The fourth dimension of technology risk that South African boards aren’t discussing
Over 25 years at CIO and CTO level, I’ve been described in reference letters, testimonials and job specs as someone who works across strategic, tactical and operational technology. It’s a familiar triad. Strategy gets the annual offsite. Tactics get the budget cycle. Operations get the dashboards and the SLA reviews.
But, there is a fourth dimension, and in most South African boardrooms it doesn’t get an agenda item, a line item, or even a name. I call it the existential dimension: the small set of technology risks that don’t threaten a bad quarter. They threaten whether the business survives at all.
Almost every executive team I’ve worked with can tell you their strategic priorities, their tactical initiatives and their operational metrics. Very few can tell you which two or three technology failures would actually end the company. Not hurt it. End it.
This piece is about those failures, and why medium-sized South African organisations are precisely the companies most exposed to them.
Why “Existential” Is the Right Word
I use the word deliberately. Operational risk is a system going down for a day. Tactical risk is a project overrunning. Strategic risk is backing the wrong horse and spending three years correcting it. Existential risk is different in kind, not just degree: it’s the event after which the business, in any recognisable form, may not come back.
Here’s the uncomfortable truth about the mid-market. A medium-sized company is big enough to have accumulated twenty years of legacy systems, big enough to be a worthwhile target for organised cybercrime, and big enough that its technology estate is genuinely complex. But it is not big enough to absorb a catastrophic failure the way a bank or a mobile operator can.
The JSE-listed giants have redundancy, war chests, and regulators watching over their resilience. The mid-market has none of that cushion. It sits in the kill zone: maximum complexity, minimum shock-absorption.
What makes these risks so dangerous is that they are invisible from the boardroom precisely because everything looks fine. Existential technology risk doesn’t announce itself in the monthly pack. It compounds quietly, and then it happens all at once.
Four of these risks come up, in some combination, in almost every organisation I assess. And for each of them, I’ve watched the theory become reality.
1. The Systems That “Still Work”
Every established company runs at least one system that everybody depends on and nobody wants to touch. The billing engine written in the early 2000s. The warehouse system that only one engineer truly understands. The integration layer held together by scheduled jobs that nobody has documented.
The phrase I hear most often is: “It still works.” And it does, right up until the day it doesn’t. That is when you discover that the vendor no longer exists, the skills no longer exist in the country, and the recovery procedure has never actually been tested.
I’m currently aware of a company whose core business support system, the system the entire operation runs on, was built over many years by a single developer. He is approaching retirement, has no appetite for change, and keeps the intellectual property firmly in his own head. Not out of malice, necessarily; protecting that knowledge protects his job.
The result is that one individual effectively holds the company hostage. Leadership knows the risk. They can see it clearly. But knowing about a risk and knowing what to do about it are two very different things, and so the situation drifts: one resignation letter, one health event, one bad day away from crisis.
South Africa adds two accelerants to this fire. The first is that years of load-shedding taught us to harden our power, but very few organisations applied the same discipline to their systems. We bought generators and UPSs while the application estate quietly aged past its support life.
The second is skills emigration. Key-person risk is a global problem; in South Africa, where scarce technical skills leave for Dubai, London and Amsterdam every month, it is materially worse. When your one developer, your one DBA, or the only person who knows the custom ERP customisations walks out the door, the risk doesn’t degrade gracefully. It steps.
Ask yourself one question: if the three most fragile systems in your business failed tomorrow, do you know (not believe, know) that you could recover them? If the honest answer is “we’ve never tested it,” that’s not an operational gap. That’s an existential one.
2. Technical Debt: The Liability That Isn’t on Your Balance Sheet
Technical debt behaves exactly like financial debt. It compounds. It attracts interest. Deferring it doesn’t make it cheaper; it makes it more expensive later. The only difference is that financial debt is disclosed, audited and managed. Technical debt appears nowhere in your annual financial statements, and so it is managed by nobody.
It doesn’t only accumulate through neglect. It also accumulates through enthusiasm.
One client I worked with had built up a technology stack of more than ninety applications. Every new product launch brought a new system. Internal development was effectively uncontrolled. Bespoke projects were commissioned without integration planning or any serious business-benefit analysis. Each individual decision looked reasonable at the time; the cumulative effect was anything but.
Total cost of ownership blew out. Complexity became a risk category of its own. And, the part that finally got the board’s attention, data integrity degraded to the point where BI and reporting became confusing and contradictory. When two dashboards give an executive team two different answers to the same question, the organisation isn’t just carrying technical debt. It has lost the ability to see itself clearly, and every decision made on that data carries the infection.
Under-investment is the same disease in slow motion. Every year that the technology budget is treated purely as a cost to be minimised, the gap between your cost-to-serve and your best competitor’s cost-to-serve widens. The existential moment isn’t dramatic. It’s the day a competitor, or an offshore entrant with no legacy at all, can serve your customer at 60% of your cost. By the time that shows up in your revenue line, the race was lost two or three budget cycles ago.
The South African twist is currency. Most serious modernisation (cloud platforms, enterprise software, specialist skills) is priced in dollars, euros or pounds. With a structurally weakening rand, every year of deferral raises the price of catching up. Deferring modernisation in this market is not a neutral decision. It is borrowing at one of the worst interest rates available to a South African business.
Boards routinely interrogate gearing ratios and debt covenants. I have almost never seen a board pack that quantifies the organisation’s technical debt with the same seriousness. It should.
3. Cybersecurity: Stop Treating It as Compliance
Most mid-market organisations treat cybersecurity as a compliance exercise: a policy document, an annual penetration test, a line in the audit report. That framing is dangerously out of date.
