Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      Koos Bekker sells R2.5-billion in Naspers and Prosus shares

      Koos Bekker sells R2.5-billion in Naspers and Prosus shares

      23 December 2025
      Tribunal clears Vumatel's takeover of Herotel - with conditions

      Tribunal clears Vumatel’s takeover of Herotel – with conditions

      23 December 2025
      Wiocc subsidiary OADC cleared to buy NTT data centres in South Africa

      Wiocc subsidiary OADC cleared to buy NTT data centres in South Africa

      23 December 2025
      Netflix launches Afcon football show, hinting at bigger sports ambitions

      Netflix launches Afcon football show, hinting at bigger sports ambitions

      23 December 2025
      Digital authoritarianism grows as African states normalise internet blackouts

      Digital authoritarianism grows as African states normalise internet blackouts

      19 December 2025
    • World
      Trump space order puts the moon back at centre of US, China rivalry - US President Donald Trump

      Trump space order puts the moon back at centre of US, China rivalry

      19 December 2025
      Warner Bros slams the door on Paramount

      Warner Bros slams the door on Paramount

      17 December 2025
      X moves to block bid to revive Twitter brand

      X moves to block bid to revive Twitter brand

      17 December 2025
      Oracle’s AI ambitions face scrutiny on earnings miss

      Oracle’s AI ambitions face scrutiny on earnings miss

      11 December 2025
      China will get Nvidia H200 chips - but not without paying Washington first

      China will get Nvidia H200 chips – but not without paying Washington first

      9 December 2025
    • In-depth
      Black Friday goes digital in South Africa as online spending surges to record high

      Black Friday goes digital in South Africa as online spending surges to record high

      4 December 2025
      Canal+ plays hardball - and DStv viewers feel the pain

      Canal+ plays hardball – and DStv viewers feel the pain

      3 December 2025
      Jensen Huang Nvidia

      So, will China really win the AI race?

      14 November 2025
      Valve's Linux console takes aim at Microsoft's gaming empire

      Valve’s Linux console takes aim at Microsoft’s gaming empire

      13 November 2025
      iOCO's extraordinary comeback plan - Rhys Summerton

      iOCO’s extraordinary comeback plan

      28 October 2025
    • TCS
      TCS+ | Africa's digital transformation - unlocking AI through cloud and culture - Cliff de Wit Accelera Digital Group

      TCS+ | Cloud without culture won’t deliver AI: Accelera’s Cliff de Wit

      12 December 2025
      TCS+ | How Cloud on Demand helps partners thrive in the AWS ecosystem - Odwa Ndyaluvane and Xenia Rhode

      TCS+ | How Cloud On Demand helps partners thrive in the AWS ecosystem

      4 December 2025
      TCS | MTN Group CEO Ralph Mupita on competition, AI and the future of mobile

      TCS | Ralph Mupita on competition, AI and the future of mobile

      28 November 2025
      TCS | Dominic Cull on fixing South Africa's ICT policy bottlenecks

      TCS | Dominic Cull on fixing South Africa’s ICT policy bottlenecks

      21 November 2025
      TCS | BMW CEO Peter van Binsbergen on the future of South Africa's automotive industry

      TCS | BMW CEO Peter van Binsbergen on the future of South Africa’s automotive industry

      6 November 2025
    • Opinion
      Netflix, Warner Bros deal raises fresh headaches for MultiChoice - Duncan McLeod

      Netflix, Warner Bros deal raises fresh headaches for MultiChoice

      5 December 2025
      BIN scans, DDoS and the next cybercrime wave hitting South Africa's banks - Entersekt Gerhard Oosthuizen

