v3.26.3
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Jun. 30, 2026
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] Cybersecurity Risk Management and Strategy
Processes for identifying and assessing material cybersecurity risks
DRDGOLD's operations rely on digital systems and infrastructure to support mining, processing, renewable energy and corporate
activities. The Group has established processes to identify, assess and manage cybersecurity risks that could affect its operations,
assets, information systems or stakeholders. Cybersecurity risks are evaluated through periodic risk assessments performed by the
Information Technology and Risk & Assurance functions using tools and methodologies aligned with recognised cybersecurity
frameworks, including ISO/IEC 27001, the NIST Cybersecurity Framework and the CIS Critical Security Controls. These assessments
consider threats to information systems, operational technology, data confidentiality, system availability and third-party connectivity.
The Group's cybersecurity programme incorporates continuous monitoring activities, employee awareness training, vulnerability
identification, control self-assessments and independent assurance reviews. An external cybersecurity assurance provider is
engaged through the Combined Assurance Framework to evaluate the effectiveness of cybersecurity risk management processes
and key controls.
Integration into enterprise risk management
Cybersecurity risks are integrated into DRDGOLD's Enterprise Risk Management ("ERM") framework and are assessed using the
same risk identification, evaluation, mitigation and reporting processes applied to other strategic, operational, financial and
compliance risks. Cybersecurity risks are recorded, monitored and reported through the Group's risk management processes and are
considered when evaluating the Group's overall risk profile and risk appetite.
The Group also evaluates cybersecurity risks associated with third-party service providers and other external parties that have access
to its systems or data. Critical vendors are required to provide assurance regarding their cybersecurity controls through independent
assurance reports or cybersecurity assessments. The results of these assessments are incorporated into the Group's broader risk
management processes.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] Integration into enterprise risk management
Cybersecurity risks are integrated into DRDGOLD's Enterprise Risk Management ("ERM") framework and are assessed using the
same risk identification, evaluation, mitigation and reporting processes applied to other strategic, operational, financial and
compliance risks. Cybersecurity risks are recorded, monitored and reported through the Group's risk management processes and are
considered when evaluating the Group's overall risk profile and risk appetite.
The Group also evaluates cybersecurity risks associated with third-party service providers and other external parties that have access
to its systems or data. Critical vendors are required to provide assurance regarding their cybersecurity controls through independent
assurance reports or cybersecurity assessments. The results of these assessments are incorporated into the Group's broader risk
management processes.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] Board of directors oversight of cybersecurity risks
The Board oversees cybersecurity risk as part of its broader responsibility for risk governance. Oversight is delegated to the Risk
Committee, which receives periodic reports regarding cybersecurity risks, emerging threat trends, control effectiveness and
significant incidents, if any. The Risk Committee monitors management's processes for identifying, assessing and managing
cybersecurity risks and reports significant matters to the Board.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] The Board oversees cybersecurity risk as part of its broader responsibility for risk governance. Oversight is delegated to the Risk
Committee, which receives periodic reports regarding cybersecurity risks, emerging threat trends, control effectiveness and
significant incidents, if any. The Risk Committee monitors management's processes for identifying, assessing and managing
cybersecurity risks and reports significant matters to the Board.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] Oversight is delegated to the Risk
Committee, which receives periodic reports regarding cybersecurity risks, emerging threat trends, control effectiveness and
significant incidents, if any.
Cybersecurity Risk Role of Management [Text Block] Management oversight of cybersecurity risks
Management is responsible for assessing and managing cybersecurity risks. Responsibility for cybersecurity governance is led by the
Head of Cybersecurity ("HCS"). The HCS oversees the Group's cybersecurity strategy, risk management activities and incident
response capabilities, and is responsible for the day-to-day management of cybersecurity risks, implementation of security controls
and remediation of identified vulnerabilities and control deficiencies.
Management receives information regarding cybersecurity risks and control effectiveness through ongoing monitoring activities, risk
assessments, assurance reviews and incident management processes. Cybersecurity matters are periodically reported to executive
management and considered as part of the Group's broader risk management and business resilience processes.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Management is responsible for assessing and managing cybersecurity risks. Responsibility for cybersecurity governance is led by the Head of Cybersecurity ("HCS").
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Management is responsible for assessing and managing cybersecurity risks. Responsibility for cybersecurity governance is led by the
Head of Cybersecurity ("HCS"). The HCS oversees the Group's cybersecurity strategy, risk management activities and incident
response capabilities, and is responsible for the day-to-day management of cybersecurity risks, implementation of security controls
and remediation of identified vulnerabilities and control deficiencies.
Management receives information regarding cybersecurity risks and control effectiveness through ongoing monitoring activities, risk
assessments, assurance reviews and incident management processes. Cybersecurity matters are periodically reported to executive
management and considered as part of the Group's broader risk management and business resilience processes.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] The HCS oversees the Group's cybersecurity strategy, risk management activities and incident
response capabilities, and is responsible for the day-to-day management of cybersecurity risks, implementation of security controls
and remediation of identified vulnerabilities and control deficiencies.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true