Let me tell you what the real thing looks like. A previous client, a business running a private cloud environment serving its own customers, was breached and ransomwared. Not just their internal systems: every client hosted on that environment was affected too.
Then came the second blow. Their cyber insurer denied the claim, because the security controls and detection capabilities the company had declared on its policy were not actually in place.
Recovery took nine months. Nine months of firefighting, rebuilding, and difficult conversations. And when the technical recovery was finally complete, the commercial damage remained: many of their customers had left and did not come back. The reputational harm outlasted the ransomware by years.
That is what a going-concern event looks like. Operations stop. Cash collection stops. Customer data is exfiltrated, which brings POPIA and the Information Regulator into the room. And the insurance you thought was your safety net turns out to be conditional on a security posture you only assumed you had.
Unlike the corporate giants, a medium-sized business doesn’t have a hundred-person security operation and a crisis-communications machine to absorb the blow. South Africa is one of the most targeted economies on the continent, and attackers know precisely that our mid-market is where valuable data meets under-invested defence.
The existential question here is not “are we compliant?” It is: if we were encrypted tonight, how many days until we invoice again, how many of those days can we survive, and would our insurer actually pay? If nobody in your organisation can answer that with evidence, you are carrying an unpriced existential risk.
4. Artificial Intelligence: The Risk Is the Curve, Not the Robots
AI is the newest entry on this list and the most misunderstood. The existential risk to a South African mid-market company is not science fiction. It is arithmetic.
AI is now driving a genuine restructuring of cost bases: in customer service, in software development, in document-heavy back offices, in analytics. The threat is not that AI replaces your business. It is that a competitor uses it to operate at a materially lower cost and faster cycle time than you, while you are still debating whether it’s hype. Being on the wrong side of a productivity curve has ended companies before; ask anyone who ran a print media business or a travel agency in 2005.
There is a second, quieter risk, and I saw it in sharp focus at a company I engaged with recently. Their approach to AI adoption was to hand out licences: Copilot for some, ChatGPT for others, Claude for a few more, distributed to key employees with the best of intentions. No governance. No policy. No controls.
Within months, staff were using these tools to write client proposals and, more alarmingly, to “vibe code” their own applications and dashboards that connect directly to live business systems and data. The executive team wasn’t reckless; they were lost. They didn’t know how to adopt AI safely, and they didn’t fully understand the risk they had already taken on.
That is the pattern I now find almost everywhere: ungoverned AI is already inside your business. You have adopted AI whether you decided to or not. The only question is whether you’re governing it.
The mid-market has one genuine advantage here: it can move faster than the giants. But that advantage expires. The window in which “we haven’t started yet” is a recoverable position is closing.
Why Boards Miss the Fourth Dimension
None of this is because executives are negligent. It’s structural.
Existential technology risk has no natural owner, no line item and no quarterly signal. The CIO reports on uptime and projects, which are measures of what’s working, not what’s fragile. The audit committee looks at what’s auditable, and fragility isn’t. The CFO sees technology as a cost line. And nobody in the organisation is incentivised to stand up in exco and raise a risk that, by definition, is currently causing no visible problem.
So, the fourth-dimension falls into the gap between everyone’s job description. Until it doesn’t.
Making the Fourth Dimension Visible, and Manageable
Here is the good news: every risk described above is manageable. The company held hostage by one developer, the ninety-application stack, the denied insurance claim, the ungoverned AI sprawl. None of these were inevitable. All of them were visible earlier, to someone who knew where to look and had no vested interest in what they found.
That last part matters. Your vendors won’t surface these risks; every one of them has something to sell you as the answer. Your internal team often can’t; they’re too close to it, and nobody is rewarded for declaring their own estate fragile. Surfacing existential risk requires an independent, senior, vendor-neutral view. That is precisely the gap m-konsult exists to fill.
In practical terms, this is what addressing the fourth dimension looks like, and how I help clients do it:
- Make it visible. A once-off, independent assessment of your IT capabilities, risks and operating model. Not another security audit, but an honest view of where the business would actually break: untested recoveries, key-person dependencies, systems past their support life, unquantified technical debt. This is exactly the kind of ad hoc engagement most of my client relationships start with.
- Put a number on it. Technical debt, application sprawl and cyber exposure should be quantified and reported to the board like any other liability, with a deliberate, budgeted pay-down plan. I help executive teams build that picture and translate it into a rationalisation and modernisation roadmap the CFO can actually work with.
- Close the survival gaps. Cybersecurity and business continuity treated as board-level assurance, not IT admin. Are the controls you’ve declared to your insurer actually in place, and have you rehearsed the events that could end the company? A single avoided breach or downtime event pays for this work many times over.
- Govern AI before it governs you. A pragmatic AI adoption framework covering policy, guardrails, approved tools and high-ROI use cases, so your people get the productivity benefit without wiring ungoverned tools into your live systems and data.
None of this requires a big-bang programme or an army of consultants. It starts with one honest, independent conversation about where your business is genuinely exposed, with someone who has sat in the CIO chair when these things go wrong, and has nothing to sell you except clarity.
The organisations that will still be here in ten years are not necessarily the ones with the best strategy. They are the ones that took the fourth dimension seriously while everything still looked fine.
If you can’t confidently name the three technology failures that could end your company, that’s the conversation to have, before one of them names itself. Start the conversation, or see how I engage: ad hoc, project-based or on retainer.
Connect with me → Contact www.m-konsult.com/contact or connect with me on LinkedIn
Other articles that may interest you: https://m-konsult.com/news/
Marius Burger is the principal consultant at m-konsult, an independent ICT advisory practice. After 25 years at CIO and CTO level across some of Africa’s largest organisations, he provides vendor-neutral technology advice to founders, executives and boards, across strategy, transformation, cybersecurity and AI.




