Experts at Executive Breakfast Summit urge board-level accountability, skills investment
Ezulwini, Royal Villas — Cybersecurity can no longer be left to the IT department alone. That was the clear message from industry leaders at the Executive Breakfast Summit held at Royal Villas this week.
“Cyber risk oversight belongs in the boardroom, not just the server room,” said Kudakwashe Charandura, Director: Cyber Advisory at SNG Grant Thornton.
Speaking during the event, Charandura stressed that organizations must conduct continuous assessments and actively monitor their networks. “You need to know what people are doing on their devices. The nature of cybersecurity is complex, and there are many blind spots that hackers can exploit.”
Dire Agnes, Chief Executive Officer, warned that technology spending is not a silver bullet. “Many organizations have invested significantly in systems and controls, but investment does not equal resilience.”
She pointed to increasingly sophisticated threats: ransomware, fraud, third-party vulnerabilities, and new risks introduced by AI. “The challenge is not to resist digital transformation, nor is it possible to eliminate every single risk. Our challenge is to govern risks, protect critical assets, and respond to disruptions as we become digitally enabled.” Agnes said this requires accountability at board and executive level. “It requires honest discussions about where we need to improve and where we are.”
Oupa Mbokodo, Director and Exco member, highlighted a critical gap. “There is a shortage of skills, not only in cyber but across the technical space — engineering and even more so in cyber.”He said the solution lies in partnerships. “Organizations don’t invest enough in people development when it comes to cyber. We need on-the-job training. Partnerships with vendors can complement internal teams, not only from a people perspective but also technologically.”
Andisiwe Kayoni, IT Governance and Enterprise Architecture Specialist at Central Bank, called on business leaders to take the lead. “Our strategy has to be formulated. Our governance cannot lack, even if there is no legal stipulation or regulatory requirement yet.”She added: “When governments make laws, they follow basic practices that they learn from us. In 10 years, when they start speaking about data governance, they will find us ahead.”
Kayoni ended with a stark reminder: “Everything can be outsourced in AI, but accountability can never be outsourced. If something goes wrong in the organization you are in, you will be held accountable. Find a way to communicate that with your third party.”

