v3.26.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Jun. 30, 2026
Cybersecurity Risk Management Strategy And Governance [Line Items]  
Cybersecurity Risk Management Processes For Assessing Identifying And Managing Threats [Text Block]
We
operate
in
the
Southern
African
fintech
industry,
which
is
subject
to
cybersecurity
risks
that
could
adversely
affect
our
business, financial
condition and
results of
operations,
including intellectual
property theft,
fraud,
extortion, harm
to employees
or
customers, violations of privacy laws, litigation and legal risk, regulatory
scrutiny and reputational harm.
We
have
implemented
a risk-based approach
to assessing, identifying
and managing cybersecurity
threats that could
affect our
business, information systems
and data. These
processes are integrated
into our broader
enterprise risk management
framework, and
cybersecurity risks are assessed
and prioritized alongside our
other principal enterprise risks.
Our cybersecurity program
is informed
by
recognized
standards
and
regulatory
requirements
applicable
to
our
business,
including
PCI
DSS,
the
NIST
Cybersecurity
Framework, SARB / Prudential Authority requirements applicable to cybersecurity
and cyber-resilience within the National Payment
System, and
the CIS
Critical Controls.
During the
year,
we continued
to mature
our cybersecurity
program, including
through our
transition
to
NIST
CSF
2.0,
further
development
of
cyber
risk
governance
processes,
and
continued
execution
of
divisional
cybersecurity roadmaps.
We
periodically conduct
third
-party security
risk assessments
to
assess
the potential
impact and
likelihood of
cyber scenarios
and
to inform
appropriate mitigation
strategies and
controls. We
use a
combination of
technical, administrative
and organizational
controls to manage cybersecurity risk, including
endpoint and network monitoring, security operations monitoring,
identity and access
controls, data protection tools,
vulnerability management, penetration testing, threat
intelligence, backup and recovery
procedures, and
cyber awareness
and training
programs. We
also conduct
periodic phishing
simulations and
crisis simulations
to support
workforce
preparedness and incident-response readiness.
We maintain incident-response processes designed to provide a consistent basis for the identification, escalation, assessment
and
response
to
cybersecurity
incidents.
During
the
year,
we
issued
an
updated
Group
Incident
Response
Plan
to
support
divisional
incident-response playbooks.
We
also
maintain
processes
to
oversee
cybersecurity
risks
associated
with
third-party
service
providers
that
have
access
to
personal, confidential
or proprietary
information or
support significant
business processes.
During the
year,
we enhanced
our third-
party risk management processes, including additional due diligence and assurance requirements
for certain service providers and the
establishment of a
cross-functional working group involving
procurement, finance, risk and
compliance, legal and
information security
personnel to support vendor risk oversight.
Management,
led
by
our
Group
Chief
Information
Security
Officer
(“
CISO
”)
and
supported
by
information
security,
risk,
compliance,
legal
and
finance
personnel,
is
responsible
for
assessing
and
managing
cybersecurity
risks.
Management
receives
information regarding cybersecurity risks through security monitoring, risk assessments, vulnerability assessments, incident
-response
processes,
third-party
risk
reviews
and
reports
from
internal
and
external
security
providers.
Material
cybersecurity
matters
are
escalated to senior management and, where appropriate, to the Audit Committee
and Board.
The Board oversees cybersecurity
risk through the Audit
Committee.
The Audit Committee receives
quarterly reports from
the
Group CISO regarding
cybersecurity posture, compliance
activities, progress against
the Group cybersecurity
strategy and roadmap,
third-party risk,
and material
cybersecurity incidents,
if any,
and related
remediation.
The Group
CISO is
a qualified
cybersecurity
professional
with
over
25
years
of
experience
and
holds
a
Master’s
in
Information
Security
from
Royal
Holloway,
University
of
London.
The Audit Committee reports to the Board on cybersecurity matters.
Cybersecurity Risk Management Processes Integrated Flag true
Cybersecurity Risk Management Processes Integrated [Text Block]
We
have
implemented
a risk-based approach
to assessing, identifying
and managing cybersecurity
threats that could
affect our
business, information systems
and data. These
processes are integrated
into our broader
enterprise risk management
framework, and
cybersecurity risks are assessed
and prioritized alongside our
other principal enterprise risks.