      BIN scans, DDoS and the next cybercrime wave hitting South Africa’s banks

      3 December 2025
      Your data, your hardware: the DIY AI revolution is coming - Duncan McLeod

      Your data, your hardware: the DIY AI revolution is coming

      20 November 2025
      Zero Carbon Charge founder Joubert Roux

      The energy revolution South Africa can’t afford to miss

      20 November 2025
      It's time for a new approach to government IT spend in South Africa - Richard Firth

      It’s time for a new approach to government IT spend in South Africa

      19 November 2025
    • Company Hubs
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • AvertITD
      • Braintree
      • CallMiner
      • CambriLearn
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • LSD Open
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Motoring
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Sections » Information security » Change leaders must put security at the heart of transformation

    Change leaders must put security at the heart of transformation

    Promoted | Treating cybersecurity as an afterthought can turn transformation into a costly recovery effort.
    By Change Logic10 October 2025
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp
    Change leaders must put security at the heart of transformation - Change Logic Keenan Crouch
    The author, Change Logic’s Keenan Crouch

    Change leaders are accustomed to thinking in terms of people and process. These are the pillars of transformation, the levers that guide organisations through mergers, digital rollouts or shifts in operating models.

    Yet today, where technology is ingrained in the heartbeat of every business, process and engagement, a third pillar is no less important. And that is security.

    As a change leader, you would be remiss to treat protection and security as a downstream concern once the change design is set and the people are mobilised. They need to be part of the change blueprint from the beginning, or the cost of neglect could cripple the business.

    The scale of the costs associated with a breach is not a scare tactic; they are real and they could be crippling. In South Africa, the average cost of a data breach in 2024 was R53.1-million, decreasing to around R44.1-million in 2025. This decline could be seen as a positive indicator that security measures are improving, but it remains a staggering figure for any business. What’s even more concerning is that the most serious cases have reached as high as R360-million. These numbers are not guesses; they are balance sheet consequences that can derail or even sink ambitious transformation or change programmes.

    Consequences of back-burner security

    What happens when we leave security too late? In July 2021 Transnet was hit by a ransomware attack that disrupted port and rail operations. The organisation was in the midst of a broader digital transformation aimed at modernising logistics and integrating systems. Instead, it was forced to declare force majeure, revert to paper-based processes and watch as export flows slowed to a crawl. Transformation stalled, reputational damage mounted and the recovery effort became a change project of its own.

    The pattern is familiar across industries. During Capital One’s move to the cloud, a single misconfigured firewall exposed credit card data from more than 100 million people. The eventual cost of penalties and settlements exceeded US$190 million. When Marriott acquired Starwood, the lack of early cyber due diligence meant that an existing breach in Starwood carried over into the merged entity. Regulators fined Marriott £18.4-million, with further multi-state settlements in the US.

    Change LogicEven rapid digital rollouts can be dangerous. In 2021 Microsoft’s Power Apps platform shipped with default public settings, leading to the exposure of 38 million records across airlines, government agencies and consumer brands. Each example delivers the same lesson, transformation without early security input is an invitation for cybersecurity risk to become reality.

    Putting change into security

    We strongly maintain that change management is designed to create clarity during times of disruption. How? It establishes the processes, communication lines and governance structures that enable complex change to occur. Yet if cybersecurity is not part of that scaffolding, change leaders risk leaving the most vulnerable points outside the plan.

    According to IBM’s findings, the average lifecycle of a breach in South Africa can stretch to 227 days before it is contained, and every week that passes without detection magnifies the financial and reputational damage. For projects in which new systems are being deployed or products from external vendors are being integrated, those delays can translate into missed deadlines, spiralling budgets and a collapse in stakeholder confidence.

    Where business is hit the hardest

    The attack vectors that dominate in South Africa are a clue to the link between change and vulnerability. Nearly a fifth of breaches originate from supply chain compromises. Every transformation that involves a new vendor, a systems integrator or a low-code developer is, therefore, a moment of heightened exposure. Unless procurement and contracting processes embed secure configuration and breach notifications from the start, the seeds of the next incident are already planted, just waiting to sprout.

