Risk Management and Strategy Sasol considers cybersecurity as a top risk and has mature governance and assurance management processes in place to provide oversight over the following: | ● | Identification and understanding of the risk; |
| ● | Implementation of preventative and corrective controls; |
| ● | Execution and monitoring of mitigating controls; |
| ● | Governance, assurance, and reporting of the process’s efficacy; and |
| ● | Continuous analysis and improvement of our cybersecurity processes to ensure we are able to respond to an ever-changing threat landscape. |
To further support this, our governance uses multiple levels of assurance by segregated and independent parties, consisting of: | ● | Level 1 & 2 risk measures which focuses on assurance activities performed by employees and management within the function; |
| ● | Level 3 assurance, which is performed by independent internal audit function; |
| ● | Level 4 assurance, which is done by external independent assurance providers; and finally |
| ● | Level 5 assurance is the accountability of the Sasol Group Executive Committee (GEC), who are the oversight body guiding cybersecurity posture, risk mitigation and information security controls. |
In addition, several penetration, red-teaming, and simulation exercises are conducted annually to continuously strengthen governance controls. Refer to “Item 3.D. Risks related to information management” on cybersecurity risks. From a framework perspective, Sasol aligns with the NIST Cybersecurity Framework (CSF) and Center for Internet Security (CIS) control benchmarks. A well-defined Incident response plan is in place, which is tested and continuously improved on a quarterly basis. Sasol’s Cybersecurity team makes use of threat intelligence, penetration testing, red-teaming, third party risk management and vulnerability management to reduce Sasol’s attack surface, in addition to several mechanisms for detecting and responding to anomalies. Sasol leverages a combination of in-house and external cybersecurity expertise to detect, protect, respond and remediate cyber threats. The Chief Information and Digital Officer (CIDO) and Head of Cybersecurity are accountable for reporting to the GEC and the Audit Committee through the Information Management and Digital Executive committee on the prevention, detection, mitigation and remediation of all cybersecurity threats and incidents. Sasol has not experienced a cybersecurity incident that had a material impact on our business strategy, operations, or financial reporting in the last financial year. Despite this, we are cognisant that cyber-attacks are increasing in both volume and sophistication, particularly with the growing use of AI to enhance adversary capabilities. In response to the evolving cyber threat landscape, Sasol is continuously strengthening its cyber security posture by evolving its control environment, actively leveraging AI to enhance detection and response across Sasol’s defence-in-depth strategy.
|