Newsletter Subscribe
Enter your email address below and subscribe to our newsletter


It’s a well-established fact that one of the greatest assets of business today is information. And while the value of data – in its various digital forms – cannot be disputed, it also presents organisations with the daunting task of having to protect this data from theft, misuse and negligent management.
Companies must not only understand the nature of the threats to which they are exposed, and the new breed of cybercriminals attached to these threats, they must also comprehend how to effectively evolve and implement robust governance structures, as well as strong policies, procedures and physical controls to combat the ever-changing nature of the cyber risk landscape.
It’s the new norm that people must be able to work anywhere and everywhere, with access to multiple and diverse environments, including internal networks in addition to cloud applications and services. This might be good for productivity, but can prove to be a living nightmare for IT security teams. Hence, while there are a number of effective tools that can be implemented and configured to address the necessary areas of vulnerability, it has become non-negotiable to execute a holistic, well-defined information governance and management framework.
Within this framework, companies are then able to make use of technology and resources to establish the right policies, procedures and reporting structures across the entire IT landscape, ensuring that all threats are identified and that proactive notifications and escalations keep management informed of issues prior to the occurrence of any possible loss or reputational damage. Here, businesses are also able to clearly define IT objectives and ensure that they are aligned to the organisation’s strategic and operational goals.
It’s important to remember that governance is not a box-ticking exercise. It’s about doing the right things; about gaining clarity around authority and responsibilities assigned, being accountable, acting mindfully and engaging in good sound ethical practices. These are the cornerstones of good governance.
Unfortunately, as we have seen all too often in the media, a company cannot claim to have the best corporate governance code in the world and still tolerate bad behaviour – good governance needs good behaviour. Sadly, the phrase “tone from the top” is often more aptly translated as “do as I say, not as I do” at the topmost levels of business.
Good governance does start at the top, as it sets the tone that filters down through the rest of the organisation, and those companies that start on this basis, anchored in ethical leadership, structures and practices such as those recommended by the King IV Report on Corporate Governance for South Africa, 2016, will effectively lead not only the governance race, but the race to remain a sustainable and prosperous company into the future.
By Nicky Downing, compliance specialist at CentralCloud