The inaugural 2025 IT Indaba saw iOCO executives Jan-Jurgens van der Walt (business unit head of technology) and Neil van Wyngaard (solutions architect) and XTND’s Johan van Dyk (executive head, forensic services) come together in a session where they made the case for weaving security into the DNA of every organisation.
Jan-Jurgens and solutions architect Neil led a discussion at the 2025 IT Indaba dubbed Inside out: Redefining security across people, process and technology, where they highlighted the need for secure design and automation at every level. Jan-Jurgens pointed out that most organisations still treat it as a final step rather than a foundation, but he takes the opposite view. His team, he revealed, engages with security teams at the start of each project, embedding protection into their design and coding practices.
“Our analysts and developers assume that every new feature, every API we deploy and every line of code we write could and most probably will be targeted in an attack. If you have that mindset, it changes everything,” he said.
For Johan, who is the executive director of forensic services at XTND, the human factor remains the greatest threat. He recalled a case where a company’s printer, still using the default password, gave hackers full network access. His point was that even the best tools cannot compensate for careless or dishonest behaviour. He urged firms to go beyond basic background checks and adopt integrity testing to reduce risks.
“In our business, we make use of voice technology, which is not intrusive at all. It can be done by telephone, it is not language dependent, and it helps us test honesty before we employ or appoint people. Several of our cyber security partners now use it to ensure their people are doing what they are supposed to do,” he said.
iOCO's Neil argued that technology’s real strength lies in removing opportunities for human error. He described how automated onboarding processes can control access rights more precisely than manual IT setups.
“If the process of giving people access to resources was automated, you can prevent people from having access to systems they are not supposed to have access to. The automated process can continuously scan these resources and immediately flag anomalies,” he said.
Buy-in from leadership
As the discussion turned to process, Jan-Jurgens explained that embedding security requires both governance and habit.
Teams must integrate secure code reviews into every phase and discuss lessons from security incidents as part of their evaluation process. He stated that support from business leaders makes the difference between compliance and company culture.
“Security should not be about adding a gate. It should be about creating secure habits and making them part of your delivery process. If you combine good practices with clear governance and leadership backing, teams realise that security enables better systems,” he said.
Neil agreed, adding that security becomes sustainable only when people no longer view it as a chore. By automating routine checks, organisations can make safety invisible and effortless.
“If the security becomes invisible, sitting behind the scenes while automation maintains it, people don’t mind because they don’t have to do it. The moment it becomes a chore, they avoid it or make mistakes. Automation takes that burden away,” he said.
Regarding the question of balancing automation with the need to create employment, Johan maintained that automation only exposes inefficiency. He revealed that productivity rose sharply at his firm after adopting AI and process automation, but no one lost their job. Instead, employees were trained to work alongside new tools.
“We had seventy-five people three years ago, and we still have seventy-five today, but our turnover has grown dramatically. Those who embraced AI became more efficient and valuable. It’s about mindset. You need to contribute, not just hold a position,” he said.
The session concluded with an explanation from Neil regarding the vulnerabilities of AI. He explained that sensitive data should never be stored in large language models. The solution, he proposed, is to separate generic and confidential data.
“You can’t put sensitive information into the model. Keep it in a database, expose it via an API, and use two AI layers. One determines the intent, the other verifies the user before retrieving data. That way, you can’t hack the AI,” he said.
















