What happens when a SA CISO answers the call from Dubai?

Richard Ford, group CTO, Integrity360.
Richard Ford, group CTO, Integrity360.

South Africa’s IT skills shortage has been well documented for years, but what gets lost in the noise is what happens when experienced security leaders, not just mid-career professionals, represent a large part of the current shortage – and the remaining few are actively headhunted by overseas employers.

According to a national survey by the CSIR and the Cybersecurity Hub, 62% of cyber security roles in South African organisations are partially or fully unfilled, while a ResearchGate paper established that South African organisations have been struggling to recruit cyber security professionals since at least 2023.

What complicates matters is that this isn’t a localised shortage only. The World Economic Forum's Global Cybersecurity Outlook 2026 shows this trend is present worldwide, and that means everyone is competing for the same thing.

The end result is that the limited number of experienced South African cyber security professionals are also being actively sought by international employers, who have the added advantage of being able to offer remuneration in stronger foreign currencies.

Migration data suggests the pipeline could become thinner still. New World Immigration data looked at 437 IT, software, data and cybersecurity professionals who approached the firm about moving to Australia between 22 April and 22 June this year.

Of those who gave a timeframe, around 70% wanted to leave immediately or within six months and nearly half were aged between 25 and 34.

That last figure should give boards serious pause because of the fact that people in their late twenties and early thirties are entering the stage of their careers where technical specialists begin acquiring broader operational responsibility and future security leaders start to emerge. 

A situation where that layer of talent leaves means South African organisations are losing both experienced senior staff and the pool from which their next CISOs can be developed.

Succession planning before the resignation

It would be a misstep to keep treating this problem as recruitment-based, where monitoring vacancies and benchmarking salaries for difficult positions to fill are the principal point, as that only tells boards something about labour availability. 

It doesn’t answer the more important question of what happens if the person currently accountable for cybersecurity today hands in a resignation tomorrow. A CISO vacancy has obvious consequences during a serious incident where decisions that affect operations and communications with regulators are made. 

Major security investments, risk acceptance and exceptions shouldn’t be left to drift until a replacement arrives, which is why CISO succession belongs in the greater business continuity conversation.

Boards are already accustomed to dealing with key-person risk elsewhere in the organisation, and there’s no reason the same shouldn’t be true for CISOs. 

If senior leadership succession is discussed well before a chief executive or finance director leaves, and potential successors are developed over time, with reporting structures agreed in advance, then cybersecurity leadership deserves the same discipline, especially when the available talent pool here at home is dwindling.

For many organisations, a sensible time horizon is three years. That gives the business time to formulate a roadmap that helps identify someone capable of stepping into greater responsibility and expose that person to the parts of the CISO role that can’t be learned from technical certification alone. 

A future security leader needs experience of board communication and commercial decision-making, and they need to understand how the organisation approaches risk, how an incident escalates and where their authority begins and ends.

These are all considerations that take time, and further still, any succession plan would need to work even before the successor is considered fully ready. 

If the CISO left, do current executives and the board themselves know where decisions sit and exactly how the broad reach of CISO coordination between departments is mapped?

Naturally those questions can be tested in the same way organisations test other elements of resilience. A tabletop exercise, for example, can show whether an incident response plan is too dependent on one individual before a genuine crisis does. 

External capability has a definite role to play as well, since an established incident response relationship can give an organisation access to specialist expertise during a leadership transition and reduce its dependence on knowledge held by one person. This is so efforts can be focused on the continuity of decision-making and response while the business manages the longer succession process.

Fixing the pipeline problem at the source

Then, at the other end of the talent pipeline, South Africa needs more sustained investment in the individuals entering the field where the mindset of developing people locally is part of the longer-term response to the flow of professionals offshore.

MiDO Academy, an NPO proudly co-sponsored by Integrity360, is one example of how young South Africans can be given SETA-accredited training and a route into security careers. Programmes like these will only become more important, given that organisations cannot build their way out of a national talent shortage through salary competition alone.

That investment, however, takes time to reach the top of the profession, and boards still need an answer for the interim years. A security programme that overly depends on one CISO for its leadership, institutional knowledge and decision-making authority quite obviously has a single point of failure. 

South African boards are reasonably good at asking whether their organisation is secure and now the same question must be applied to the person most responsible for protecting it. 

Share

Read more


ITWeb proudly displays the “FAIR” stamp of the Press Council of South Africa, indicating our commitment to adhere to the Code of Ethics for Print and online media which prescribes that our reportage is truthful, accurate and fair. Should you wish to lodge a complaint about our news coverage, please lodge a complaint on the Press Council’s website, www.presscouncil.org.za or email the complaint to enquiries@ombudsman.org.za. Contact the Press Council on 011 484 3612.
Copyright @ 1996 - 2026 ITWeb Limited. All rights reserved.