Cybersecurity Beyond IT: A governance imperative

RUMBIDZAI MASHAYAHANYA

 

In July 2024, Check Point Software Technologies released a ranking that should have jolted Zimbabwe’s corporate sector into action.

 

Zimbabwe, a country more commonly associated internationally with its currency history than its digital infrastructure, ranked as the third most cyber-attacked nation in the world, not third in Africa, but third globally, ahead of countries with far larger digital economies and significantly bigger cybersecurity budgets.

 

It was the kind of statistic that should have moved cybersecurity from the server room to the boardroom overnight.

 

For many organisations, it has not.

 

Yet the risks are mounting. The Reserve Bank of Zimbabwe’s Financial Stability Report warned that the rapid expansion of digital financial services has outpaced the safeguards designed to protect them, leaving the financial system increasingly exposed to cybercriminals.

 

The Bankers Association of Zimbabwe has also acknowledged that several cyber incidents went unreported in a single year, with unexplained service disruptions often the only visible indication that systems had been compromised.

 

Regulators recorded dozens of cyber-related offences in a single quarter, even as financial institutions processed nearly US$200m through digital channels every day.

 

This is no longer a technical issue confined to IT departments. It is a core business risk that threatens the integrity of the very systems on which modern commerce depends.

 

The question is why the response has lagged so far behind the threat.

 

The answer, according to many within the industry, is not technical but cultural.

 

As one Zimbabwean banking executive observed, cybersecurity has traditionally been viewed as a cost centre—an expense organisations only prioritise after suffering an attack.

 

That mindset reflects a governance failure rather than a technology gap.

 

Firewalls, encryption and intrusion detection systems are engineering solutions to engineering problems. But deciding whether to invest in those solutions before or after a breach, determining the organisation’s risk appetite, and ensuring cyber resilience are governance decisions. They belong in the boardroom, not solely in the IT department.

 

Nor is this challenge unique to Zimbabwe or even Africa.

 

Microsoft now detects around 600m cyberattacks every day across its global ecosystem. The annual cost of cybercrime is projected to approach US$20 trillion, up from about US$8 trillion only a few years ago, while attacks targeting supply chains have risen by more than 400%.

 

The Institute of Internal Auditors’ 2026 Risk in Focus survey ranked cybersecurity as the world’s leading business risk for the fifth consecutive year, with nearly three-quarters of respondents describing it as critical.

 

Yet the same survey found that fewer than one in five organisations believe they exceed the minimum standard of cyber resilience, while roughly half have yet to implement even the basic controls required to identify and manage cyber risk effectively.

 

Across the world, boards are attempting to govern a threat they have not fully accepted as their responsibility.

 

Regulation, however, is moving faster than boardroom practice.

 

Zimbabwe’s Cyber and Data Protection Act of 2021 already imposes statutory obligations relating to data governance, breach reporting and accountability. Meanwhile, ZimCode II, expected to be launched in October, places digital governance and cybersecurity among its central pillars.

 

Globally, regulators are taking the same direction. Europe’s NIS2 Directive, the Digital Operational Resilience Act (DORA), and enhanced disclosure requirements from United States securities regulators all assume one fundamental principle: boards, not merely chief information officers, are ultimately accountable for managing digital risk.

 

The law is increasingly demanding what many boards have yet to embrace voluntarily.

 

Owning cyber risk at board level does not require directors to become cybersecurity specialists.

 

It requires disciplined governance.

 

First, cybersecurity should feature as a standing agenda item at board meetings, receiving the same attention as financial, operational and strategic risks rather than appearing as an annual footnote in an audit committee report.

 

Second, boards should require regular cyber incident simulations, ensuring management rehearses realistic breach scenarios before an actual attacker, or regulator, forces the organisation into a public crisis.

 

Third, reporting from chief information officers and cybersecurity leaders must be presented in clear, business-focused language that enables non-technical directors to challenge assumptions, assess preparedness and exercise meaningful oversight.

 

A board that cannot ask informed questions about its cyber exposure has not exercised governance, it has delegated it.

 

Admittedly, strengthening cybersecurity demands investment at a time when boards face competing pressures on capital allocation.

 

But cybersecurity should no longer be viewed simply as another cost to be contained.

 

It is an investment in organisational resilience.

 

Businesses that cannot demonstrate robust digital governance will ultimately struggle to retain the confidence of customers, investors, regulators and business partners, regardless of the strength of their financial performance.

 

Trust has become a strategic asset, and cybersecurity is increasingly one of its foundations.

 

For a country ranked among the world’s most targeted by cyberattacks, treating cyber risk as background noise is no longer an option.

 

Indeed, neither is it for businesses anywhere else.

 

The organisations that will distinguish themselves over the coming decade will not necessarily be those that avoid every cyberattack—an increasingly unrealistic expectation in today’s threat landscape.

 

They will be those whose boards recognised early that cybersecurity is fundamentally a leadership challenge, invested in resilience before crisis struck, and responded to inevitable incidents with transparency, preparedness and credibility.

 

Cybersecurity was never merely an IT issue.

 

It has always been a governance issue.

 

It is time Zimbabwean boardrooms and boardrooms across Africa started treating it as one.

 

Rumbidzai Mashayahanya heads Business Development and Communications at CEO Africa Roundtable. She writes in her personal capacity.

Related Articles

Leave a Reply

Back to top button