Cybersecurity Risk Management and Strategy Disclosure |
12 Months Ended |
|---|---|
Jun. 30, 2026 | |
| Cybersecurity Risk Management, Strategy, and Governance [Line Items] | |
| Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] | Cybersecurity Risk Management and Strategy Processes for identifying and assessing material cybersecurity risks DRDGOLD's operations rely on digital systems and infrastructure to support mining, processing, renewable energy and corporate activities. The Group has established processes to identify, assess and manage cybersecurity risks that could affect its operations, assets, information systems or stakeholders. Cybersecurity risks are evaluated through periodic risk assessments performed by the Information Technology and Risk & Assurance functions using tools and methodologies aligned with recognised cybersecurity frameworks, including ISO/IEC 27001, the NIST Cybersecurity Framework and the CIS Critical Security Controls. These assessments consider threats to information systems, operational technology, data confidentiality, system availability and third-party connectivity. The Group's cybersecurity programme incorporates continuous monitoring activities, employee awareness training, vulnerability identification, control self-assessments and independent assurance reviews. An external cybersecurity assurance provider is engaged through the Combined Assurance Framework to evaluate the effectiveness of cybersecurity risk management processes and key controls. Integration into enterprise risk management Cybersecurity risks are integrated into DRDGOLD's Enterprise Risk Management ("ERM") framework and are assessed using the same risk identification, evaluation, mitigation and reporting processes applied to other strategic, operational, financial and compliance risks. Cybersecurity risks are recorded, monitored and reported through the Group's risk management processes and are considered when evaluating the Group's overall risk profile and risk appetite. The Group also evaluates cybersecurity risks associated with third-party service providers and other external parties that have access to its systems or data. Critical vendors are required to provide assurance regarding their cybersecurity controls through independent assurance reports or cybersecurity assessments. The results of these assessments are incorporated into the Group's broader risk management processes.
|
| Cybersecurity Risk Management Processes Integrated [Flag] | true |
| Cybersecurity Risk Management Processes Integrated [Text Block] | Integration into enterprise risk management Cybersecurity risks are integrated into DRDGOLD's Enterprise Risk Management ("ERM") framework and are assessed using the same risk identification, evaluation, mitigation and reporting processes applied to other strategic, operational, financial and compliance risks. Cybersecurity risks are recorded, monitored and reported through the Group's risk management processes and are considered when evaluating the Group's overall risk profile and risk appetite. The Group also evaluates cybersecurity risks associated with third-party service providers and other external parties that have access to its systems or data. Critical vendors are required to provide assurance regarding their cybersecurity controls through independent assurance reports or cybersecurity assessments. The results of these assessments are incorporated into the Group's broader risk management processes.
|
| Cybersecurity Risk Management Third Party Engaged [Flag] | true |
| Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] | true |
| Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] | false |
| Cybersecurity Risk Board of Directors Oversight [Text Block] | Board of directors oversight of cybersecurity risks The Board oversees cybersecurity risk as part of its broader responsibility for risk governance. Oversight is delegated to the Risk Committee, which receives periodic reports regarding cybersecurity risks, emerging threat trends, control effectiveness and significant incidents, if any. The Risk Committee monitors management's processes for identifying, assessing and managing cybersecurity risks and reports significant matters to the Board.
|
| Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] | The Board oversees cybersecurity risk as part of its broader responsibility for risk governance. Oversight is delegated to the Risk Committee, which receives periodic reports regarding cybersecurity risks, emerging threat trends, control effectiveness and significant incidents, if any. The Risk Committee monitors management's processes for identifying, assessing and managing cybersecurity risks and reports significant matters to the Board.
|
| Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] | Oversight is delegated to the Risk Committee, which receives periodic reports regarding cybersecurity risks, emerging threat trends, control effectiveness and significant incidents, if any.
|
| Cybersecurity Risk Role of Management [Text Block] | Management oversight of cybersecurity risks Management is responsible for assessing and managing cybersecurity risks. Responsibility for cybersecurity governance is led by the Head of Cybersecurity ("HCS"). The HCS oversees the Group's cybersecurity strategy, risk management activities and incident response capabilities, and is responsible for the day-to-day management of cybersecurity risks, implementation of security controls and remediation of identified vulnerabilities and control deficiencies. Management receives information regarding cybersecurity risks and control effectiveness through ongoing monitoring activities, risk assessments, assurance reviews and incident management processes. Cybersecurity matters are periodically reported to executive management and considered as part of the Group's broader risk management and business resilience processes.
|
| Cybersecurity Risk Management Positions or Committees Responsible [Flag] | true |
| Cybersecurity Risk Management Positions or Committees Responsible [Text Block] | Management is responsible for assessing and managing cybersecurity risks. Responsibility for cybersecurity governance is led by the Head of Cybersecurity ("HCS"). |
| Cybersecurity Risk Management Expertise of Management Responsible [Text Block] | Management is responsible for assessing and managing cybersecurity risks. Responsibility for cybersecurity governance is led by the Head of Cybersecurity ("HCS"). The HCS oversees the Group's cybersecurity strategy, risk management activities and incident response capabilities, and is responsible for the day-to-day management of cybersecurity risks, implementation of security controls and remediation of identified vulnerabilities and control deficiencies. Management receives information regarding cybersecurity risks and control effectiveness through ongoing monitoring activities, risk assessments, assurance reviews and incident management processes. Cybersecurity matters are periodically reported to executive management and considered as part of the Group's broader risk management and business resilience processes.
|
| Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] | The HCS oversees the Group's cybersecurity strategy, risk management activities and incident response capabilities, and is responsible for the day-to-day management of cybersecurity risks, implementation of security controls and remediation of identified vulnerabilities and control deficiencies.
|
| Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] | true |