Principal risk
Context
Mitigating actions
Strategic
Objective
1
Access to
spectrum
Speed of impact:
Slow
>12 months
A failure to secure access to
additional spectrum, needed to
deliver cost-effective expansion of
our radio access network (RAN),
would significantly impact our
ability to increase capacity and
deliver future system capabilities.
Key challenges include: proposed
policy changes relating to spectrum
licence; non-renewal of existing
licences; and increasing competition
for access to spectrum.
•
We maintain constructive relations with government
and regulators, and strive to work collaboratively with
them to find solutions that are in the collective
interest of business, government and society.
•
We ensure that our spectrum strategy is in line with
regulatory and market developments.
•
As data demand continues to grow exponentially we
entered into a commercial agreement to roam on the
data network of our partners, and to identify and
acquire entities which have access to spectrum, e.g.
SNT in Tanzania.
2
Cyber
threat
Speed of impact:
Very rapid
<6 months
An external cyber-attack, insider
threat or supplier breach (malicious
or accidental) could result in service
interruption and/or the breach of
confidential data, with resulting
negative impacts on customers,
revenues and reputation, and
potential costs associated with fraud
and/or extortion.
•
We have a global risk-based security strategy, and a
global security function that develops and implements
relevant policies and processes.
•
Security controls are implemented centrally. In local
markets, we have a continuous improvement
programme to mitigate against changing risks.
•
We manage the risk of malicious attacks on our
infrastructure through our cyber intelligence centre
that provides continuous proactive monitoring of our
Group infrastructure, responds to incidents and
manages recovery from those incidents.
•
We apply layers of security control to all applications
and infrastructure that store or transmit confidential
personal and business voice and data traffic.
•
We have an assurance programme that incorporates
both internal and external reviews of third parties that
hold data on our behalf.
3
Customer
data
misuse or
leakage
Speed of impact:
Very rapid
<6 months
Respect for privacy is essential for
maintaining customer trust.
Customer data is also an important
strategic asset for Vodacom. Failure
to strategically manage customer
privacy and ensure data integrity will
have significant negative
reputational implications, reduce
the value of our data assets and
result in regulatory non-compliance.
This could result in substantial fines,
reputational damage and a negative
impact on customer NPS.
•
We process personal data honestly, ethically, with
integrity and consistent with applicable laws and with
the Vodafone Global Privacy Framework.
•
We are responding to privacy requirements through an
enterprise project across all areas in the business.
•
We monitor and enforce compliance with regulations
and our internal policies, and provide regular security
and privacy awareness training to relevant employees.
•
Our legal and regulatory affairs teams engage with key
stakeholders to ensure that we implement the
necessary controls.
•
We ensure compliance with privacy requirements as
stipulated by data protection legislations.
21
Our business
Operating context
Delivering on our strategy
Our governance structure
Administration
Our Strategies
Best Customer
Experience
Best
Technology
Digital Organisation
and Culture
Segmented
Propositions
Our Brand and
Reputation




