Speaking exclusively to CIO South Africa, Palo Alto Networks chief information officer Meerah Rajavel explains why offline power outages do not solve your security issues, sharing a global playbook for local digital transformation.
When Meerah Rajavel, chief information officer at Palo Alto Networks, recently engaged with CIO South Africa, she brought a wealth of international expertise directly to our local context.
Drawing on her journey from a small town in India to the helm of a global cybersecurity giant, Meerah details how South African organisations can navigate the tight margins of emerging markets by establishing visibility, protecting software pipelines, and adopting an AI-first architecture.
In this sharp and engaging discussion, she explains why security must be baked into technology from the start – much like oil in a delicious recipe – and why curiosity remains the ultimate skill for the next generation of digital leaders.
South African enterprises are adopting generative AI fast but without mature security governance. What is the single biggest blind spot you see in organisations moving quickly on AI adoption?
Visibility is the single biggest blind spot when organisations adopt AI. If you do not know how AI is being used in your company, you cannot secure it. There is tremendous goodness in AI from a productivity perspective, but you must have visibility of every single third-party AI or large language model being accessed. Once you establish visibility, you can put the necessary guardrails and policies in place to ensure people are using it safely.
As organisations move from safety to building applications, security must protect the entire software supply chain. In our case, we have 9,000 engineers doing spec-based coding and vibe coding. We must ensure malware does not infect the software we distribute, which means protecting endpoints, managing model posture, and implementing runtime protection against prompt injections.
Security is a maturity curve starting with visibility, leading to specific use-case protection, and finally agentic protection. We must remember that security is trying to catch up with how fast AI is moving.
Local CIOs are facing pressure to show return on investment on AI, especially on tight budgets. What is a realistic first step for a mid-sized South African company to secure its AI usage without a large enterprise budget?
My advice for mid-sized organisations on tight budgets is to go back to the basics, because technology by itself never produces business outcomes. It must be combined with a clear understanding of the specific business problem you are trying to solve. Throwing AI at people without clarity leads to token burn and runaway costs. It is crucial to focus on the people, processes, and technology, as AI requires a complete paradigm shift.
We must rethink our policies and processes with an AI-first mindset. For example, when we introduced our personal assistant, Panda AI, we realised that 99.9 percent of travel and expense requests were approved anyway. Instead of a traditional approval workflow, we reimagined the process using probability-based AI.
By designing our workflows around AI-first principles before throwing expensive technology at the problem, the business value can easily exceed the cost, sometimes yielding up to a 20-fold return. This is how organisations can achieve significant success in resource-constrained environments.
A lot of local thinking is focused on keeping the human in the loop. You speak about building with an AI-first approach. How do you reconcile these two perspectives?
Humans in the loop and humans on the loop represent two very different ways of designing processes.
Human in the loop is like working with a business partner – the AI assists the human, where you do a step and the AI does a step.
In contrast, human on the loop means the AI does the entire job while the human acts as a watcher, trainer, and guide. This is similar to training an intern who gradually learns and becomes autonomous.
An AI-first approach does not mean eliminating humans, but reimagining processes based on the specific use case. For highly critical outputs, like publishing financial statements, you absolutely want a human in the loop.
For other tasks, such as generating marketing documents, you can have a human on the loop to monitor and provide feedback. Ultimately, regardless of the model you choose, you must rethink your workflows so they are designed for an AI-first world. This ensures we are using technology effectively and efficiently.
How should CIOs in emerging markets think differently about AI-driven attacks – such as deepfakes, AI-generated phishing, and agentic malware – compared to their peers in the US or Europe?
Cyber adversaries do not differentiate between emerging and developed markets; they only care about finding the path of least resistance. If their primary motivation is economic, they will target organisations where it is easiest to get in and where the money is.
Therefore, chief information officers in South Africa must secure their environments just as stringently as their global peers, ensuring their security is tightly integrated across the business.
Because AI-driven attacks happen incredibly fast, it is very difficult for humans to intervene in the middle of an active breach. If you do not have solid guardrails and a kill switch, these attacks can spiral out of control very quickly.
Furthermore, heavy-duty AI workloads require substantial compute and power, which can introduce physical infrastructure constraints. Security must be real-time and automated so that systems can instantly respond and defend themselves against fast-moving threats, rather than relying on slow manual human interventions.
South Africa has well-documented cybersecurity skills shortages and a talent drain. As a female leader, what is your view on how South Africa can build and retain its cybersecurity talent pipeline?
Building a cybersecurity talent pipeline does not begin with higher education; it must start much earlier by getting young children interested in technology. Cybersecurity is a layer on top of that foundation, and AI is changing the landscape completely.
Because attacks are now launched by AI, we can no longer rely solely on humans – we must fight AI with AI by combining cybersecurity domain expertise with AI knowledge from the start. Human-led, manual security is no longer sufficient to counter the speed and sophistication of AI-powered attacks so AI-driven defense is therefore absolutely crucial.
We cannot stop skilled professionals from moving where they want to go, but we can foster curiosity and continuous learning.
When I spoke to high school students recently, they were intrigued by cybersecurity, seeing it as a thrilling cat-and-mouse game between protectors and adversaries.
In this industry, you can never just release a product and relax; you must constantly reinvent yourself to stay ahead. Fostering this excitement from primary school onwards is key to building a resilient pipeline for our country.
