Direct Transact CISO Dirk Labuschagne shares why CIOs must shift cybersecurity to the boardroom

post-title

Direct Transact CIO Dirk Labuschagne discusses why IT chiefs in the financial services should convince their boards to invest in a three-pronged defence approach.

If you still view cybersecurity as an IT issue confined to server rooms and firewalls, you are already on the back foot. The battlefield has shifted. Today, financial services organisations are in the crosshairs of various new breeds of adversaries: nation-states seeking to destabilise economies, multinational syndicates running billion-dollar rackets and corporate entities engaged in industrial espionage and sabotage. Coupled with the disruptive potential of AI and quantum computing, the threat landscape is more complex and dangerous than ever.

For the financial sector, a breach is no longer just a data leak. It’s a direct threat to the stability of highly interconnected national payment systems, customer trust and economic stability. Recent widespread IT outages caused by supply chain vulnerabilities are a stark warning that your security is only as strong as your weakest vendor.

In this high-stakes environment, and as an industry veteran, it is my pleasure to share my team’s strategic cybersecurity playbook with our industry peers, because we are in this together after all.

Cybersecurity today needs to be built on three pillars:

Pillar 1: The human firewall – your first and last line of defence

Technology alone cannot save you. The weakest point will always be how employees behave in the digital environment. Their knowledge and vigilance have not kept up with the pace of criminal innovation.

Phishing training is a must. It’s a well-known statistic, but it bears repeating: over 90 percent of successful cyberattacks begin with a phishing email. Annual tick-box training is obsolete. You need continuous, simulated phishing campaigns that adapt to new tactics and provide immediate, constructive feedback.

Ransomware tabletop exercises are a dress rehearsal for reality. These drills are arguably the most critical preparedness activity you can undertake and must involve your entire organisation, not just the IT department. It helps you test and refine incident response plans, identify shortcomings and improve communication between departments.

During a simulation, IT handles technical containment, legal ensures compliance with notification laws, PR manages the reputational crisis, and the executive team coordinates with negotiators and makes important decisions. It’s a full-team sport and we run them company-wide every year.

HR is a cybersecurity function: Your people strategy is integral to your security and vetting is an essential part of the process. It’s essential to conduct rigorous background checks during recruitment.

Treat your cybersecurity talent exceptionally well to ensure retention. A disgruntled insider is a catastrophic risk, while retaining top expertise is a massive strategic advantage. As I learnt from Harvard, you can never be fully covered for vulnerabilities, but a motivated, vigilant team is your best asset.

Pillar 2: The technology shield – vigilance, patching and zero trust

The sophistication of attacks today demands an equally sophisticated tech defence. You can have the best software in the world, but if it’s not patched and backed up all the time, you’re vulnerable.

Vulnerability and patch management: The volume and speed of threats make proactive patching a top priority. Test before you deploy. When Microsoft releases new patches, my team never rolls them out directly to production. We thoroughly test them first to ensure they don’t break anything in our complex environment. A rushed patch can cause an outage as damaging as an attack.

Adopt a ‘zero trust’ architecture: The old “trust but verify” model is dead. Operate on the principle of “never trust, always verify”. Segment your networks and enforce strict access controls to ensure a breach in one area doesn’t become a network-wide catastrophe.

Balance data privacy with productivity: Tools like Microsoft Intune are excellent for managing devices and data, but they must be supplemented. We layer them with advanced endpoint protection from leaders like Trend Micro and enforce biometric authentication and other solutions for added security steps that are difficult to bypass.

Scrutinise your antivirus and code: Don’t just set and forget your antivirus solution. Partner with a supplier known for constant improvement. In the age of AI-generated code, tools like SonarQube are indispensable in our DevOps pipeline to check for bugs and vulnerabilities before deployment. AI is powerful for updating legacy systems, but its output must always be rigorously vetted.

Hire companies to try and hack you: Every year, when we strive to reach the top cybersecurity certifications, we hire external experts to attempt to breach us.

Pillar 3: The compliance backbone – navigating the regulatory maze

The National Institute of Standards and Technology (NIST) framework, built on the classic five pillars of identify, protect, detect, respond and recover, remains the foundational guide. A sixth pillar, governance, was also added recently. It is non-negotiable for establishing robust detection and monitoring capabilities.

For anyone handling card data, PCI DSS 4.0.1 is a non-negotiable standard in secure payment processing. It’s a strategic commitment to security by design, and that’s what makes it so challenging – but such an important validation of your company’s security standards. This standard is now mandatory, while others like ISO remain guidelines.

The South African Reserve Bank’s recently updated cybersecurity joint standard is not a suggestion, it’s essential to follow the local cybersecurity directives. It is a direct instruction to the industry to fortify our national financial infrastructure. Every financial institution must be fully compliant to safeguard the National Payment System.

It’s time to shift cybersecurity from an IT problem to boardroom priority

The era of delegating cybersecurity to the IT department is over. The threats and consequences are too severe. To protect our institutions and the customers who depend on them, cybersecurity must be a standing, strategic risk item on every board agenda. The c-suite must understand the risks, allocate resources and champion a culture of security from the top down.

My call to action to the financial industry, and other top industries, is to get board level and executive support to run regular company-wide, human ransomware and phishing exercises, to conduct thorough, immediate audits of vulnerability and patch management protocols and third-party supply chain vulnerabilities, and to map your current security posture against the NIST Cybersecurity Framework and the SARB directive.

The integrity of our financial ecosystem is at stake. We have a duty to protect it together.

Related articles

CIOs, your attackers may already be inside

CIOs still approach cybersecurity as if attackers are trying to “break in”. That thinking is outdated. Modern cybercriminals are not smashing through firewalls wearing hoodies in dark rooms. They are logging in through the front door using stolen credentials, hijacked Microsoft 365 accounts and employees who unknowingly hand over access every single day.

CTIO Hans Zachar puts people first

Hans Zachar, 2025 CIO Awards Cybersecurity award-winner, built Nutun’s international technology platform with the same quiet discipline that shaped his life growing up in Edenvale. For the group chief technology and information officer, global scale, trust and innovation have always been about people first – and systems second.

CIOs discuss AI, automation and the fight to protect our data

As AI and automation continue to proliferate in workplaces, there is growing tension in boardrooms across South Africa as cyber threats become an increasingly pressing issue for CIOs. IT leaders unpack how they are building cyber resilience while enabling innovation in their organisations.

Top