As AI and automation continue to proliferate in workplaces, there is growing tension in boardrooms across South Africa as cyber threats become an increasingly pressing issue for CIOs. IT leaders unpack how they are building cyber resilience while enabling innovation in their organisations.
Automation and AI are reshaping the security landscape with promises of efficiency and faster responses to threats, but they also expand the attack surface and introduce new risks. Cisco’s 2025 Cybersecurity Readiness Index shows that only five percent of South African organisations are fully prepared to withstand modern cyberattacks.
Against this backdrop, CIO South Africa spoke with three leaders on the frontline of cybersecurity, including Ritasha Kalidas who is the group head of cybersecurity at Coca-Cola Beverages Africa (CCBA); Adrian Sing, CIO of Bestmed; and Cathy Leso, CIO at the Department of Mineral Resources and Energy.
Cybersecurity continues to take centre stage in South Africa, with major organisations in both the public and private sector reporting major breaches. Cisco’s index revealed that 54 percent of local organisations experienced AI-related security incidents in the past year, yet only 59 percent believe employees fully understand AI-driven threats. This disconnect between incident exposure and workforce readiness is emerging as one of the most significant challenges facing CIOs and CISOs.
Cathy notes that in the public sector, the understanding of technology as both an enabler and a source of risk remains limited. This lack of awareness heightens exposure at a time when digitalisation is expanding across government departments. For the private sector, the challenge lies less in awareness and more in balancing the competing priorities of security and innovation.
Ritasha stresses that embedding security from the earliest stages of automation projects is essential if organisations are to innovate without exposing themselves to unnecessary risk. “At CCBA, we have an overall IT risk assessment which is specific to AI. This is executed against all AI specific and automation projects and forms part of our overall AI governance as well as AI policy requirements,” she adds.
Her point reflects a shift away from treating cybersecurity as an afterthought, which is essential to addressing the emerging threat landscape. In CCBA’s model, assessments are not only technical but also tied to governance structures and policy compliance. This alignment ensures that security does not stifle innovation but is instead designed into processes from the outset.
Automation as a tool and a target
Adrian echoes this approach in the healthcare sector, where sensitivity of personal and medical data demands rigorous safeguards. “We embrace digital innovations such as automation and AI to drive efficiencies without compromising our cybersecurity defences. On the flip side the Bestmed Scheme increasingly relies on automation and AI in our cybersecurity operations to improve our defences,” he explains.
For Bestmed, automation is not only part of the business model but also central to how the organisation secures its systems. By applying the same technologies to both enable efficiency and defend critical infrastructure, Adrian illustrates the dual role of automation as both a tool and a target.
Emerging threats linked to automation are wide-ranging and sophisticated. AI-powered phishing bots can generate personalised and convincing attacks at scale. Automated botnets allow cybercriminals to launch distributed denial-of-service campaigns that are larger and more resilient than ever before. AI-generated malicious scripts can identify and exploit vulnerabilities rapidly, outpacing traditional manual defences.
These developments enable cybercriminals to run attacks that are scalable, fast and resource intensive. They also employ advanced evasion techniques, making detection and response more difficult. Security teams face the challenge of managing enormous volumes of data generated by such attacks, requiring significant expertise and resources to interpret and counter effectively.
The scale of these attacks threatens to overwhelm under-resourced security teams. South African organisations, many of which already operate with constrained budgets and skills shortages, face the additional challenge of competing against adversaries who leverage automation to accelerate their operations.
Ritasha draws attention to the distinction between securing internal and external workflows. “Internal workflows are always easier to secure as they are already subject to internal security protocols. It is the external workflows which need to be assessed by security architecture and the appropriate security controls need to be put in place.”
Not just a risk
Her point underscores the layered nature of enterprise security. Internal workflows benefit from being housed within known environments and established processes. By contrast, external workflows introduce dependencies on third-party providers, shared platforms and external data exchanges. These areas often demand customised strategies, architecture reviews and heightened control mechanisms.
Adrian points to third-party risks as a key focus area for his organisation. “The Scheme works closely with our external service providers to design and test our technology interactions in the most secure manner possible. The final step to implement any external data integration service is the cybersecurity team’s approval,” he says.
Both Ritasha and Adrian agree that automation cannot be viewed solely as a risk but must also be harnessed as part of the defensive arsenal. Ritasha provides an example of how CCBA deploys automation in real-world scenarios. “We already have systems which make automated real-time decisions in SA. For example a network monitoring tool will detect suspicious behaviour and will automatically quarantine the malware from the network thereby preventing any spread.”
Such systems reduce the time between detection and response, which is critical in containing modern attacks that propagate rapidly. While these tools cannot replace human oversight, they provide first-line defence capabilities that operate at machine speed.
Ritasha adds that AI-based security systems are still in their early stages in South Africa, and that no single tool is sufficient to secure an enterprise environment. She emphasises the importance of layered defences that combine multiple capabilities across detection, prevention and response.
On the other hand, Adrian believes that the role of the CIO is critical in shaping not only the technical response but also the organisational culture around security. “If executives and managers understand the importance of security and compliance standards then they will accept meaningful levels of automation without compromising information security,” he adds.
By framing security as a cultural issue as much as a technical one, Adrian highlights the importance of leadership in embedding security priorities into organisational decision-making.
Public sector realities and workforce readiness
In the public sector, Cathy pointed out that resource limitations create unique pressures. Skills development is constrained by funding and capacity challenges, leaving departments more reliant on partnerships and training initiatives to build resilience.
“We are approaching cybersecurity holistically looking at people, process and technology because the exposure is mainly related to the level of competent human resources. The measures in place would be empowering the human resources on what this means, how it affects them and how to deal with attacks,” she explains.
Partnerships, she added, help fill these gaps. “We are addressing the growing cybersecurity skills gap through partnerships with service providers for on-the-job training, formal and informal training. With the government having limited resources, partnerships compensate for the challenges and assist with development as well.”
Her comments reflect a pragmatic approach in which capacity gaps are filled through collaboration with external providers who can offer training and mentorship alongside technical solutions.
Cisco’s research confirms the scale of the workforce challenge, reporting that 78 percent of South African organisations identified the recruitment and retention of skilled cybersecurity staff as a major challenge. For many organisations this shortage translates into increased vulnerability and slower response times when incidents occur.
Cathy emphasises that cybersecurity success should not be measured only by compliance. “When IT human resources can be conversant with cybersecurity risks and ensure compliance as their daily job and not a tick box exercise, this will reflect a reduction of incidents, knowledge management of incidents and effective resolution turnaround time,” she says.
As automation accelerates, CIOs in both the private and public sectors face a rapidly shifting security environment. The message from these leaders is clear: security cannot trail innovation.
The CIO guide to building lasting cyber resilience
Together the perspectives of Ritasha, Adrian and Cathy highlight several shared lessons for South African organisations:
- Embedding security into design from the outset of automation projects ensures that innovation and protection advance together.
- Leadership support is critical in shaping security culture and balancing the twin priorities of efficiency and compliance.
- Investment in people and partnerships is essential in addressing the persistent skills gap and enabling organisations to manage the growing complexity of AI-driven threats.
















