CIO Maletsema Phofu’s strategic vision for cybersecurity at UJ

post-title

At the University of Johannesburg (UJ), CIO Maletsema Phofu is redefining the balance between innovation and security by championing collaboration, business alignment and clear communication across the institution’s digital landscape.

Speaking at the inaugural IT Indaba UJ CIO Maletsema Phofu shared how she is steering an evolving digital landscape that places cybersecurity and innovation on equal footing at the university. Her insights reveal a pragmatic approach grounded in collaboration, business alignment and strategic communication.

According to Maletsema, security begins at the top. She believes that the most effective cybersecurity culture is one where leadership drives the message. “Whether you are a CIO or CISO, you need to push the requirements and the need for security all the way to the top,” she said.

She further noted that the chief executive sets the tone and the rest of the organisation follows. Security training and compliance become part of the institutional rhythm rather than isolated exercises when the messaging around the security culture comes from the top.

She acknowledges that tension once existed between CIOs and CISOs, particularly when their mandates were not clearly defined. That dynamic, she notes, has changed significantly. “There used to be this conflict where the CIO and the CISO were competing. Over the years, we’ve seen that really coming down.”

She attributes this improvement to the real-world impact of cyber incidents, which have demonstrated that collaboration is no longer optional. “It’s very important that there’s a mutual understanding of what a CIO does and what a CISO does. Together, we have to work to drive the institution toward its objectives.”

This partnership extends into practical governance. The CIO’s role is to enable processes, implement innovative technology and support strategic goals, while the CISO protects the organisation. Both must align around shared outcomes. “That understanding really helps in achieving institutional goals,” she said.

Positioning cyber risk as business risk

When it comes to cybersecurity investment, Maletsema is realistic about budget pressures and the unique context of higher education. “I work for a university and our budgets are often very tight,” she said candidly. She explains that financial discussions with executives must be rooted in risk awareness and options.

“I will go to the executives and explain the risks I am currently facing as well as their magnitude. If you invest R10 million, it will reduce risk to this level. If you give me R20 million, you will set it at its lowest level and then they can decide.” By framing decisions in terms of measurable risk reduction, she empowers leadership to take ownership of security outcomes.

Equally, Maletsema stresses the need to speak the language of business. Technical terminology alienates decision-makers and hinders funding requests. “One of the things we struggle with is talking business language. Going to the CFO and saying we have vulnerabilities means nothing to them,” she said.

Demonstrating value in terms of cost avoidance, efficiency or reputation is what builds credibility. “Security is intangible, so when you don’t face an attack, that’s actually what is good for you. This is difficult to explain, until it actually does happen,” she added.

Her philosophy on emerging technology reflects balance and patience. “AI is new and we don’t fully understand all its capabilities,” she said. At UJ, successful adoption means taking a gradual, governance-led approach. “Approaching it slowly, building appreciation for it and creating frameworks or guardrails as we go along. This also helps with gaining buy-in from both employees and students.”

Maletsema’s leadership reflects an understanding that technology transformation must walk hand-in-hand with human understanding. Her approach, which is grounded in risk awareness, collaboration and communication, has positioned UJ to innovate securely while maintaining resilience in a rapidly changing digital environment.

Related articles

CIOs, your attackers may already be inside

CIOs still approach cybersecurity as if attackers are trying to “break in”. That thinking is outdated. Modern cybercriminals are not smashing through firewalls wearing hoodies in dark rooms. They are logging in through the front door using stolen credentials, hijacked Microsoft 365 accounts and employees who unknowingly hand over access every single day.

CTIO Hans Zachar puts people first

Hans Zachar, 2025 CIO Awards Cybersecurity award-winner, built Nutun’s international technology platform with the same quiet discipline that shaped his life growing up in Edenvale. For the group chief technology and information officer, global scale, trust and innovation have always been about people first – and systems second.

CIOs discuss AI, automation and the fight to protect our data

As AI and automation continue to proliferate in workplaces, there is growing tension in boardrooms across South Africa as cyber threats become an increasingly pressing issue for CIOs. IT leaders unpack how they are building cyber resilience while enabling innovation in their organisations.

Top