Our cybersecurity program
is informed
by
recognized
standards
and
regulatory
requirements
applicable
to
our
business,
including
PCI
DSS,
the
NIST
Cybersecurity
Framework, SARB / Prudential Authority requirements applicable to cybersecurity
and cyber-resilience within the National Payment
System, and
the CIS
Critical Controls.
During the
year,
we continued
to mature
our cybersecurity
program, including
through our
transition
to
NIST
CSF
2.0,
further
development
of
cyber
risk
governance
processes,
and
continued
execution
of
divisional
cybersecurity roadmaps.
Cybersecurity Risk Management Third Party Engaged Flag true
Cybersecurity Risk Third Party Oversight And Identification Processes Flag true
Cybersecurity Risk Materially Affected Or Reasonably Likely To Materially Affect Registrant Flag false
Cybersecurity Risk Materially Affected Or Reasonably Likely To Materially Affect Registrant [Text Block]
As of the date of
this Annual Report, we do
not
believe that risks from cybersecurity threats, including as
a result of any previous
cybersecurity
incidents,
have
materially
affected
or
are
reasonably
likely
to
materially
affect
the
Company,
including
its
business
strategy,
results of operations or
financial condition.
Cybersecurity Risk Board Of Directors Oversight [Text Block]
The Board oversees cybersecurity
risk through the Audit
Committee.
Cybersecurity Risk Board Committee Or Subcommittee Responsible For Oversight [Text Block]
The Audit Committee receives
quarterly reports from
the
Group CISO regarding
cybersecurity posture, compliance
activities, progress against
the Group cybersecurity
strategy and roadmap,
third-party risk,
and material
cybersecurity incidents,
if any,
and related
remediation.
Cybersecurity Risk Process For Informing Board Committee Or Subcommittee Responsible For Oversight [Text Block]
The Board oversees cybersecurity
risk through the Audit
Committee.
The Audit Committee receives
quarterly reports from
the
Group CISO regarding
cybersecurity posture, compliance
activities, progress against
the Group cybersecurity
strategy and roadmap,
third-party risk,
and material
cybersecurity incidents,
if any,
and related
remediation.
The Group
CISO is
a qualified
cybersecurity
professional
with
over
25
years
of
experience
and
holds
a
Master’s
in
Information
Security
from
Royal
Holloway,
University
of
London.
The Audit Committee reports to the Board on cybersecurity matters.
Cybersecurity Risk Role Of Management [Text Block]
Management,
led
by
our
Group
Chief
Information
Security
Officer
(“
CISO
”)
and
supported
by
information
security,
risk,
compliance,
legal
and
finance
personnel,
is
responsible
for
assessing
and
managing
cybersecurity
risks.
Management
receives
information regarding cybersecurity risks through security monitoring, risk assessments, vulnerability assessments, incident
-response
processes,
third-party
risk
reviews
and
reports
from
internal
and
external
security
providers.
Material
cybersecurity
matters
are
escalated to senior management and, where appropriate, to the Audit Committee
and Board.
Cybersecurity Risk Management Positions Or Committees Responsible Flag true
Cybersecurity Risk Management Positions Or Committees Responsible [Text Block]
Group
Chief
Information
Security
Officer
(“
CISO
”)
Cybersecurity Risk Management Expertise Of Management Responsible [Text Block]
The Group
CISO is
a qualified
cybersecurity
professional
with
over
25
years
of
experience
and
holds
a
Master’s
in
Information
Security
from
Royal
Holloway,
University
of
London.
Cybersecurity Risk Process For Informing Management Or Committees Responsible [Text Block]
Management
receives
information regarding cybersecurity risks through security monitoring, risk assessments, vulnerability assessments, incident
-response
processes,
third-party
risk
reviews
and
reports
from
internal
and
external
security
providers.
Material
cybersecurity
matters
are
escalated to senior management and, where appropriate, to the Audit Committee
and Board.
Cybersecurity Risk Management Positions Or Committees Responsible Report To Board Flag true