News

Home » News » InfoTeam International Hosts High-Level Cybersecurity & Identity Roundtable in Johannesburg as AI and Emerging Threats Redefine Enterprise Risk

InfoTeam International Hosts High-Level Cybersecurity & Identity Roundtable in Johannesburg as AI and Emerging Threats Redefine Enterprise Risk

Johannesburg, 15 November 2025 – InfoTeam International convened senior cybersecurity, identity, and risk leaders on 13 November at the NH Sandton for a focused Executive Roundtable examining the rapidly evolving threat landscape and the regional implications of AI, identity transformation, and enterprise resilience. The event was proudly partnered by Ping Identity.

The closed-door summit brought together some of South Africa’s most influential CISOs, identity architects, and technology strategists for a half-day of structured discussions followed by an evening networking dinner. Delegates explored the business and societal shifts shaping cybersecurity in the region, and the escalating pressure this places on security leaders and the organisations they protect.

The session was moderated by Steve Benton,  Independent Strategic Cyber Advisor with InfoTeam International and member of the Global CISO Advisory Council at CyberMindz.

Business Interruption Becomes the Defining Cyber Risk

Industry leaders at the event agreed that cyber attacks have moved well beyond data theft. The region is now witnessing a surge in incidents capable of halting business operations entirely.

Recent disruptions, affecting institutions such as the National Health Laboratory Service (NHLS), South African Weather Service, and the Department of Public Works, mirror high-profile international outages at major UK retailers and manufacturers.

“Digital dependence has created a perfect storm,” said one participant. “A single cyber incident can stop an entire enterprise, supply chain, or critical service.”

Experts at the roundtable warned that today’s attacks are more destructive, more targeted, and potentially indicative of new modes of cyber extortion and geopolitical cyber aggression.

AI: A Force Multiplier for Both Attackers and Defenders

A dominant theme was the transformative impact of artificial intelligence, now embedded in organisational growth strategies and equally leveraged by threat actors.

Attendees highlighted the dual-edged nature of AI:

  • Attackers are using AI to enhance reconnaissance, exploit vulnerabilities faster, and generate highly convincing social engineering content.
  • Defensive teams face pressure to integrate AI safely, ensuring identity control and system governance keep pace.
  • AI agents will soon operate autonomously within enterprise environments, requiring rigorous identity, credential, and access oversight.

Several security leaders emphasized the need for AI-specific business continuity and disaster recovery planning, noting that traditional RPO and RTO assumptions may no longer be sufficient.

Identity Emerges as the New Security Battleground

Participants agreed that identity, not the network, has become the primary perimeter in modern security architecture.

With human, system, machine, and AI-agent identities projected to grow exponentially, organisations must modernise identity and access management (IAM) to meet the demands of connected enterprises.

Key observations included:

  • Unified identity strategies across the workforce, partners, and customers are increasingly achievable and necessary.
  • Siloed identity infrastructures can be orchestrated under a centralised strategy while organisations transition to long-term models such as decentralised identity.
  • Many IAM programmes fail due to under-resourcing rather than technical limitations.

“Identity is now a business-critical capability,” noted an InfoTeam International spokesperson. “It must be treated as a strategic investment aligned to digital transformation, not just a technical function.”

Regulation Accelerates, but Security Fundamentals Still Matter

With the EU AI Act, global privacy frameworks, and South Africa’s forthcoming National AI Policy, regulation is evolving faster than in previous technology cycles. Still, roundtable participants cautioned organisations against waiting for legislation.

Security leaders recommended applying foundational information security principles, least privilege, CIA triad, and ISMS governance to prepare for regulatory alignment and ensure AI-driven transformation remains secure and ethical.

Delegates also agreed that data ethics will become increasingly relevant as traditional data privacy frameworks struggle to keep pace with the scale and speed of AI systems.

Resilience by Design and the Human Factor

A highlight of the roundtable was Grace Tabea Letseka, Head of Resilience and Data at FNB South Africa and Board of Director: Academic Relations and Education at ISACA South Africa Chapter. Grace shared insights from her “Resilience by Design” framework, underscoring the importance of aligning cyber programmes with business outcomes. Key takeaways included:

  • Quantifying the financial and revenue impact of cyber risks helps sustain board-level engagement.
  • Security must adapt to each business function rather than imposing uniform controls.
  • Human resilience remains the foundation of organisational resilience.

A growing theme was the mental and emotional toll on cyber professionals. With burnout escalating across the industry, delegates pointed to organisations like Cybermindz, which specialise in psychological support for cyber teams, as essential partners in strengthening long-term resilience.

“We cannot secure the enterprise if we do not support the people defending it,” one attendee stated.

A Path Forward: Segmentation, Modern IAM, and Adaptive GRC

The final session focused on practical next steps for regional organisations:

  • Segmenting legacy environments to enable safe innovation. 
  • Scaling IAM as a strategic imperative with proper funding and visibility.
  • Transforming GRC into an adaptive, business-embedded function capable of keeping pace with modern change cycles.
  • Deepening collaboration across public–private partnerships, national cyber hubs, and sector-focused CSIRTs.

Participants agreed that South Africa’s cyber maturity continues to advance—but shared intelligence, identity modernisation, and human resilience will determine the region’s readiness for the next wave of digital disruption.

Driving Transformation through Modern IAM and Adaptive GRC

The roundtable concluded with a dynamic panel led by Tichaona Zororo, Director, Digital & Cybersecurity Advisory at EGIT | Enterprise Governance of IT (Pty) Ltd, focusing on the practical steps organisations must take to modernise their security and governance frameworks in the era of digital transformation. Tichaona emphasised the need to segment and compartmentalise legacy systems, enabling safe pools of innovation while protecting critical legacy infrastructure. The discussion highlighted that IAM must scale strategically, requiring business-driven approaches and adequately resourced teams, as under-resourcing is often the key reason IAM initiatives fail. 

The panel also stressed the importance of adaptive GRC, encouraging teams to move beyond “ivory tower” processes to engage directly with business units, enabling faster, agile, and context-aware governance aligned with organisational change. Finally, collaboration across public–private partnerships, sector CSIRTs, and national cyber hubs was underscored as essential for sharing threat intelligence, driving resilience, and supporting a thriving, digitally secure ecosystem in South Africa.

InfoTeam International to Return in Early 2026

Following the success of the 2025 roundtable, InfoTeam International confirmed it will return to Johannesburg in early 2026 to continue the dialogue. Next year’s sessions will expand to include a deeper regional focus on Secure Access Service Edge (SASE) and its transformative impact on cloud security, identity strategy, and enterprise connectivity across Africa.