• Home
  • Opinion
  • The rise of the 'ministers of defence' in South African boardrooms

The rise of the 'ministers of defence' in South African boardrooms

Richard Ford, group CTO, Integrity360.
Richard Ford, group CTO, Integrity360.

South Africans understand continuity better than most. Resilience has come in the form of the generator, the water tank, the UPS, and the make a plan ‘just in case’ attitude that has led to households and businesses building operational muscle memory around the assumption that infrastructure can go down, but life must still carry on.

That same instinct has made its way into the boardroom with the rise of the Chief Resilience Officer, says Richard Ford, Group CTO at Integrity360, and in the ways in which boards are prioritising the speed of recovery over the height of the firewall. 

“Boards have spent years asking whether their organisations are secure enough, but the better question today is whether the business can still operate when security fails. In a threat environment shaped by ransomware-as-a-service, AI-assisted social engineering, and machine-speed vulnerability discovery, prevention has a ceiling.

“Sooner or later, something will get through which means recovery time of both a strategic number and a competitive one.”

In that sense, the CRO is a minister of defence in all but name, Ford quips.

The World Economic Forum’s Global Cybersecurity Outlook 2026 notes that ransomware remains the primary concern for CISOs, while cyber-enabled fraud and phishing have become the leading concerns for CEOs. At the same time, the gap between recovery confidence and real-world recovery is becoming harder to ignore.

“Backups are still vital, but the presence of a backup is not the same as recovery capability. Boards need to know whether backups are protected, whether identity systems can be restored, whether clean environments are available, and whether the organisation has actually tested the sequence of recovery under pressure,” explains Ford.

He adds that while the title of Chief Resilience Officer may not exist in every organisation, the executive-level resilience mandate should, and whether the responsibility sits with the COO, CIO, CISO or another senior leader, the point is ownership rather than the title itself. “The spirit of being a figurative defence minister is what needs to be instilled in the roles.”

In South Africa, the compliance dimension is also very clear. Under POPIA, responsible parties are required to notify the Information Regulator and affected data subjects where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person.

“If recovery is everyone’s responsibility in theory, it often becomes nobody’s responsibility in practice. A named owner gives the board a line of sight across the full lifecycle: detect, respond, contain, recover, communicate and learn.”

The business case is especially strong in South Africa, where many organisations are already operating under uniquely persistent economic pressure. Margins are tight, skills are stretched, and downtime is expensive. A cyber incident that takes a business offline for days can interrupt cash flow, delay service delivery, affect employees, and damage customer relationships that took years to build.

“Resilience means accepting that cyber incidents are business events. It requires tested incident response plans, clear escalation routes, defined communication protocols, measurable recovery time objectives, and visibility of the systems that matter most. 

It also means knowing which services must come back first, which data is essential to operate, and which dependencies could slow recovery when every hour counts. 

The maturity marker for boards should of course encompass how much the organisation spends on defence, but equally important is whether it has named an owner for recovery and tested how fast that recovery actually happens,” notes Ford.

The familiar analogy for South African companies is less about whether the lights will go out, but how a business can keep trading when they do. 

“Cyber resilience is not a pessimistic way to think about security. It really is just a practical one. For that reason, the strongest organisations are not those that assume nothing will go wrong – they are the ones that have rehearsed what happens when it does, and can move from breach to recovery in hours rather than weeks,” he says.

Share

Read more


ITWeb proudly displays the “FAIR” stamp of the Press Council of South Africa, indicating our commitment to adhere to the Code of Ethics for Print and online media which prescribes that our reportage is truthful, accurate and fair. Should you wish to lodge a complaint about our news coverage, please lodge a complaint on the Press Council’s website, www.presscouncil.org.za or email the complaint to enquiries@ombudsman.org.za. Contact the Press Council on 011 484 3612.
Copyright @ 1996 - 2026 ITWeb Limited. All rights reserved.