Digital quotient of boards and directors: What questions are we not asking about cybersecurity resilience?

 

Lorreta Songola

Herald Correspondent

GOVERNANCE has always been about stewardship. But what does stewardship look like when an organisation’s most critical assets are invisible, intangible and increasingly under threat?

Boards across Zimbabwe need to consider this carefully, especially as remote work, digital payments, cloud-based operations and online service delivery have become part of everyday business.

The same digital infrastructure that powers our businesses is also what malicious actors probe and exploit every day.

Cyber resilience is strongest when organisations combine strong internal governance with trusted partnerships and shared threat intelligence.

As cyber threats become more sophisticated and more disruptive, cyber resilience must receive the same level of oversight as financial, operational, and reputational risk.

One way for boards to test their preparedness is to regularly challenge their assumptions with the following questions.

 

Do we have enough digital fluency in the room?

 

In many boardrooms, the moment cyber security is raised, the instinct is to defer to the IT team. It’s understandable: technical topics are often presented in language that excludes rather than informs. But digital quotient isn’t about technical specialism.

It’s about asking the right questions, reading the warning signs and holding the organisation accountable.

Board members don’t need to know how a firewall is configured. What matters is understanding whether appropriate controls are in place, who is accountable for them, and what the consequences would be if they failed. Cyber resilience, like financial or reputational resilience, is ultimately a governance responsibility.

 

Are we treating compliance as a ceiling rather than a floor?

It’s natural for boards to approach cyber security through a compliance lens: Have we met regulatory requirements and fulfilled our obligations? Zimbabwe’s legal framework is clear and enforceable. The Cyber Security and Data Protection Act is in force, POTRAZ breach-reporting requirements are mandatory and every organisation must appoint a data protection officer. The Government’s National Cybersecurity Strategy also encourages collaboration with CERT-Zim.

Meeting regulatory requirements may protect an organisation from penalties, but it does not protect it from attack. Interpol’s African Cyberthreat Assessment identifies Southern Africa as a prime target for AI-driven phishing, business email compromise, and digital extortion. Effective governance requires more than meeting minimum requirements.

Organisations should have a clearly defined cyber risk appetite, provide regular reporting on cyber security readiness and trends, and maintain escalation procedures that can be activated immediately when an incident occurs.

Organisation looking to move beyond compliance are increasingly turning to integrated cyber resilience services that provide continuous monitoring, threat intelligence, incident response support, and governance reporting through a single framework. Liquid Intelligent Technologies’ Secure360 gives organisations greater visibility across their digital environments while strengthening their ability to detect, respond to, and recover from cyber threats, ensuring the cyber risk management becomes proactive as compared to reactive.

 

Have we actually rehearsed what happens when an incident occurs?

No organisation can guarantee it will never face a cyber incident. What matters is how effectively it responds. Too often, breaches surface through journalists, customers or social media before they reach organisational leadership. By then, the technical incident has already become a reputational crisis.

In Zimbabwe, the stakes are particularly high. Critical digital infrastructure such as ZimSwitch, mobile money platforms, RTGS and ZWG payment systems underpin daily economic activity, meaning a significant cyber event could have consequences far beyond a single organisation.

The difference between a manageable incident and a full-scale crisis is often determined in the first few hours. Organisations should regularly rehearse cyber incident scenarios, maintain clear escalation paths, and ensure that everyone involved understands their role during the critical first 24 hours.

Do we know where our third-party exposure really lies?

One of the most overlooked sources of cyber risk sits outside an organisation’s own walls. Vendors, suppliers, contractors, and service providers often have access to systems, data, or networks. Yet these relationships are frequently assessed primarily on commercial or operational considerations, with cyber risk treated as a secondary concern.

If a third party is connected to an organisation’s systems, its security posture becomes part of the organisation’s risk profile. Boards should, therefore, ensure that high-risk relationships are identified, regularly assessed and governed through appropriate access controls and ongoing oversight.

 

Are we building a culture where people report early?

 

Technology can only do so much. A single human error can undermine even the strongest security controls: a phishing email clicked, a password reused, a laptop left unattended. At the same time, social engineering attacks have become highly sophisticated, with criminals impersonating executives, finance leaders, auditors, and trusted partners.

Building a culture of digital responsibility means ensuring that employees know what to report, how to report it, and feel confident doing so without fear of blame.

While culture is built day-to-day by leadership and employees, boards have a responsibility to ensure that accountability, awareness and cyber security practices are embedded throughout the organisation.

Are we investing in the partnerships that support resilience?

No organisation can address cyber security in isolation. Zimbabwe operates within a regional threat landscape where attacks, vulnerabilities, and criminal networks do not respect organisational or national boundaries.

Strengthening resilience depends on collaboration with trusted technology providers, industry bodies, regulators and threat intelligence networks. Organisations that engage with the broader cyber security ecosystem are often better positioned to identify emerging threats and respond more effectively when incidents occur.

Boards should ensure that external cyber security relationships are actively managed, benchmarked against recognised standards and used to support information sharing and continuous improvement.

Cyber security resilience is a governance challenge that requires active oversight, informed decision-making, and a long-term view of risk.

As Zimbabwe’s digital economy continues to expand, cyber resilience will increasingly become a measure of organisational resilience.

The organisations that thrive will be those whose boards are asking the right questions long before a crisis forces them to find the answers.

 

The author, Lorreta Songola, is the vice president and chief executive officer, of Liquid Intelligent Technologies Zimbabwe.

Related Posts

Air Zimbabwe’s Flight UM724 ready to depart for London

Freeman Razemba Senior Reporter The Air Zimbabwe’s Airbus A330-300 aircraft which is plying the Harare–London route is now ready to leave Robert Gabriel Mugabe International Airport in Harare for Gatwick…

Asia, Zim enter new phase of cooperation

Gibson Nyikadzino Zimpapers Politics Hub RELATIONS between Zimbabwe and Asian countries are set for a new phase of cooperation as the two parties celebrate the longstanding friendship and growing people-to-people…

Leave a Reply

Your email address will not be published. Required fields are marked *

×