A team reviews database security, access records, integrations, and support timelines on a large dashboard in a server-room meeting.
South Africa's new King V governance code is being read by many boards as a reporting chore. Johan Lamberts, managing director of Ascent Technology, argues in ITWeb that it is more than that. He says Principle 10 makes directors accountable for the database estate now, not for a paragraph in a 2027 annual report. His piece is an opinion article issued by a company that sells services in this area. Even so, the question it raises is one every Windows and SQL Server administrator will recognise: can you prove what you run, where the sensitive data sits, and who can reach it?

What King V actually says​

The Institute of Directors in South Africa (IoDSA) says King V was released on 31 October 2025 and supersedes King IV. It applies to financial years beginning on or after 1 January 2026, with early adoption encouraged. That makes 2026 the first governed year, and calendar-year companies are already most of the way through it.

King V is a governance code, not a statute. How it applies depends on the organisation and on other rules that bind it.

Lamberts points to Principle 10, "Data, information and technology". His reading rests on three points:

  • Accountability. He says the board should be accountable for the effective, compliant and ethical management and control of data and information. That covers acquisition, creation, use, dissemination and disposal.
  • Delegation. The code lets boards delegate to the risk committee, as he notes. In his reading that doesn't remove the board's accountability.
  • Assurance. Practice 104 asks the board to consider periodic assurance. He treats this as the part most boards will skip.

His argument that a policy and a paragraph aren't enough is commentary, not a requirement written into the code. It is a reasonable reading, but it is his.

The four questions he says will land on IT​

Lamberts says directors won't answer Principle 10 themselves. The questions will travel down to the CIO, the head of data and whoever runs the databases. He frames them as follows.

  1. Where does the sensitive data sit? He means tables, columns, reporting-layer copies and file-share extracts, not just an asset-register systems list.
  2. Who has standing access? He cites service accounts with DBA rights granted for a project and never withdrawn.
  3. Which engines holding the data are still supported?
  4. Who else touches the data? That means outsourced DBAs, hosting providers, reporting tools and payroll bureaus.

The third question is where Microsoft lifecycle facts matter, and they can be checked.

The Microsoft support clock​

Lamberts names three Microsoft products. Here is what Microsoft's documentation and other reporting establish.

  • SQL Server 2016 reached the end of extended support on 14 July 2026. Microsoft's FAQ lists that date, with Extended Security Updates (ESUs) available until 17 July 2029.
  • What changes after that date. A Microsoft Tech Community post says servers keep running and applications keep connecting. What changes is the risk profile. Without ESUs there are no security updates, hotfixes or support.
  • ESU limits. Enterprise and Standard editions of SQL Server 2016 are eligible. Microsoft's FAQ says ESUs cover only Critical-rated security updates, for at most three years. It adds that third-party application control tools are not a replacement for product security fixes.
  • Support tickets. On-premises SQL Server 2016 customers without ESUs can't log a support ticket, even with a support plan, according to the same FAQ.
  • A cost trap. One consultancy write-up says SQL Server 2014's free-ESU-on-Azure-VM route does not carry over to SQL Server 2016. It cites Microsoft Learn on this. Check your own licensing, because Microsoft's FAQ says ESU eligibility and billing depend on how the instance is hosted.
  • Windows Server 2016 follows on 12 January 2027. Microsoft's 2027 lifecycle list shows the same date for IIS 10 on Windows Server 2016, Hyper-V Server 2016 and several System Center 2016 products.
  • SQL Server 2017 ends support on 12 October 2027. On 5 October 2026 that is just over a year away. Lamberts' "13 months" is slightly generous.

The distinction matters in an audit. SQL Server 2016 is already out of support. Windows Server 2016 is days-of-calendar away from it, not yet there. An inventory that lumps these together will mislead a board.

Where the argument needs care​

Several of the supporting claims could not be verified, and one is wrong on the evidence available.

  • Joint Standard 2 timing. Lamberts says the 12-month implementation period ended in June, implying June 2026. The official joint communication and the Reserve Bank's later strategy point to an effective date of 1 June 2025 instead. Treat the June 2026 claim as likely mistaken. The standard also applies to specified financial institutions, not to every supplier.
  • The Information Regulator's numbers. He cites 788 security-compromise notifications in the first quarter of 2026. We found no official source for that figure. A Deputy Justice Minister's 30 July 2026 speech, citing the Regulator, gives different figures. It reported 2,375 notifications in 2024/25 and 2,693 in 2025/26, with 800 from April 2026 to the date of the speech. Those periods differ from his, so the figures shouldn't be mixed.
  • The enforcement notice. The Regulator's enforcement page does list a notice against Central Johannesburg TVET College dated 20 May 2026. It was issued under section 95 of the Protection of Personal Information Act (POPIA). That supports his folder-level example. We couldn't confirm that it was the Regulator's "first" notice of 2026, so don't repeat that label.
  • Industry statistics. The Redgate survey figures, Sophos's identity-compromise percentages and Cyanre's 18-day dwell time are his claims. We didn't locate the original reports, so their sampling and scope are unchecked.
  • Microsoft licensing. His remarks about renewal terms and currency adjustments are opinion, not verified product facts.

There is also a counterpoint. A well-run risk committee with a current policy is not automatically non-compliant. King V is principles-based, and "apply and explain" gives boards room to justify different approaches. Lamberts' claim that policies alone fall short is a strong argument, not a finding from a regulator.

A practical evidence pack for admins​

None of this is a verbatim King V mandate. It is a sensible way to turn the governance language into artefacts you can show someone. It also lines up with POPIA's section 19 expectation of reasonable technical and organisational safeguards that are verified and updated.

  • Data map. List databases, reporting copies and file-share extracts that hold personal or sensitive information, with an owner for each.
  • Version register. Record the product, edition, service pack, host OS and support end date for every SQL Server and Windows Server instance. Mark whether ESUs are active.
  • Access review. Document who holds sysadmin-level and other standing rights, including service accounts. Keep minutes showing the review took place.
  • Third-party list. Name every outsourced DBA, host and connected tool with access, and the contract terms covering security.
  • Recovery and logging. Keep records of a restore test that was actually run, and of audit logging that would show what happened after an incident.
  • Upgrade path. For SQL Server 2016, Microsoft's own guidance points to SQL Server 2025, Azure SQL Managed Instance, SQL Server on Azure VMs or ESUs. The route you choose should be written down, with a date.

The bottom line​

The strongest part of Lamberts' argument is the simplest. Evidence has to exist before someone asks for it. Some of his numbers need checking, and his deadline for Joint Standard 2 looks wrong. The Microsoft support dates are solid. If your estate still runs SQL Server 2016, you are already past the end-of-support line. If it runs Windows Server 2016, you have until 12 January 2027.

 

References

  1. The board now owns the database - ITWeb ITWeb 2026-10-05T09:00:00+00:00
  2. Publications-King V - The Institute of Directors in South Africa NPC iodsa.co.za
  3. SQL Server 2016 Reaches End of Support: A Customer Engineer's Perspective on What's Next techcommunity.microsoft.com