Central University of Technology (CUT) CIO, Galeboe Mogotsi, writes about his experience transitioning from a CISO role to a CIO role and shares the key lessons he has learnt in the early phase of the transition.
Two months into my role as CIO at the Central University of Technology, one insight has crystallised: the greatest risk to institutional transformation is not technological – it is misalignment.
I have been entrusted with developing a university-wide digital transformation strategy and implementing it once approved. It is a significant mandate. From the outset, however, one principle has guided me: this strategy must be owned and executed by the university, not by ICT.
Because this is not an ICT strategy, it is an institutional transformation agenda enabled by technology. If it is framed otherwise, it will struggle to endure.
With a background in cybersecurity and governance, my instinct was to begin with risk posture, architectural rationalisation and systems modernisation.
Instead, I paused.
In my first weeks, rather than mapping platforms, I met with executive peers and academic leaders. The questions were deliberately operational:
- Where is friction slowing the institution down?
- Where are processes duplicated or unclear?
- Where is data unreliable?
- Where does technology enable – and where does it obstruct?
The responses were not about firewalls or cloud migration. They were about workflow, accountability and integration.
That reframed the work.
Transformation is not triggered by technology upgrades. It is triggered by clarity of institutional intent.
Confronting structural silos
Universities are structurally autonomous by design. Faculties, research units and administrative portfolios operate with independence that protects academic depth.
But autonomy also creates fragmentation.
If transformation is driven exclusively from ICT, it risks reinforcing those silos rather than dissolving them. Breaking silos is not a systems challenge. It is a leadership challenge.
This has required resisting the temptation to define transformation in technical terms. Instead, the strategy is being framed around institutional capability – integrated processes, trusted data, streamlined governance and aligned decision-making.
Technology supports structure. It does not substitute for it.
From “digital” to institutional transformation
The language of “digital transformation” is often misunderstood. It suggests automation, cloud adoption or system replacement. That framing narrows accountability. A more durable approach is to shift the lens from digital to institutional transformation.
Technology is the enabler and the institution is what must evolve.
Institutional transformation reshapes:
- Academic delivery models
- Research enablement and protection
- Administrative efficiency
- Executive decision-making through reliable data
- The end-to-end student experience
When articulated this way, transformation becomes an executive and governance priority – not an ICT programme competing for attention. Language determines ownership. Ownership determines sustainability.
Governance as strategic legitimacy
Higher education operates through layered governance structures – councils, senates, statutory committees and risk oversight forums. To leaders from more centralised environments, this can initially feel procedural.
In reality, governance provides legitimacy.
If transformation does not move through governance rigorously, it remains operational improvement. Once embedded in governance frameworks, it becomes institutional direction.
Early engagement with oversight structures has strengthened the strategy itself – sharpening accountability, financial discipline and outcome clarity before execution begins.
Speed without alignment creates fragility. Alignment creates durability.
A candid reflection for cybersecurity leaders
For cybersecurity executives transitioning into CIO roles, the shift is substantive.
As CISOs, we are conditioned to see exposure first – control gaps, vulnerabilities and compliance risk. That discipline remains valuable, but it is not sufficient.
At CIO level, the aperture must widen.
The question is no longer only, “Where is the risk?” It becomes, “How must the institution function and how can technology enable that?”
Risk must be balanced with opportunity. Control must be balanced with culture. Technical assurance must be complemented by financial stewardship and stakeholder alignment.
Cybersecurity expertise sharpens judgement. Institutional leadership requires integration.
Collaboration as an operating model
Holding the mandate to develop and implement the transformation strategy does not justify centralised control. It demands distributed ownership.
Institutional transformation requires:
- Executive alignment before roadmap finalisation
- Faculty engagement to secure academic legitimacy
- Financial integration to ensure sustainability
- Risk oversight to ensure resilience
- Operational buy-in to ensure adoption
In universities, authority rarely produces change. Alignment does. Institutional change moves at the speed of trust.
The CIO as integrator
The effectiveness of a university CIO is not measured solely by project milestones or system uptime.
It is measured by whether the institution begins to operate differently – more integrated, more data-informed, more resilient and more student-centric.
Digital platforms are visible.
Institutional transformation is structural.
The former can be acquired.
The latter must be cultivated.
The CIO does not implement transformation alone. The CIO integrates it – aligning governance, culture, finance and technology into a coherent institutional trajectory.
Two months into the role, one conclusion is clear:
The university CIO who sees the position as managing IT will remain operational. The CIO who sees it as shaping institutional direction will redefine how the university functions.
Transformation in higher education is not fundamentally a technology programme. It is a leadership mandate and its success depends on whether it belongs to ICT or to the institution.
















