NWU Institutional Repository

Exploring cyber risk reporting in South African banks

dc.contributor.advisorNyamah, G.
dc.contributor.advisorMeiring, W.
dc.contributor.authorRikhotso, Tlhoki
dc.contributor.researchID
dc.contributor.researchID
dc.date.accessioned2025-06-19T08:38:21Z
dc.date.available2025-06-19T08:38:21Z
dc.date.issued2025
dc.descriptionMaster of Commerce in Applied Risk Management , North-West University, Vanderbijlpark Campusen_US
dc.description.abstractUsing a qualitative document analysis method, this research explored a unique area with actual risk work, in cyber risk reporting by South African banks listed on the JSE. The study used publicly available integrated reports, risk management reports, and corporate governance reports (collectively referred to as governance reports) from the top five JSE-listed banks, to address the research question: How can South African banks and regulators enhance cyber risk reporting to better inform investors? As a new research area, this question appeals to stakeholders of the banks and investors. Firstly, to address the research question, a literature review was conducted, analysing peer-reviewed academic literature, South African regulations, and SEC cyber risk reporting guidelines and regulations. This review informed the development of a thematic codebook containing themes and subthemes for cyber risk reporting information, useful for investor decision-making. The literature review highlighted gaps in South Africa's regulatory framework on cyber risk reporting. Secondly, the banks' governance reports were evaluated against these themes and subthemes to assess whether the information provided is beneficial for investor decision-making. The findings indicated that, while banks report some relevant cyber risk information, there are gaps in the completeness and comprehensiveness. As such, the study recommends that South Africa's regulators enhance regulatory requirements to mandate cyber risk incident reporting for investor decision-making and to provide more detailed guidance on information to be included in annual governance reports. It is also recommended that banks use these findings to evaluate and improve their reporting for greater transparency. Although this study has limitations, it offers valuable insights into the banking industry, regulators, and academics by providing guidance to the banks to improve their cyber risk reporting practices, suggesting improvements to the regulatory framework, and contributing to the body of knowledge on cyber risk reporting in a South African context.en_US
dc.description.thesistypeMastersen_US
dc.identifier.urihttps://orcid.org/0009-0000-3919-8497
dc.identifier.urihttp://hdl.handle.net/10394/42942
dc.language.isoenen_US
dc.publisherNorth-West University (South Africa)en_US
dc.subjectCyber risken_US
dc.subjectCyber threatsen_US
dc.subjectRisk reportingen_US
dc.subjectInvestor decision-makingen_US
dc.subjectSouth African banksen_US
dc.titleExploring cyber risk reporting in South African banksen_US
dc.typeThesisen_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Rikhotso_TL_2025.pdf
Size:
760.28 KB
Format:
Adobe Portable Document Format
Description:
Thesis (Masters)

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.61 KB
Format:
Item-specific license agreed upon to submission
Description: