About
Subscribe
  • Home
  • /
  • Malware
  • /
  • Cyber security is everyone’s problem. Here’s how to build a security culture that lasts

Cyber security is everyone’s problem. Here’s how to build a security culture that lasts

Johannesburg, 06 Oct 2026
Natalie Borcherds, Security Services Manager and Nikishca Moolman, Information Security Consultant at Galix.
Natalie Borcherds, Security Services Manager and Nikishca Moolman, Information Security Consultant at Galix.

Cyber security training remains one of the most persistent challenges in corporate South Africa, not because organisations don’t invest in it, but because too many still treat it as a once-off exercise. Ticking a compliance box and moving on. The result? Employees forget what they learned, threats evolve and the organisation stays vulnerable.

But it doesn’t have to be this way. According to Nikishca Moolman, Information Security Consultant at Galix, the organisations that get security right are those that stop treating it as a technology problem and start treating it as a people problem. “When cyber security is woven into the DNA of the business, it becomes a natural part of daily processes and decision-making rather than a once-off intervention,” she says.

It starts at the top

Cultural change in any organisation begins with leadership. When executives visibly champion cyber security, it sends a clear signal to every level of the business. Equally important is how leadership responds when things go wrong. Stepping in to support rather than reprimand reinforces the message that cyber security is a shared responsibility, not a stick to punish people with.

Making training personal is another powerful lever. Natalie Borcherds, Security Services Manager at Galix, has seen this firsthand: “When people understand how cyber security affects their families, homes and bank accounts, it quickly shifts from an abstract work requirement to a personal priority,” she says. Real-world examples drawn from social media habits or everyday interactions help employees recognise threats they’ve actually encountered, turning abstract lessons into genuine habits.

One size definitely doesn't fit all

A blanket training approach is one of the most common mistakes organisations make. Different departments face different threats, and treating everyone the same, says Moolman, is “setting yourself up to fail”.

Finance teams are prime targets for fraud and phishing. HR handles sensitive employee data. IT holds the technical keys to the entire organisation. Each of these teams needs training that reflects their actual risk landscape. Moolman recommends regular risk profiling at a department and role level – ideally at least once a year – to ensure training stays relevant. “You can’t manage what you don't know,” she notes.

The practical framework she advocates is built in layers: baseline training covering password hygiene and phishing awareness for everyone; role-specific content tailored to each department’s tools and risks; scenario-based learning that makes consequences tangible; and regular refreshers to keep pace with an evolving threat environment. Importantly, this doesn’t require expensive bespoke systems, organisations can adapt real-world incidents from the news and use the tools they already have.

AI: Powerful ally, potential liability

Artificial intelligence is reshaping how organisations deliver security training, offering the ability to personalise content, simulate threats and scale awareness programmes across large workforces. But Moolman urges caution. “AI can be a best friend or a worst enemy,” she warns.

The risk she highlights most is one many organisations overlook: employees inadvertently exposing sensitive data when engaging with AI tools. Seemingly harmless prompts such as uploading documents, describing workflows, sharing personal details can contribute to a growing digital footprint. “Everything you do leaves a footprint on the internet,” she explains, and AI systems can quietly use that information in ways users never anticipated.

Borcherds adds that AI-driven training still needs to be grounded in real-world scenarios relevant to the organisation, not just generic content served by an algorithm. Over-reliance on automation can also dull human oversight, and poorly developed AI platforms can produce flawed guidance. The key is balance: using AI to extend the reach and relevance of training while preserving the human judgment and critical thinking that no software can replace.

From knowing to doing

Perhaps the most important question in cyber security training isn’t what people know, but whether they act on it. Borcherds argues that the shift happens when training connects to emotional impact – when people feel the weight of potential consequences, not just understand them intellectually.

Moolman points to experiential learning as the most effective catalyst: simulated phishing tests, mock ransomware incidents, role-based attack scenarios. These exercises make threats feel real and build the healthy scepticism that helps employees spot when something is “too good to be true”. Over time, secure behaviours such as stronger passwords, multi-factor authentication and reporting anomalies stop feeling like rules imposed from above and start feeling like common sense.

Embedding security into everyday workflows matters too. When secure processes are the default, employees become more attuned to when something is off. “Noticing and acting on a small system error, instead of ignoring it, reflects growing confidence and ownership,” says Moolman.

And when employees hit the limits of their knowledge? That's not a failure; it’s an opportunity. Knowing when to ask for help, whether from a colleague or an experienced cyber security partner, is itself a mark of a mature security culture. As Moolman puts it, relying on experts rather than a quick online search ensures businesses get accurate, contextual advice aligned with their real risks.

Cyber security awareness, done well, isn’t a programme. It’s a mindset, and building it takes consistency, relevance and the commitment to treat every employee as the first line of defence.

Share

Editorial contacts