Boards are comfortable with financial risk, legal risk and operational risk. Digital risk is where the discipline breaks down — it gets delegated to "IT," treated as technical, and never returns to the board in a language directors can govern. That is a governance failure, and increasingly a personal one.
King IV makes technology and information governance an explicit responsibility of the governing body — not something a board may delegate and forget. POPIA goes further: it designates an Information Officer who is, by default, the head of the organisation, and who carries real accountability for how personal information is protected. When a breach becomes a regulatory matter or a headline, "the IT team handled that" is not a defence a director wants to be relying on.
You don't need to become technical to govern this well. You need to be able to ask the right questions and recognise a weak answer. Here is the register.
The Seven Questions
Question 1 — Data & POPIA
Do we know exactly what personal information we hold, and can we prove we're POPIA-compliant?
A board should be able to say what personal information the organisation processes, where it lives, and who is accountable for it. If the honest answer is "not precisely," that is the finding. POPIA's eight conditions, a designated Information Officer, and a documented, defensible position are the baseline — and there is a 72-hour clock on reporting a qualifying breach.
Question 2 — Independent validation
When was our security last tested by an independent party — and what did they find?
"We have antivirus and a firewall" describes spending, not security. Only independent testing shows what an attacker could actually do. If the last real test was "never," the board is governing on assumption. A recent, independent penetration test is increasingly expected by insurers, tenders and enterprise clients too.
Question 3 — Resilience
Could we recover from a ransomware attack without paying — and how long would it take?
The right answer is a tested restore process and a known recovery time, not "we have backups somewhere." The board should know the recovery-time expectation for the systems the business cannot run without, because that number is the difference between an incident and an existential event.
Question 4 — Access & accountability
Who can access our most sensitive data — and would we know if that access were abused?
Least-privilege access and proper logging are what turn "one compromised laptop" into a contained event rather than a full breach. If access is broad and unlogged, the organisation cannot detect misuse, cannot investigate it, and cannot prove what happened afterwards.
Question 5 — AI governance
What AI is being used across our business, and is any of it governed?
Staff are already pasting company and client data into public AI tools, and systems are increasingly being built with AI assistance that nobody has reviewed. Both are live exposures. The board should know where AI touches the business and whether guardrails, policy and oversight exist — or whether "AI slop" is quietly accumulating in production.
Question 6 — Third-party & supplier risk
What is our exposure through the vendors and platforms we rely on?
Much of an organisation's real attack surface sits with its suppliers — the payroll provider, the cloud platform, the outsourced developer. A board should understand which third parties hold or touch its data, and whether that dependency has ever been examined rather than assumed.
Question 7 — Incident readiness
Do we have an incident-response plan the board has actually seen and tested?
A plan filed in a drawer that no one has rehearsed is not readiness — it is paperwork. The board should have seen the plan, know who decides what during a crisis, and know that the POPIA notification obligations are built into it. The middle of an incident is the wrong time to discover the plan is fiction.
This Is Oversight, Not Administration
None of these questions asks a director to configure a firewall. They ask whether the organisation knows its exposure, has tested its assumptions, and can act under pressure — which is precisely the board's job. The firms that handle a cyber incident or a regulator's enquiry well are almost never the ones with the most technology. They are the ones whose leadership was already asking these questions, calmly, on an ordinary Tuesday.
That is the work we do with boards and executive teams: translating digital risk into the language leadership can actually govern, testing the assumptions independently, and closing the gaps that turn up — before someone else finds them first.