Integrated_Annual_Report_2026 - Flipbook - Page 145
INTRODUCTION
SASOL AT A
GLANCE
DRIVING SUSTAINABLE
VALUE CREATION
EXECUTING
STRATEGY
DELIVERING
BUSINESS VALUE
SUMMARISED FINANCIAL
PERFORMANCE
CORPORATE
GOVERNANCE
SUSTAINABILITY
REPORT
REMUNERATION
REPORT
ASSURANCE/
ADMINISTRATION
GOVERNANCE CONTINUED
Ethics continued
Information
management, digital and cybersecurity
COMMITMENT
Sasol is committed to ensuring a secure
information management and cybersecurity
environment by implementing measures to
address and mitigate associated risks.
GROUP
APPROACH
To support the organisation in achieving its goals and strategic objectives, Information Management (IM) and Digital
aims to guide the effective and efficient use of IT solutions and services by establishing appropriate decision-making
structures and governance frameworks, including policies and processes.
IM Governance forms a subset of Sasol corporate governance with a groupwide risk management process that is
aligned to international standards and best practice. Cybersecurity is noted as a Group material risk for Sasol and
oversight lies with the Sasol Audit Committee
For more details refer to Risk and opportunities on pages 21 – 32.
PROGRAMMES AND PERFORMANCE
Chief Information
and Digital Officer
GEC EVP
Commercial
and Legal
BOARD
Audit Committee
Capital Investment
Committee
FY26 focus areas, included:
Improving customer experience
Growing IM talent and digital
enablement
Enabling strategic business
and digitalisation initiatives
Exploring the value cases
for Artificial Intelligence (AI)
and Generative AI (GenAI)
for Sasol
Improving Mobility applications
for the retail fuels business
Progressing the company’s
cloud journey
Improving data governance
and quality.
Optimising Sasol’s spend on
outsourced services
Focusing on cybersecurity
to secure operations and
the organisation
Strengthening the organisation’s
IT General Control environment
SASOL INTEGRATED REPORT 2026
Despite operating in a financially constrained
environment, the organisation has
sufficient protection in place and has not
experienced a cybersecurity incident
that had a material impact on Sasol’s
business strategy, operations, or financial
reporting in the last financial year. Despite
this, Sasol is cognisant that cyberattacks are increasing in both volume and
sophistication, particularly with the growing
use of artificial intelligence (AI) to enhance
adversary capabilities.
Sasol’s cybersecurity posture is
continuously assessed to identify areas of
improvement, analyse emerging threats,
and implement enhancements as needed or
schedule them for future deployment.
Within the supply chain, IM focuses on
ensuring the confidentiality, integrity and
availability of data; document retention
requirements; data privacy; information
classification and security.
Policies and compliance
Sasol’s Information Management
Policies and Code of Conduct reflect its
commitment and dedication to ensuring
compliance with IM-related regulation and
legislation. The use of Sasol computing
devices, systems and services is governed
by Sasol IM policies. By accessing a Sasol
account, each user acknowledges these
policies and the terms of acceptable use.
144
Any non-compliance is addressed in
accordance with the stipulated policies,
taking into consideration jurisdictional
implications.
Training and awareness
Through robust information security
awareness campaigns, Sasol shares
monthly themes with its employees and
service providers. Employees are enrolled
in training on Sasol’s Learning Management
Systems, which focuses on critical topics
for cybersecurity awareness such as deep
fakes, securing data and insider threats.
Month-to-month participation ranges from
95% to 98%.
Awareness training is mandatory.
Participation is monitored, with feedback
shared with Group Executives and Senior
Vice Presidents to promote completion.
Additionally, employees who miss two or
more training sessions are considered
non-compliant, and network restrictions are
applied until they become compliant again.
Frequent phishing tests are conducted
and results are reported to management
to evaluate employees’ awareness of
potential risks.
Employees also receive comprehensive
training on the use of IM systems and tools,
as well as business system-specific training
tailored to their respective job roles.