Eswatini's business leaders, board members and governance professionals gathered recently for the Governing the Digital Kingdom Executive Breakfast Dialogue, where industry experts explored one of the most pressing leadership challenges facing organisations today: how to effectively govern cyber risk in an increasingly digital world.
Hosted against a backdrop of accelerating digital transformation, the event brought together executives and specialists to examine the growing disconnect between perceived cyber maturity and actual organisational preparedness, and to discuss practical approaches to strengthening resilience.
At the centre of the event was a keynote address by Agnes Dire, CEO of SNG Grant Thornton, who challenged leaders to rethink cybersecurity not as a technical issue, but as a strategic business imperative that demands active governance and executive oversight. Agnes was also joined by other industry experts such as Nithan Naidoo, the CEO of Snode Technologies, who spoke about the Southern Africa threat landscape, as well as Andisiwe Kayoni of the Central Bank, Tipho Shabalala from Standard Bank and SNG Grant Thornton Director Kuda Charandura.
Cyber risk is business risk
Dire highlighted the opportunities that digital transformation and artificial intelligence are creating across Africa and within Eswatini. While these technologies are enabling organisations to innovate, grow and improve service delivery, they are also introducing new layers of complexity and risk.
"Cybersecurity has traditionally been viewed as a technology issue, something largely left to IT departments and technical specialists. That is no longer sufficient. Cyber risk is now business risk," she said.
Dire emphasised that cyber threats today extend far beyond technology environments, carrying significant implications for organisational strategy, operations, reputation and stakeholder trust.
As organisations accelerate their digital journeys, leaders must move beyond asking whether they are investing enough in cybersecurity and instead focus on whether they truly understand their exposure, are governing risks effectively and are prepared to respond when incidents occur.
Bridging the gap between confidence and preparedness
A central theme of Dire's address was the growing gap between organisations' perception of their cyber readiness and their actual resilience.
While many organisations have made substantial investments in technology, systems and controls, Dire noted that investment alone does not automatically translate into preparedness.
"The honest question organisations must ask is how closely their sense of security matches their real level of resilience," she said.
This challenge is becoming increasingly relevant as businesses face more sophisticated cyberattacks, ransomware threats, fraud schemes, third-party vulnerabilities and emerging risks associated with artificial intelligence and other new technologies.
At the same time, regulatory requirements continue to evolve, placing greater responsibility on boards and executive leadership teams to demonstrate robust governance and oversight.
SNG Grant Thornton director Kuda Charandura also spoke to the Cyber Security blind spots many companies face and called for a holistic strategy that included people, technologies, processes and partnerships that effectively manage a cyber security approach. The blind spots he spoke to included Shadow IT and AI, Third Party Risks, Overreliance on Technology, Insecure Configurations, Board Oversight and Insider Threats.
He noted that many organisations continue to focus on isolated controls while overlooking the wider ecosystem in which cyber risk exists. Effective resilience requires organisations to connect governance, technology, people and physical security, supported by regular cyber exercises that test preparedness rather than simply assuming it. As organisations adopt AI and other emerging technologies, governance frameworks must evolve at the same pace if they are to remain effective.
"Cyber resilience is not achieved through technology alone. It comes from understanding where your blind spots are and ensuring that governance, people, technology and physical security work together as one ecosystem," said Charandura.
Building resilience through better governance
Dire went on to stress that organisations cannot eliminate every risk, nor should they seek to slow digital progress. Instead, the focus should be on strengthening governance frameworks that enable businesses to manage risks while continuing to innovate and grow.
She highlighted several critical priorities for organisations seeking to improve resilience, including increased visibility of cyber exposure, clearer accountability at board and executive level, stronger internal capabilities and strategic partnerships that can provide specialist expertise when required.
Importantly, she called for more honest conversations around organisational vulnerabilities and areas requiring improvement.
"Our intention is that leaders leave with greater clarity about the questions their organisations should be asking, the responsibilities leadership must own and the practical steps they can take to strengthen resilience," she said.
From awareness to action
Building on these themes, SNG Grant Thornton facilitated a panel discussion titled "Governing Risk in Practice: Building Resilient Organisations in Eswatini."
The panel featured the Central Bank of Eswatini’s IT Governance and Enterprise Architecture Specialist, Andisiwe Kayoni; Snode Technologies’ CEO, Nithan Naidoo and SNG Grant Thornton’s Managing Director, Oupa Mbokodo.
Building on the keynote presentations, the panel explored the event's central question: How do organisations move from knowing that cyber risk exists to governing it effectively? Panellists examined the practical realities facing boards and executives as they navigate evolving cyber threats, increasing regulatory expectations and the need to balance innovation with resilience. The conversation focused on governance accountability, risk visibility, organisational preparedness and the importance of integrating cyber risk considerations into broader business decision-making.
Panellists agreed that cyber resilience begins with visibility. Organisations cannot invest effectively until they understand where they are most exposed and the risks they are trying to address. The discussion reinforced that technology alone is not the solution; informed governance, clear priorities and selecting the right capabilities for the right risks are equally important.
Naidoo emphasised that organisations should resist investing in technology before understanding the business problem they are trying to solve. "The right tools only deliver value when they are applied to the right problem. Visibility into your risks should always come before investment decisions," he said.
The panel reinforced the view that effective cyber governance is not solely an IT responsibility but requires active involvement from leadership across the organisation.
Helping organisations build resilience through integrated solutions
A consistent message throughout the morning was that organisations no longer experience cybersecurity, governance, fraud, regulation and technology as isolated challenges. Instead, they are interconnected business issues requiring integrated solutions and multidisciplinary expertise.
For SNG Grant Thornton, the event reflected the firm's ongoing commitment to helping businesses and institutions strengthen governance, manage risk with confidence and navigate an increasingly complex digital landscape through practical, client-centred solutions.
Digital progress should not come at the expense of trust; it should strengthen it. But trust is not built through technology alone. It is built through visibility, informed leadership, effective governance and organisations working together across an increasingly connected ecosystem. By understanding where they are most exposed and responding with the right capabilities, organisations can embrace digital opportunity with greater confidence and resilience.
Ends
