: who is responsible?
Boards that treat cyber risk as an operational issue handled by the CIO are finding that accountability does not stop at the IT department. Customers, regulators and the media want to know whether leadership took reasonable steps to protect the organisation and the people whose data it holds.
The governance shift: King IV, POPIA and fiduciary duty
King IV defines corporate governance in South Africa and makes it clear that boards are responsible for governing information and technology. Principle 12 states that the board should govern technology and information in a way that supports the organisation’s strategic objectives and resilience. That includes cyber risk.
The Protection of Personal Information Act places a direct duty on responsible parties to secure personal information. Directors who fail to act can face administrative fines, reputational damage and personal liability. This is not about becoming a security engineer. It is about exercising the same fiduciary care that boards apply to financial risk, legal risk and operational risk.
Why cyber risk cannot be delegated to IT alone
IT teams understand the technical controls. They manage firewalls, endpoint protection, patch management and backups. But cyber risk is broader than technical controls. It includes whether the board has approved a security strategy, whether the organisation has tested its incident response plan, whether legal and communications teams are ready for a breach, and whether third parties are being managed with the same care as internal systems.
Boards that simply ask IT whether everything is secure are not governing risk. They are accepting assurance they do not fully understand. The gap between technical work and organisational accountability is where governance failures happen.
Five questions boards should ask management
Boards do not need to design security architectures. They do need to ask management clear, evidence-based questions. Here are five practical questions that can be raised in any board meeting.
1. Do we have a tested incident response plan?
A plan that has never been tested is a plan that will fail under pressure. Ask management when the plan was last exercised, who leads the response, how legal and communications are involved, and how the board will be informed during an incident.
2. What is our compliance posture for POPIA and ISO 27001?
Ask how the organisation addresses its POPIA duties and whether it maps its information security management system to ISO 27001. Use auditor and board language. The goal is not a certificate on the wall. The goal is a defensible, documented approach to managing information risk.
3. How do we manage third-party and supply chain risk?
Many breaches start with a supplier, cloud provider or outsourced service. Ask how management assesses vendor security, what contractual protections are in place, and whether critical third parties are covered by the same risk standards as internal operations.
4. Is our cyber insurance aligned with our actual risk?
Insurance is not a substitute for controls, but it is part of a mature risk strategy. Ask what the policy covers, what exclusions apply, and whether the insurer has reviewed the organisation’s security posture.
5. Does management report cyber risk in terms the board can act on?
Boards need risk reporting that supports decisions, not just technical metrics. Ask for a clear view of the organisation’s top cyber risks, the controls that address them, the residual risk that remains, and the decisions the board needs to make.
How Hayshack helps boards map cyber risk to governance obligations
Hayshack works with South African boards and executives to connect cyber risk with governance obligations. We do not certify compliance. Instead, we help organisations understand where they stand against King IV, POPIA and ISO 27001 and build practical roadmaps to close gaps.
Our engagements are designed for boards: clear reporting, practical recommendations and language that directors can use in board packs and risk committee discussions. Whether the board needs an independent assessment, support for the risk committee or help preparing for an external audit, we frame our work in governance terms so that cyber risk can be managed at the right level. Explore our governance and risk services.
Start the conversation before an incident forces it
The boards that handle cyber incidents best are the ones that started asking questions early. Waiting for a breach to put cyber risk on the agenda is the most expensive way to learn governance.
If your board is ready to review its cyber risk posture, contact Hayshack. We help South African directors and executives turn cyber risk from a technical uncertainty into a governed, board-level responsibility.