Palo Alto Networks invests heavily in upskilling engineers internally on AI. Is there a version of this model that could be used for African economies, where there is less capital to invest per employee?
At Palo Alto Networks, we expect our employees to invest in their own upskilling, rather than the company doing it for them. AI is evolving so rapidly that by the time you finish a traditional course, the technology has already changed.
In 2023 everyone talked about large language models, in 2024 it was copilots, in 2025 it was autonomous agents, and now we are focusing on harness engineering to extract real value from these models.
To replicate this in resource-constrained environments, organisations should foster a culture of self-learning and experimentation.
In my own department, we host a weekly peer-to-peer session called AI Warriors, where hundreds of people share practical concepts they have implemented. It requires no massive corporate budget – just a platform for people to experiment, learn, and tinker.
Even as a global leader, I have my own AI lab at home because staying on top of technology requires hands-on curiosity and active exploration.
Loadshedding, unreliable connectivity, and power constraints are everyday realities for South African IT teams. How should security strategies adapt in an environment where uptime and power reliability cannot be taken for granted?
Loadshedding, unreliable connectivity, and power constraints are fundamental infrastructure realities for South African IT teams. AI is simply a layer on top of technology, so it relies on the same foundation as other digital transformations.
If the electricity and internet connection are not reliable, you have an output and productivity problem, rather than a security problem. In some ways, if your grid is down and you are offline, cyber attackers cannot reach you anyway because there is no connectivity.
However, the real challenge arises when heavy-duty AI workloads increase your compute and power requirements.
South African organisations must design self-sustaining architectures to manage these power constraints across provinces. Rather than relying on a centralised province that could go down and impact everyone, the security and IT architecture should be integrated and self-contained.
This approach ensures that local systems remain self-sustaining, secure, and resilient even during severe power outages and connectivity failures.
Cloud adoption in South Africa is growing but still lags behind mature markets. What security missteps do you see most often in organisations mid-transition from on-premises to the cloud?
Achieving scale in the era of AI is extremely difficult without cloud adoption because powerful models require immense compute resources that typically run in the cloud. If an organisation remains entirely on-premises, it will inevitably face severe scaling constraints.
However, as token costs rise, we are seeing a shift where organisations are beginning to train smaller, domain-centric models locally rather than relying exclusively on massive public clouds.
These smaller models do not necessarily require expensive graphics processing units (GPUs) to function; they can run on powerful central processing units (CPUs) put together.
Nevertheless, local companies must remain highly thoughtful about their specific use cases and where they invest their limited capital. It is the data that matters far more than the infrastructure alone.
Chief information officers in emerging markets must carefully balance on-premises hardware investments with cloud-based power to avoid expensive infrastructure mistakes, scale safely, protect their assets, and achieve business value.
In terms of data protection, our local laws share DNA with the GDPR, but enforcement and maturity levels differ. From a global CIO lens, what should local companies get right early, rather than treating compliance as a checkbox exercise?
Data sovereignty is a serious concern for modern nations, and every government has its own viewpoint on what is right for its country. Because local laws share DNA with the GDPR, organisations must prioritise data privacy and understand exactly where their data, particularly personally identifiable information, is stored.
However, trying to solve data sovereignty entirely on your own is extremely expensive and complex when managing multiple applications across a modern enterprise.
The most practical approach for local companies is to partner with established solution providers who build robust data sovereignty capabilities into their software. For example, we use local clouds in specific territories to ensure compliance with national laws. By leveraging the built-in sovereign features of your vendors for standard SaaS applications, you can focus your resources on securing the custom systems you build internally.
This turns compliance into a strategic partnership rather than a tedious checkbox exercise that drains your valuable budget.
Public sector and critical infrastructure in South Africa have faced high-profile cyber incidents recently. What is your take on public-private collaboration models that actually work versus those that just look good on paper?
The private and public sectors must collaborate because cyber adversaries only need to be right once, while defenders must be right every single time. It is impossible for any organisation to secure itself in isolation against thousands of sophisticated attackers, especially with growing geopolitical tensions.
When political conflicts arise globally, we consistently see an uptick in cyberattacks across those territories, making collective defence and collaborative intelligence absolutely monumental for national security.
For this collaboration to work, public and private partnerships must move beyond paper-based agreements and adopt platform-integrated security. Security is a solvable problem only if it is real-time, automated, and integrated.
If you are trying to stitch together 50 different disconnected tools, a human defender has already lost the game. We must use AI to fight AI, deploying automated systems that can block in-line attacks, share threat intelligence, and respond to threats in real time to protect critical infrastructure from devastating disruption.
For Women’s Month in South Africa, what is your advice to women and young girls who may not see themselves as executive-level material?
I came from a rural part of India and never imagined I would become a chief information officer, let alone that such a role existed.
My first piece of advice is to believe in yourself. If you put your heart and mind to what you want to achieve, nothing can stop you. We must overcome our own self-doubt and have the confidence to step forward and lead, because self-belief is the foundation of success.
Secondly, do not be afraid to take risks. The worst thing that can happen is that you fail, but you will learn from it, stand back up, and keep moving forward with courage. Finally, stay curious and commit to continuous learning. In a world where technology changes overnight, your curiosity is the ultimate engine that will drive your career. If you have the courage to fall and get back up, you can achieve anything you set your mind to.
















