
South Africa: Building Lasting Cybersecurity Culture for Compliance
Natalie Borcherds, Security Services Manager and Nikishca Moolman, Information Security Consultant at Galix. Cyber security training remains one of the most persistent challenges in corporate South Africa, not because organisations don’t invest in it, but because too many still treat it as a once-off exercise. Ticking a compliance box and moving on. The result? Employees forget what they learned, threats evolve and the organisation stays vulnerable. But it doesn’t have to be this way. According to Nikishca Moolman, Information Security Consultant at Galix, the organisations that get security right are those that stop treating it as a technology problem and start treating it as a people problem. “When cyber security is woven into the DNA of the business, it becomes a natural part of daily processes and decision-making rather than a once-off intervention,” she says. Cultural change in any organisation begins with leadership. When executives visibly champion cyber security, it sends a clear signal to every level of the business. Equally important is how leadership responds when things go wrong. Stepping in to support rather than reprimand reinforces the message that cyber security is a shared responsibility, not a stick to punish people with. Making training personal is another powerful lever. Natalie Borcherds, Security Services Manager at Galix, has seen this firsthand: “When people understand how cyber security affects their families, homes and bank accounts, it quickly shifts from an abstract work requirement to a personal priority,” she says. Real-world examples drawn from social media habits or everyday interactions help employees recognise threats they’ve actually encountered, turning abstract lessons into genuine habits. A blanket training approach is one of the most common mistakes organisations make. Different departments face different threats, and treating everyone the same, says Moolman, is “setting yourself up to fail”. Finance teams are prime targets for fraud and phishing. HR handles sensitive employee data. IT holds the technical keys to the entire organisation. Each of these teams needs training that reflects their actual risk landscape. Moolman recommends regular risk profiling at a department and role level – ideally at least once a year – to ensure training stays relevant. “You can’t manage what you don't know,” she notes. The practical framework she advocates is built in layers: baseline training covering password hygiene and phishing awareness for everyone; role-specific content tailored to each department’s tools and risks; scenario-based learning that makes consequences tangible; and regular refreshers to keep pace with an evolving threat environment. Importantly, this doesn’t require expensive bespoke systems, organisations can adapt real-world incidents from the news and use the tools they already have. Artificial intelligence is reshaping how organisations deliver security training, offering the ability to personalise content, simulate threats and scale awareness programmes across large workforces. But Moolman urges caution. “AI can be a best friend or a worst enemy,” she warns. The risk she highlights most is one many organisations overlook: employees inadvertently exposing sensitive data when engaging with AI tools. Seemingly harmless prompts such as uploading documents, describing workflows, sharing personal details can contribute to a growing digital footprint. “Everything you do leaves a footprint on the internet,” she explains, and AI systems can quietly use that information in ways users never anticipated. Borcherds adds that AI-driven training still needs to be grounded in real-world scenarios relevant to the organisation, not just generic content served by an algorithm. Over-reliance on automation can also dull human oversight, and poorly developed AI platforms can produce flawed guidance. The key is balance: using AI to extend the reach and relevance of training while preserving the human jud
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Finish Reading the Full Story and the Expert Analysis.
Get the latest legal & regulatory intelligence in South Africa
Wansom is AI and can make mistakes.
