Barloworld’s Karin Höne learnt during dog training that reward can be a powerful motivator and uses this in her career to retain and attract top cyber talent.
On weekends, you might find Karin Höne out in the field. Not with laptops or dashboards, but guiding her Labrador through a dog agility course. Tunnels, hoops, jumps – it’s all part of the routine. No stopwatch pressure to win gold; instead, she focuses on clear rounds and steady improvement. “I compete against myself,” she says. “It’s about setting goals we can achieve together and enjoying it.”
It’s an unexpected image for someone who spends her weekdays fending off cyber threats as group chief information security officer (CISO) at Barloworld. But if you pay attention to how she describes both worlds (dog sport and digital defence) the parallels become obvious: structure matters, resilience counts and communication is everything.
Karin brings that same grounded clarity to one of South Africa's most complex enterprises at a time when cyberthreats are mutating faster than ever, turbocharged by artificial intelligence (AI).
After serving as Barloworld's acting CIO until 30 April (while simultaneously maintaining her CISO responsibilities), she returned to her security-focused role. “If you’re a true CISO, which I think I am, your passion lies in security,” she says with conviction. “You need a different personality to be an effective CIO. The CISO is all about protecting the environment, backed by strict governance and rules. We’re very much risk-minded personas. A CIO is more of a friend of business, there to enable and build relationships so the business can achieve its objectives.”
Karin’s security journey began during her honours degree studies, where she became fascinated with cryptography principles. After starting her career at Eskom, she quickly transitioned to their cybersecurity team and has remained in the security field ever since, with extensive experience across financial services before joining Barloworld.

A balanced approach
This deep security expertise proved invaluable during the recent migration of a significant legacy system, a multi-year project where Karin’s team was integrated from the beginning rather than as an afterthought.
“We were allowed to journey with the project team from a cybersecurity perspective,” she says. “We set out our principles up front based on our own standards, not vendor defaults, and journeyed alongside the business and technology team throughout.”
The project revealed important lessons about organisational change that resonate beyond just security implementation. When initially proposing the new system, users unanimously requested replacing the old one. Yet once the replacement process began, those same users suddenly found virtues in the legacy system they’d previously criticised.
“Change management is probably one of the biggest elements of a project that we could not ignore or neglect,” Karin reflects.
“We had an independent party for change management, which proved extremely effective because they weren’t vested either way. They could objectively listen to complaints and praise, craft non-biased messages and help us deal with detractors without being emotionally involved.”
This focus on the human factors in technological change reflects Karin’s balanced approach to security leadership. While she maintains rigorous technical standards, she recognises that effective security depends equally on understanding people. Her risk-based mindset also defines her leadership style: direct but thoughtful; strategic yet human-centred.
Her ability to bridge hard-edge risk thinking with collaborative delivery has become something of her signature style. And nowhere does it show more clearly than in how she’s tackling one of today’s most amorphous threats: AI-driven attacks.
When AI writes better phishing emails than people do
Karin doesn’t mince words about how AI has changed cybersecurity permanently, and unnervingly fast.
“For many years, we’ve trained our user community in terms of phishing emails: check for bad grammar, check for spelling mistakes. That’s all gone,” she says. “Threat actors are using AI to craft phishing messages that eliminate those telltale signs. One of our fundamental pieces of the puzzle in spotting phishing messages has been taken away overnight with the advent of AI.”
She sees this shift as a philosophical challenge: the rules defenders used no longer apply, while attackers adapt faster than controls can keep up. “We used to teach patterns,” she explains. “Now there are no patterns.”
This constant fluidity is precisely what keeps pulling her deeper into cybersecurity, not further out towards broader IT management roles. “No two days ever look alike,” she adds, with unmistakable satisfaction. “You plug one hole...and immediately have three new ones opening elsewhere.”
Maintaining this vigilance requires continuous learning, which Karin prioritises for herself and her team. She values the cybersecurity industry’s strong certification requirements, like her own certified CISO credential that mandates ongoing education.
