The recent Google Cloud breach serves as a sharp reminder that even the most advanced platforms are vulnerable. glu CIO Sibusiso Mbingo says the incident highlights key priorities for CIOs and CISOs.
Financial services face an increasingly complex threat landscape, with AI accelerating the scale and sophistication of attacks. For glu CIO Sibusiso Mbingo, resilience depends on combining strong technical defences with a culture of awareness, while aligning cybersecurity to broader business goals.
“The recent Google Cloud breach is a reminder that even the most advanced platforms are vulnerable,” says Sibusiso. He believes CIOs must rethink their priorities, with identity and access controls, zero trust frameworks and secure by design principles at the top of the agenda. Attackers are increasingly targeting APIs and recovery systems, which Sibusiso says must be hardened. Just as importantly, he stresses that security must be aligned with business strategy. Translating technical risk into business impact is key to gaining executive support.
Sibusiso warns that AI is reshaping the tactics and sophistication of cybercriminals. “Threat actors use AI to automate phishing campaigns, generate deepfakes and tailor scams using behavioural data, making social engineering more effective,” he explains.
“We are also seeing a rise in AI driven payment fraud, where attackers exploit transaction patterns and execute real time fund extraction.” Open banking environments and third party integrations are becoming attractive targets, making AI-powered defences critical.
Sibusiso recommends adopting AI threat detection, strengthening identity and access controls and proactively monitoring for synthetic fraud and anomalous behaviour to mitigate the risks posed by these emerging threats.
Defence against emerging cyber risks
When it comes to defence, he highlights the importance of behaviour-based detection. “AI threats don’t knock, but they slip in silently. That’s where behaviour based detection becomes our frontline defence,” he says. By monitoring patterns such as login habits, device usage and interaction timing, these systems can flag anomalies in real time.
Sibusiso notes that they are particularly effective against threats like deepfakes and AI generated phishing which may look legitimate but behave abnormally. “By learning and adapting continuously, behaviour-based tools help detect synthetic identities, prevent account takeovers and reduce false positives,” he adds.
Technology on its own is not enough. “Human error accounts for more than 80 percent of breaches,” Sibusiso points out. He believes that financial organisations must integrate robust technologies such as encryption, threat detection and zero trust frameworks with cultural measures like phishing simulations and training.
Measuring success is also a key factor in determining the efficacy of cybersecurity measures. Sibusiso recommends implementing metrics such as simulation results, training engagement, incident response time, employee reported threats and patch management rates.
Zero trust remains central to resilience. “Identity and access management must enforce strict authentication and role-based access. Least privilege access should be the norm,” he continues. He also points to continuous monitoring and analytics to detect anomalies, micro segmentation to limit lateral movement and endpoint checks to ensure device security before granting access.
Leveraging AI for threat detection
Looking ahead, Sibusiso sees a major role for AI in anticipating future risks. “By analysing historical attack patterns, user behaviour and threat intelligence feeds, AI can identify emerging risks before they materialise,” he explains.
He notes that behavioural analytics can flag insider threats, natural language processing (NLP) can scan dark web chatter for early signs of attacks, and graph-based AI models can predict lateral movement paths. “This proactive approach enables better resource allocation, faster prevention and more resilient security postures,” he adds.
Sibusiso also underscores the role of customer communication in reducing fraud risk. “Clear, timely and multi channel communication is key,” he says. Real time alerts, educational messages, consistent branding and two way verification channels are all effective tools. Tracking phishing report rates, alert response times and training engagement allows organisations to measure their impact.
For CIOs looking to strengthen resilience against AI driven attacks, Sibusiso offers a clear set of priorities. “Implement AI powered threat detection. Adopt a zero trust model to limit access. Train employees on AI enabled social engineering tactics. Use threat intelligence platforms to anticipate emerging threats. And continuously track detection speed, incident response time and user behaviour anomalies to improve resilience.”
