    Financial services have always been, and will always be, the target of attackers. These firms face average breach costs of around R70.2 million, yet PwC reports that only 29% of South African organisations expect to increase their cybersecurity budgets by 6% to 10% for 2025. The mismatch between risk and investment is stark.

    Change LogicChange leaders, who already advocate for resources to support training, communication and adoption, must now also make the business case for security. It is not an ancillary cost; it is part of protecting the value of transformation itself.

    Security must be part of the change process

    Inserting security into the change process isn’t hard, but it does require a shift in mindset. Security should be treated as a formal workstream within every change initiative. That means requirements gathering that includes threat modelling, design reviews that incorporate secure configuration and go-live milestones that are gated by security readiness checks.

    In mergers and acquisition, it means conducting cyber due diligence pre-close and reassessing integration at day one and day 100. In cloud migrations, it means configuring least-privilege access and conducting red-team exercises before production rollout. These are technical tasks, governance and leadership decisions, all rolled into one, and they belong on the agenda of those steering change.

    To succeed, change leaders must be as deliberate about protection as they are about process and people. Security can’t be a bolt-on after the work of change is done. It must be the foundation that ensures the future and success of change.

    • The author, Keenan Crouch, is the executive associate at Change Logic
    • Read more articles by Change Logic on TechCentral
    • This promoted content was paid for by the party concerned


    Change Logic Keenan Crouch
    Subscribe to TechCentral Subscribe to TechCentral
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleTCS+ | Cloud On Demand’s Senzo Mbhele on the benefits of the AWS distribution model
    Next Article Remgro-backed EXSA powers up R87-million solar farm in South Africa

    Related Posts

    Stop chasing busy: why marketing leaders must make strategic choices - Change Logic Natania Pio

    Stop chasing busy: why marketing leaders must make strategic choices

    13 November 2025
    Change management: the missing link in successful digital payment transformation

    Change management: the missing link in successful digital payment transformation

    31 October 2025
    Reassessing change management: why big investments aren't driving impact - Anton Hingeston

    Reassessing change management: why big investments aren’t driving impact

    22 July 2025
    Add A Comment

    Comments are closed.

    Company News
    Why TechCentral is the most powerful platform for reaching IT decision makers

    Why TechCentral is the most powerful platform for reaching IT decision makers

    17 December 2025
    Business trends to watch in 2026 - Domains.co.za

    Business trends to watch in 2026

    17 December 2025
    MTN Zambia launches world's first 4G cloud smartphone solution - Huawei

    MTN Zambia launches world’s first 4G cloud smartphone solution

    17 December 2025
    Opinion
    Netflix, Warner Bros deal raises fresh headaches for MultiChoice - Duncan McLeod

    Netflix, Warner Bros deal raises fresh headaches for MultiChoice

    5 December 2025
    BIN scans, DDoS and the next cybercrime wave hitting South Africa's banks - Entersekt Gerhard Oosthuizen

    BIN scans, DDoS and the next cybercrime wave hitting South Africa’s banks

    3 December 2025
    Your data, your hardware: the DIY AI revolution is coming - Duncan McLeod

    Your data, your hardware: the DIY AI revolution is coming

    20 November 2025

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    Koos Bekker sells R2.5-billion in Naspers and Prosus shares

    Koos Bekker sells R2.5-billion in Naspers and Prosus shares

    23 December 2025
    Tribunal clears Vumatel's takeover of Herotel - with conditions

    Tribunal clears Vumatel’s takeover of Herotel – with conditions

    23 December 2025
    Wiocc subsidiary OADC cleared to buy NTT data centres in South Africa

    Wiocc subsidiary OADC cleared to buy NTT data centres in South Africa

    23 December 2025
    Netflix launches Afcon football show, hinting at bigger sports ambitions

    Netflix launches Afcon football show, hinting at bigger sports ambitions

    23 December 2025
    © 2009 - 2025 NewsCentral Media
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}