Sasfin Wealth head of IT Reshen Sukhram believes a unified response to cybersecurity is key to corporate survival. He stressed this at the recent CIO Day held in Johannesburg.
While AI innovation took centre stage at the 2025 CIO Day, hosted at the prestigious Marriott Hotel Melrose Arch, cybersecurity was also a dominant theme of the day’s discussions. A live scenario workshop challenged two groups of CIOs to develop distinct cybersecurity strategies under simulated crisis conditions, with only 60 minutes to defend their organisation’s data and reputation.
Reshen stressed that the first step in responding to a cybersecurity attack is assembling a unified, coordinated team. “You need to bring your outsourced security partners on board immediately to assess the breach and devise an action plan,” he explained.
Many ICT teams often fail to develop unified cybersecurity strategies due to competing demands, resource limitations and issues related to integrating legacy systems with modern security solutions. “It’s essential to identify which stakeholders are impacted and partner with them to mitigate the impact. This often results in an expedited response and service restoration,” Reshen continued.

Although the groups built two unique strategies, a shared consensus emerged among the CIOs: an immediate response is paramount in the event of a breach. This necessitates planning and preparation. “You cannot define your response strategy at the time of the crisis,” said an attendee.
Both groups also emphasised the importance of securing data as a critical first line of defence. Incident management was a crucial part of group one’s cybersecurity solution, with the group recommending the appointment of an expert incident commander. In severe cases, this incident commander would have the authority to override the CEO to ensure a quicker system recovery.
While the first group employed a more human-led solution, the second group focused on leveraging AI to augment human decision-making. AI security can detect and isolate malicious IP addresses in real time, automatically initiating a triage and response process after three predefined threat assessments.
A key takeaway from the discussions among the CIOs was that AI, rather than replacing human roles, is transforming how security professionals work. “We’ve come to understand that AI won’t take our jobs, but it will in fact enhance our processes and help us respond more effectively,” one attendee noted.
Once the storm passes, the next phase begins: reflection and continuous improvement. “I think it is also important to note down lessons learnt from the attack and learn from how different departments handled the crisis and improve on future solutions,” Reshen concluded.
















