EPISODE 37: From IT Issue to Business Imperative: Why CHROs Must Lead the Cybersecurity Agenda

Lucas Molefe - Episode 37 - HR Future Live Podcast
HR Future Live
EPISODE 37: From IT Issue to Business Imperative: Why CHROs Must Lead the Cybersecurity Agenda
Loading
/

Cybersecurity is no longer a technical back-office concern – it’s a frontline business risk with direct implications for talent, culture, and organisational resilience. Yet many organisations still treat it as an IT problem rather than a people priority.

Insights from cybersecurity expert Lucas Molefe reveal a critical shift: cybersecurity is now a human issue as much as it is a technological one.

For CHROs, this presents both a risk and an opportunity.

The Real Risk: Your People Are the New Attack Surface

The modern workplace is digital-first. Employees collaborate online, share data across platforms, and operate in increasingly hybrid environments. But with this shift comes vulnerability.

Cybercriminals are no longer just targeting systems – they’re targeting behaviour.

  • Employees clicking on fraudulent emails
  • Finance teams approving manipulated payment requests
  • Executives being impersonated using AI-generated voice or messaging

As Molefe highlights, cybersecurity breaches often occur because organisations assume: “It will never happen to me.”

That assumption is now one of the biggest threats facing businesses.

AI Has Changed the Game (and the Speed)

One of the most urgent developments CHROs must understand is the role of AI in cybercrime.

AI is enabling attackers to:

  • Launch highly targeted attacks at scale
  • Mimic voices, identities, and communication styles
  • Automate campaigns that previously took weeks, now executed in minutes

This means traditional awareness training and outdated policies are no longer enough.

The pace of risk has outgrown the pace of organisational learning.

Why CHROs Must Step In

Cybersecurity directly impacts:

  • Business continuity
  • Employer brand and reputation
  • Employee trust and psychological safety
  • Compliance and governance

And yet, many organisations still lack a people-led cybersecurity strategy.

This is where CHROs must lead.

Because ultimately:

Cybersecurity is a behaviour problem before it is a technology problem.

From Reactive to Preventative: The Leadership Shift Required

A key theme from the discussion is the need to move from reactive to preventative cybersecurity.

Too many organisations wait for a breach before taking action.

But as Molefe explains, that approach is equivalent to learning self-defence after being attacked.

What Preventative Leadership Looks Like:

1. Reframe Cybersecurity as a Business Risk

CHROs should partner with CEOs and CFOs to position cybersecurity as:

  • A revenue risk
  • A reputational risk
  • A workforce risk

This shifts accountability beyond IT.

2. Embed Cyber Awareness into Culture

Cybersecurity training should not be a once-a-year compliance exercise.

Instead:

  • Integrate it into onboarding
  • Reinforce it through micro-learning
  • Use real-world scenarios employees can relate to

Goal: Make secure behaviour instinctive, not instructional.

3. Prioritise Behavioural Design, Not Just Policy

Policies don’t prevent breaches, behaviour does.

CHROs should:

  • Simplify security processes
  • Reduce friction in compliance
  • Use nudges and reminders to guide behaviour

For example:

  • Pop-up warnings before sending sensitive data
  • Alerts for unusual login patterns

4. Address the Cyber Skills Gap Internally

There is a global shortage of cybersecurity expertise, and organisations are feeling it.

CHROs can respond by:

  • Upskilling existing IT teams
  • Introducing cybersecurity learning pathways
  • Embedding digital risk awareness across all roles—not just technical ones

5. Invest in Managed Expertise (Without Overloading Teams)

Molefe recommends leveraging Managed Detection and Response (MDR) services, external experts who monitor threats 24/7.

For HR leaders, this means:

  • Reducing pressure on internal teams
  • Providing continuous protection
  • Enabling knowledge transfer to employees

The Hidden Risk: Cybersecurity and Employee Wellbeing

One often overlooked dimension is the human cost of cyber incidents.

Cyberbullying, data exposure, and reputational damage can:

  • Impact mental health
  • Reduce employee engagement
  • Create workplace distrust

Employees today don’t just need to be productive – they need to feel safe online.

This makes cybersecurity part of the broader employee wellbeing agenda.

Practical Actions for CHROs (Starting Now)

To turn strategy into action, CHROs should:

  • Run a Cyber Awareness Audit
    Assess current employee understanding and behaviours
  • Introduce Scenario-Based Training
    Simulate phishing, fraud, and impersonation attacks
  • Collaborate with IT on Risk Mapping
    Identify high-risk roles (e.g. finance, HR, executives)
  • Update Policies for the AI Era
    Include guidelines on deepfakes, impersonation, and data sharing
  • Make Cybersecurity a Leadership KPI
    Hold leaders accountable for team awareness and compliance

Final Thought: Culture Is Your Strongest Firewall

Technology alone cannot protect an organisation.

Firewalls, software, and AI tools are essential, but they are only as strong as the people using them.

As Molefe emphasises, every individual in the organisation must understand cybersecurity.

For CHROs, this is the real mandate:

Build a culture where secure behaviour is second nature, because in the AI era, your people are both your greatest risk and your strongest defence.

About the Expert

Lucas Molefe is a cybersecurity specialist at ESET Southern Africa, a leading global digital security company. Based in Cape Town, he works on the front lines of cyber threat detection, prevention, and awareness across diverse industries.

With a strong focus on real-world cyber risks, Lucas specialises in helping organisations shift from reactive security models to proactive, preventative strategies. His expertise spans AI-driven cyber threats, ransomware, and organisational cybersecurity resilience.

Lucas is particularly passionate about cybersecurity education and believes that every employee, not just IT teams, plays a critical role in protecting an organisation. Through his work, he advocates for increased awareness, upskilling, and a culture-first approach to digital safety in the modern workplace.

0
    0
    Your Cart
    Your cart is emptyReturn to Shop
      Calculate Shipping
      Apply Coupon
      Unavailable Coupons
      half Get 50% off
        Products you might like
        Products you might like