Boards are comfortable with financial risk, legal risk and operational risk. Digital risk is where the discipline breaks down — it gets delegated to "IT," treated as technical, and never returns to the board in a language directors can govern. That is a governance failure, and increasingly a personal one.

King IV makes technology and information governance an explicit responsibility of the governing body — not something a board may delegate and forget. POPIA goes further: it designates an Information Officer who is, by default, the head of the organisation, and who carries real accountability for how personal information is protected. When a breach becomes a regulatory matter or a headline, "the IT team handled that" is not a defence a director wants to be relying on.

You don't need to become technical to govern this well. You need to be able to ask the right questions and recognise a weak answer. Here is the register.

The Seven Questions

Question 1 — Data & POPIA

Do we know exactly what personal information we hold, and can we prove we're POPIA-compliant?

A board should be able to say what personal information the organisation processes, where it lives, and who is accountable for it. If the honest answer is "not precisely," that is the finding. POPIA's eight conditions, a designated Information Officer, and a documented, defensible position are the baseline — and there is a 72-hour clock on reporting a qualifying breach.

Question 2 — Independent validation

When was our security last tested by an independent party — and what did they find?

"We have antivirus and a firewall" describes spending, not security. Only independent testing shows what an attacker could actually do. If the last real test was "never," the board is governing on assumption. A recent, independent penetration test is increasingly expected by insurers, tenders and enterprise clients too.

Question 3 — Resilience

Could we recover from a ransomware attack without paying — and how long would it take?

The right answer is a tested restore process and a known recovery time, not "we have backups somewhere." The board should know the recovery-time expectation for the systems the business cannot run without, because that number is the difference between an incident and an existential event.

Question 4 — Access & accountability

Who can access our most sensitive data — and would we know if that access were abused?

Least-privilege access and proper logging are what turn "one compromised laptop" into a contained event rather than a full breach. If access is broad and unlogged, the organisation cannot detect misuse, cannot investigate it, and cannot prove what happened afterwards.

Question 5 — AI governance

What AI is being used across our business, and is any of it governed?

Staff are already pasting company and client data into public AI tools, and systems are increasingly being built with AI assistance that nobody has reviewed. Both are live exposures. The board should know where AI touches the business and whether guardrails, policy and oversight exist — or whether "AI slop" is quietly accumulating in production.

Question 6 — Third-party & supplier risk

What is our exposure through the vendors and platforms we rely on?

Much of an organisation's real attack surface sits with its suppliers — the payroll provider, the cloud platform, the outsourced developer. A board should understand which third parties hold or touch its data, and whether that dependency has ever been examined rather than assumed.

Question 7 — Incident readiness

Do we have an incident-response plan the board has actually seen and tested?

A plan filed in a drawer that no one has rehearsed is not readiness — it is paperwork. The board should have seen the plan, know who decides what during a crisis, and know that the POPIA notification obligations are built into it. The middle of an incident is the wrong time to discover the plan is fiction.

How to read the answers: you are not scoring the technology — you are scoring whether the organisation can answer at all. Confident, specific, evidenced answers mean the risk is being governed. Vague answers, or answers that only IT can give, mean the board is exposed and doesn't yet know it.

This Is Oversight, Not Administration

None of these questions asks a director to configure a firewall. They ask whether the organisation knows its exposure, has tested its assumptions, and can act under pressure — which is precisely the board's job. The firms that handle a cyber incident or a regulator's enquiry well are almost never the ones with the most technology. They are the ones whose leadership was already asking these questions, calmly, on an ordinary Tuesday.

That is the work we do with boards and executive teams: translating digital risk into the language leadership can actually govern, testing the assumptions independently, and closing the gaps that turn up — before someone else finds them first.

Bring these questions to your next board meeting — with real answers.

We run a director-level digital-risk review: an independent, plain-language read of where you stand against exactly this register, and a prioritised plan to close the gaps.