During a panel discussion on The human factor: strengthening workforce readiness for cyber threats at the 2025 IT Indaba, three technology leaders shared insights on how people remain both the greatest vulnerability and the strongest defence against cyberattacks.
Speaking on the panel were Pulana Ngwasheng, head of IT at Avis Budget Group; Sibusiso Mbingo, CIO at glu Mutual and Dr Denisha Jairam-Owthar, CIO at the Council of Medical Schemes (CMS). Together, they explored how organisations can move beyond technical defences and cultivate a security-conscious workforce through culture, education and accountability.
Pulana opened the discussion by underscoring the idea that cybersecurity is no longer just a technology issue.
“Cybersecurity has evolved beyond IT; it’s now an organisational issue that must be part of the company’s DNA,” she said. “You can lose your business from one cyber incident. Every employee needs to understand that protecting information is everyone’s job.”
Pulana added that while investment in systems and tools is important, the long-term safeguard lies in building a cyber-conscious culture.
“We need to integrate cyber awareness into our daily operations and ensure that staff at all levels take ownership,” she cautioned.
For Sibusiso, the conversation always comes back to people. He explained that security training should not be seen as a compliance exercise, but as a shared responsibility.
“When you look at how most breaches happen, it’s rarely because a system completely failed, it’s because a person did,” he noted. “The entry point to a breach can be your receptionist’s desk. That’s why I say cybersecurity is everyone’s business.”
Sibusiso also spoke about the importance of creating what he called a vigilance culture where employees are constantly alert to potential risks. He insisted on the need to build environments where people think before they click, question before they share and understand that every digital action has consequences.
Being prepared
Denisha emphasised that creating such a culture requires collaboration between leadership and employees. She added that complacency is one of the biggest threats.
“Culture is built from both directions. Leadership must champion it, but staff must internalise it. There’s this myth of, it won’t happen to me. But the truth is, the weakest link is often the person sitting between the chair and the laptop,” she observed.
For Denisha, cyber risk is not about paranoia, but preparedness. “Cybercrime is now a global economy, and we have to approach it as such. Awareness, education and behaviour change are not one-off campaigns, they’re continuous,” she said.
Pulana noted that while prevention remains important, organisations must also prepare for what happens when defences fail. She stressed the need for recovery readiness, not just prevention.
“It’s not a matter of if you’ll be hacked, it’s when,” Pulana emphasised. “We need clear plans that outline what happens in the event of a breach. Who leads communication? How do we restore operations? How do we maintain customer trust?”
At Avis Budget Group, Pulana said, regular simulation exercises have become essential. She noted that they run simulated cyberattacks to test not only IT’s response but the readiness of all departments, arguing that cybersecurity is not something IT can do alone.
Denisha agreed, adding that theory is no substitute for practice. At CMS, she said, the organisation conducts live, unannounced simulations to gauge real reactions.
Changing behaviour
“No piece of paper can prepare you for the day it happens,” she warned. “We want to see how people behave under pressure, who freezes, who communicates and who takes initiative.”
She explained that such exercises reveal practical weaknesses that no policy document can predict. Sibusiso argued that annual cyber awareness sessions are no longer effective in today’s fast-changing digital environment.
He noted that expecting lasting behaviour change from just one training session a year is unrealistic, as people quickly forget.
At glu Mutual, Sibusiso said, the company introduced gamified learning modules to keep awareness fresh. He added that artificial intelligence tools now help identify employees who might need extra support.
“We use small, interactive lessons throughout the year, fun but educational. And because it’s ongoing, it becomes part of everyday thinking. We track who clicks on phishing tests, who struggles with certain modules and we give them additional, targeted training. It’s not about punishment, it’s about improvement,” Sibusiso explained.
Pulana echoed this point, noting that accountability must be balanced with empathy. She explained that her organisation uses role-specific training to address unique risks faced by different departments.
“Finance, payroll and marketing all have different exposure points. We tailor their training accordingly,” she said.
Where repeated mistakes occur, Pulana said the approach is corrective, not punitive.
Denisha added that creating internal cyber champions within departments helps to sustain awareness. She noted that when people hear about cyber issues from someone they work with daily, it feels more relatable. She also believes in the power of visual communication.
Real-time visibility essential
“Sometimes people need to see the impact. We show short videos of what happens when an organisation is breached, the downtime, the financial loss and the reputational damage. When employees see those consequences, the message sticks,” she explained.
For Sibusiso, real-time visibility is essential. He noted that you can’t improve what you can’t measure. At glu Mutual, his team uses dashboards to track training participation, phishing test results and security scores across departments.
He also called for cybersecurity to be a standing item on board agendas.
“The board must have line of sight on where we stand, what risks are emerging and how our people are responding. Awareness has to start at the top,” Sibusiso said.
Denisha concluded by reminding attendees that managing cyber risk is a proactive responsibility, cautioning that by the time an audit takes place, the damage may already be done. She encouraged CIOs to raise red flags early, ensure budgets are sufficient and use storytelling to make cyber risks more tangible.
The panellists agreed that while technology continues to evolve, people remain the constant in the cybersecurity equation. They emphasised that the key lies not in fear, but in fostering a culture of collective vigilance.
















