Galeboe Mogotsi, CISO at Wits University, shares valuable insights and strategies that IT leaders can implement to secure their environments against the growing landscape of cybersecurity risks.
In part two of CIO South Africa’s exclusive interview with Wits CISO Galeboe Mogotsi, he offers insights into cybersecurity and proactively protecting one’s environment, including in his own environment of higher education.
Here, he provides key principles that support an effective cybersecurity framework:
- Risk management is essential – continuously assessing and prioritising potential threats based on the criticality of the assets they affect helps ensure that the most important areas are secured first. Staying proactive by identifying and mitigating vulnerabilities is key to building resilience.
- A multi-layered defence approach – combining various technologies and processes to protect data. Utilising encryption, access control, and secure authentication are standard practices that help safeguard sensitive information. Ensuring that data is encrypted, both at rest and in transit, adds a vital layer of security.
- Incident response preparedness – having a well-defined and regularly tested incident response plan allows institutions to quickly detect, respond to, and recover from potential cyber-incidents. Running simulations and preparedness exercises ensures that the team is ready to act swiftly in the event of a breach, minimising any damage.
- Cybersecurity awareness training – training plays a significant role in strengthening the institution’s defences. Educating faculty, staff, and students on current cyber threats, such as phishing and social engineering, helps reduce the risks posed by human error. Building a culture of vigilance and awareness is critical in any organisation.
“The general approaches of risk management, layered defence, incident readiness, and cybersecurity education are key elements that any organisation can adopt to strengthen its security posture,” he says.
Staying ahead of emerging cybersecurity threats
According to Galeboe, staying ahead of emerging cybersecurity risks, particularly in the higher education sector, requires a proactive and adaptive approach.
“The fast-paced evolution of technology and the increasing sophistication of cyber-threats mean that institutions must remain vigilant and continuously refine their security strategies,” he notes.
“For me, this begins with a commitment to continuous learning and awareness. The cybersecurity landscape is ever-changing, so staying informed about new trends and developments is crucial.”
Galeboe practises what he advocates by attending conferences, participating in industry forums, and engaging with fellow cybersecurity experts. “This ongoing education helps ensure that I am always aware of the latest risks and innovations that could impact the institution,” he adds.
He shares strategies for staying ahead of emerging cybersecurity risks, with a focus on the unique challenges faced in higher education:
- Leveraging threat intelligence and monitoring systems – by using real-time threat detection tools, we can stay on top of potential vulnerabilities as they emerge. Collaborating with cybersecurity organisations allows us to tap into a broader network of intelligence, providing us with early warnings about new threats. These advanced monitoring systems, combined with our connections in the cybersecurity community, help us identify and respond to risks quickly.
- Regular risk assessments and cybersecurity audits – in an environment like higher education, where students, faculty, and researchers often use multiple devices and platforms, the risk landscape is complex. By conducting frequent audits and assessments, we can identify any weaknesses in our systems and adjust our security posture as needed. This proactive approach ensures that we are not caught off guard by emerging threats.
- Collaboration and partnerships – in higher education, working closely with other institutions and cybersecurity experts is vital. By sharing information and best practices, we benefit from the collective knowledge of the sector, helping us stay informed about the latest developments and threats. This collaborative network provides valuable insights specific to the education sector and enhances our ability to address risks effectively.
- Emerging technologies – AI and machine learning have also become integral to Wits’ cybersecurity strategy. These tools help us detect anomalies and suspicious activity by analysing patterns in network traffic and user behaviour. Their ability to identify threats early and accurately allows us to respond swiftly, mitigating potential damage.
Despite these tools and strategies, Galeboe highlights that human error remains one of the most significant vulnerabilities. This holds true across all organisations, including in higher education.
“To reduce this risk, we place a strong emphasis on cybersecurity awareness and training, regularly educating faculty, staff, and students on best practices,” he explains. “Things like recognising phishing and using multi-factor authentication, can significantly reduce incidents resulting from human mistakes.”
"In a collaborative, open environment like higher education, staying ahead of cybersecurity risks demands a multifaceted approach. By combining continuous learning, real-time monitoring, regular assessments, collaboration, and emerging technologies we can maintain a robust, adaptable cybersecurity posture suited to the challenges of today’s digital landscape," Galeboe concludes.
