“In cybersecurity, certifications automatically force you to remain up to date, do extra courses, or attend webinars. I find, in my personal opinion, that in other IT areas, there are certifications, but often no requirement to remain current. For me, continuous education is very important.”
Although the goalposts may move daily, some fundamentals stay fixed: keeping visibility high inside your organisation while staying agile enough outside it. To do this well requires people who aren’t just technically sharp, but adaptable thinkers committed enough not only to stay current themselves, but to push others along too.
This commitment to ongoing development helps her team maintain cutting-edge skills, though it creates vulnerability to talent poaching: a challenge exacerbated by the post-Covid-19 remote work revolution that allows South African security specialists to work for international organisations without relocating.
Co-sourcing partnerships
Barloworld isn’t a bank, nor is it a healthcare giant or insurance conglomerate. Top-tier cyber talent tends naturally towards these industries because they’re high-stakes environments with bleeding-edge tools and urgent problems hourly. So, how does Karin compete and attract top talent?
“I’m not a bank or insurance company, so I will not be able to have the masses of teams or skills and talent needed to run an effective cybersecurity division alone,” Karin explains, adding that she doesn’t try to compete directly. Instead, she leans heavily on co-sourcing partnerships. “I’ve got my internal team who know our environment like second nature. That institutional knowledge matters hugely. But I supplement them with specialist partners whose job is bringing fresh skills into our world without me needing massive headcount budgets.”
The model works well because it’s dynamic: it allows skill rotation based on emerging threats while shielding internal burnout risks. But even then, retention remains tricky. Especially post-Covid-19, where global firms now recruit South African talent remotely at higher pay scales few locals can match legally, let alone culturally.
Still, she fights attrition strategically instead of reactively, with continuous upskilling mandates built around accredited certifications such as CISSP or CEH that require active renewal. “Those CPD points force relevance,” she notes. “You’re never done learning.”
In fact, it mirrors exactly how she stays relevant herself – by celebrating small wins loudly, even when nobody else thinks they're big.
Leading with humanity (and sometimes treats)
If there’s one thing dog agility taught Karin outside those tunnels, it’s patience...and reward timing. “We don’t focus on winning medals – we focus on clear rounds,” she’ll tell you. “And we celebrate those moments fully.”

This philosophy extends to how she leads her team. Drawing from a formative career experience, Karin emphasises celebrating incremental victories.
“At a previous employer one of our values was celebrating success. Initially, I was all about getting the job done and moving on. But when I reflected on why it was a value, I realised it motivates people and acknowledges them,” she explains. “It’s about giving them the fuel they need to continue. Celebrating success is very important – if you do it consistently, it energises the team to strive toward the next goal.”
Without these moments of recognition, Karin observes, work “just becomes this long, drawn-out, never-ending journey to nowhere. Because ultimately, for all its governance checklists and threat matrices, cybersecurity still comes down to people feeling seen for doing hard things well under pressure. And that’s something automation will never replicate reliably.”
Despite leading in an industry where threats never sleep, Karin maintains a work-life balance through deliberate boundaries and personal pursuits. Beyond dog agility competitions, she previously enjoyed horseback riding and currently sings in a 650-person community choir that assembles twice yearly for intensive rehearsals culminating in weekend performances.
“You need to find something that helps you switch off, whatever it is – whether it’s exercising, reading, or music. You need that one thing that resets your mind, resets your body, and gives you the energy to start the journey again.”
Now, fully returned from interim CIO duties and focused on CISO territory again, you’d think she’d be resetting mentally after months of wearing two hats simultaneously? Not quite: “My cyber team will feel like it’s a reset – I’ll be able to give them 100 percent again. But for me? This wasn’t switching roles so much as switching focus – I’ve kept both muscles working all along.”
Whether guiding staff through transformational change or guiding Labradors over competition hurdles, Karin leads without drama, but always with direction. Not chasing trophies, but clarity, alignment, and better outcomes… One round at a time.
















