Information and technology governance

Blu Label continued to mature its information and technology governance in FY25, building on the foundations set in FY24 and guided by formal IT board and Group Exco reporting. Our governance approach remains pragmatic and integrated: it aligns technology investment to business outcomes, strengthens controls and resilience, and supports regulatory and commercial obligations.

PLATFORM AVAILABILITY AND RESILIENCE

We have materially strengthened platform redundancy, failover capability and observability to limit customer disruption and meet contractual service levels for our transactional systems. Core‑system SLAs improved significantly in FY25: the SLA three-month average was 99.957% and the six-month average 99.972%, with seven of 12 months achieving 99.99%+ availability. During Q1 to Q2 2025, we recorded a month uptime of 100% (Mar 2025), 99.984% (Apr 2025) and 100% (May 2025). These improvements reflect additional failover lines, SD-WAN upgrades and closer co-ordination with mobile network operators.

We continue to hold operational availability targets appropriate to the channel and service type. For core transactional systems our operational target remains aggressive (99.8% baseline with a continuing ambition to operate at 99.99% availability for peak services). At the same time, channel and partner SLAs are managed individually to reflect third-party constraints. Where external suppliers (notably some electricity aggregators and municipalities) cause incidents, we adopt compensating controls and targeted remediation plans. Over recent months a small cohort of municipal suppliers accounted for a disproportionate share of downtime; we continue prioritising supplier engagement and technical de-risking.

PLATFORM UPTIME – HISTORICAL SNAPSHOT

  • FY23: 99.57% (reported).
  • FY24: 99.62% (reported).
  • FY25: 99.96% (reported FY25 performance/core SLA improvements).

MODERNISATION – BLUSKY AND CORE PLATFORM TRANSFORMATION

FY25 saw accelerated delivery of our modernisation programme (BluSky). The programme replaces the legacy AEON XML gateway with a WS02 API gateway, migrates core stacks to cloud (Azure/AWS), adopts microservices and an API-first model and implements active-active, blue/green deployment patterns. These architecture changes are designed to reduce single-system dependencies, enable continuous delivery (CI/CD), and allow incremental, low-risk migration of customers and products. The BluSky rollout has already activated customers across airtime, data, vouchers and electricity, with staged launches and a co-existence strategy to de-risk migration.

Key delivery items in FY25 included:

  • WS02 API gateway implementation and progressive replacement of XML integrations.
  • Cloud migration of Blu Label Connect platforms and active-active deployment patterns to improve resilience and elasticity.
  • Environment automation and integration pipelines to shorten release cycles and reduce human error.

CYBERSECURITY AND COMPLIANCE

Information security continues to be a priority. Blu Label maintained and expanded its security controls and monitoring posture through FY25: we implemented a SOC, strengthened detection and response, completed vulnerability remediation cycles and advanced our back-up strategy. The Group has achieved and operates under ISO 27001 certification and embeds ISO/alignment requirements into project lifecycle controls and supplier onboarding. These measures both reduce cyber risk and increase commercial assurance for customers and partners.

Measured outcomes include improved fraud prevention (fraud losses reduced from R2.1 million in FY24 to circa R0.2 million in FY25 following device, credential and integration hardening) and progress on audit remediation actions tracked through the Group internal audit tracker.

SERVICE MANAGEMENT, SLAs AND INCIDENT RESPONSE

Operational discipline has been enhanced by the revised service-management processes, new failover topologies, and strengthened monitoring with a triage model that targets rapid acknowledgement and response. Enterprise Support has improved ticket acknowledgement (circa 89% to 90% within 15 minutes in recent months), and overall customer satisfaction with desktop and service support remains very high. Time-to-resolution targets for major incidents remain tightly controlled (service restoration expectations within SLA windows, with major incidents managed to sub-six-hour restoration where feasible).

IT RISK MANAGEMENT AND GOVERNANCE FRAMEWORKS

We continue implementing a formal IT Governance Framework based on COBIT and best-practice standards (ISO/IEC 38500, ITIL, NIST) that the Executive Committee actively oversees. Phase 3 of the framework (integrating IT process flows) has moved into operational delivery; we have also digitised risk tracking through a Group risk platform to enable real-time visibility and co‑ordination across the three lines of defence. Regular internal and external audits, penetration tests and an audit-tracker process ensure remediation and continuous improvement.

PEOPLE, COST AND DELIVERY MANAGEMENT

We align resourcing, organisational structure and vendor economics to the new operating model: a rationalised vendor and hosting footprint, headcount optimisation in certain areas, and contract renegotiation. This allows reinvestment into security, cloud and modernisation while improving the technology function’s fixed/variable cost profile.

BOARD OVERSIGHT AND REPORTING

IT and security matters are reported regularly to Group Exco and the Board via the IT governance reporting cycle. The IT board pack provides a single source of truth for uptime metrics, project delivery status (including BluSky releases), audit findings and risk heatmaps – enabling executive escalation and prioritisation where supplier or systemic issues require cross-functional intervention. This reporting cadence has materially improved transparency and enabled faster corrective action on high-impact items.

LOOKING AHEAD (FY26 PRIORITIES)

  • Complete the subsequent phases of BluSky migration with incremental customer scale-up and decommissioning of legacy components.
  • Deliver the security roadmap (privileged access, data protection, automated dashboards) and close remaining high-risk audit findings.
  • Continue supplier stabilisation (MNO failovers, municipal/ electricity aggregator engagement) to reduce externally driven outages.
  • Reduce run costs via cloud economics and operational efficiencies while preserving targeted reinvestment in security and resilience.