In today's rapidly evolving enterprise landscape, cybersecurity can no longer be treated as a behind-the-desk operation. Lilian Kamara, IT Manager at AAR Healthcare Uganda, shares her insights on why technology leaders must spearhead this shift and embed a security-first culture across the modern enterprise.
For Lilian Kamara, IT Manager at AAR Healthcare Uganda, the days of viewing cybersecurity and digital transformation as purely the preserve of the IT department are over. Instead, current trends demand that cybersecurity become part of the business's strategy.
"Cybersecurity is an important part of the everyday culture of the entire organisation. It must become a business resilience issue not just an IT issue anymore, with the trend we are moving towards., We must find a way of integrating it into the business strategy," she says.
Part of embedding cybersecurity into an organisation's culture, according to Lilian, is building a security-first mindset to guide employees in their duties. This, she believes, can only be achieved through the active participation of tech leaders.
"The only way organisations can build that culture is through their tech leaders. We must become champions of cybersecurity so we can disseminate this information to the people we work with, ensuring they understand, appreciate, and incorporate it into their business processes," she says.
Lilian also encourages tech leaders to embed security into the design stage rather than adding it later in the implementation and development process. This, she says, helps leaders innovate without compromising on security.
"We must move away from designing systems and only remembering to add security once they're out in the world. When designing any system based on business functional requirements, we must also factor in cybersecurity requirements from the outset. Starting there makes things easier even if you won't close every gap 100%," she says.
Data security as a strategic priority
As the tech landscape continues to evolve and data becomes an increasingly important strategic asset for businesses, Lilian advises organisations to treat data security as a core part of their wider cybersecurity efforts.
Specifically, she urges organisations to pay close attention to where their data is stored.
"Data protection internally is fairly straightforward, because you can put processes like data encryption in place. But if data is stored on the cloud, the host must be a reputable organisation with strong cybersecurity practices," says Lilian, adding that failing to conduct due diligence when choosing a cloud platform puts the safety of that data at risk.
Nevertheless, Lilian argues that cybersecurity efforts are fruitless if people aren't part of the journey and emphasises on user training and awareness.
“We can not run away from the fact that one of our biggest threats is the user of the technology. You can have all the security protocols in place, but with uninformed users, the chances of a breach rise sharply. One uninformed user in a single branch can make a mistake that affects the entire organisation. As long as users remain unaware, it's essentially the same as having no cybersecurity measures at all," she says.






