Environmental, Social and Governance (ESG) discussions in South African boards generally default to carbon, community impact and governance process. While those remain essential, they do not tell the full story of organisational sustainability.
A business may define sustainability narrowly. However, it still fails if it cannot protect data and recover quickly from cyber disruption in a digital economy. As a result, boards now expand their thinking. They increasingly include cyber maturity as a key disclosure within the ‘S’ and ‘G’ of ESG. This shift aligns with treating cybersecurity as a sustainability metric.
Cybersecurity already maps onto existing reporting structures. These include the JSE’s Sustainability Disclosure Guidance. The guidance explains how sustainability-related risks link to enterprise value. It also links them to the quality of information available to investors and stakeholders.
In this way, cyber risk functions as business continuity risk. It also operates as a governance risk. In addition, it serves as a valuation criterion. This reinforces treating cybersecurity as a sustainability metric in practical decision-making.
Investors are watching
Investors now pay closer attention to operational resilience. They assess whether companies can withstand shocks. They also examine how firms protect sensitive information and manage digital dependencies responsibly.
Global investor sentiment confirms this trend. PwC’s 2025 Global Investor Survey found that 55% of investors and analysts view cyber risk exposure as high or extreme. In addition, 88% of investors call on executives to increase capital allocation to cybersecurity. This demand reinforces treating cybersecurity as a sustainability metric across investment decisions.
Financial consequences also matter significantly. IBM’s Cost of a Data Breach Report 2025 estimated the global average cost of a breach at $4.4 million. In South African terms, this equals almost R75 million.
The report also warns that AI adoption without proper governance increases exposure and cost. Even when organisations absorb direct costs, second-order effects persist. These include regulatory scrutiny, weakened customer confidence, reputational damage and the long recovery period required to rebuild trust.
Expanding the ‘S’ and ‘G’ in the cyber context
Although the ‘E’ in ESG often dominates discussion, cyber risk sits firmly within both the ‘S’ and the ‘G’. A breach represents a failure in social responsibility and governance discipline.
Within the Social (S) pillar, a cyberattack breaks the social contract between a company and its stakeholders. When customer data leaks, individuals face privacy violations immediately. They may also suffer financial loss or identity theft.
The social cost extends further. Companies lose brand equity permanently. They also risk losing the informal licence to operate that depends on public trust. In South Africa, where trust develops slowly, this damage often lasts longer than financial recovery. This dynamic strengthens treating cybersecurity as a sustainability metric, because social trust directly influences long-term viability.
From a Governance (G) perspective, cybersecurity tests fiduciary duty. Boards must maintain clear visibility of digital risks. They must also demonstrate a structured response capability.
Strong governance requires more than a firewall. It demands cyber-integrity. This includes transparent reporting on data handling. It also includes clarity on access controls and third-party supply chain resilience. If a board cannot explain its cyber-risk posture to shareholders, it fails its governance mandate. This failure further undermines treating cybersecurity as a sustainability metric in credible ESG reporting.
Boardroom responsibility
The King IV Report on Corporate Governance already defines the board’s responsibility for technology and information oversight. It emphasises alignment between technology governance and strategic objectives.
The Protection of Personal Information Act (POPIA) reinforces this responsibility. It requires organisations to notify the Information Regulator and affected individuals after a data breach.
Together, these frameworks increase accountability pressure. Boards must oversee cyber risk internally. However, they also face external scrutiny through mandatory disclosure. This environment makes treating cybersecurity as a sustainability metric a practical governance requirement rather than a theoretical concept.
Cyber to the centre of the ESG story
Organisations that respond effectively break down silos between cyber, compliance, risk and sustainability. They adopt a more rigorous understanding of exposure and dependency on third parties.
Cyber maturity now forms part of modern corporate resilience. It directly affects governance quality, stakeholder confidence, and an organisation’s ability to absorb shocks.


For South African companies, especially those in regulated or data-intensive sectors, this shift has already begun. Cybersecurity and ESG now operate as interconnected indicators of long-term sustainability and resilience. Ultimately, a company cannot credibly claim to be future-fit, well governed, or sustainable if its digital foundations remain fragile.
Richard Ford | Group CTO | Integrity360 | mail me |



























