Mulwana CIO, Robert Jenkins Sibbechai, believes the biggest gap in how organisations use AI isn't the technology itself but the absence of any rules governing what it's allowed to do with the data it's fed. He explains why this complicates cybersecurity and how a decade of oversharing on social media set the stage for it.
Robert Jenkins Sibbechai doesn't think the next big cyber threat will look anything like what IT departments spent the last twenty years preparing for.
"It is no longer a place where I am attacking you to deny you a service, which is also still possible, but now attackers want data," he says."
That shift, in Robert’s view, didn't begin with AI at all. Rather, it began with how comfortable people became handing over information about themselves long before AI entered the picture. This shift, according to him, can be traced back to the rise of social media as a mass data-collection exercise that trained a generation to volunteer their location, habits and relationships without a second thought.
"People are sharing data about themselves with artificial intelligence. You don't even need to stalk them. They're already telling you where they are," he says.
Regulation, not resistance
Nevertheless, Robert is still a proponent of AI. In fact, his organisation has already adopted AI tools to speed up debugging, draft communications, and even to build a change-management tool in-house rather than buying one off the shelf.
His worry around AI is the absence of any real boundary around what staff can share with AI systems while using them well. This is further worsened by the fact that no one knows where this data lands and neither can anyone affirm the security of that data and how it is used.
Even more frustrating to him is the fact that Internal data classifications offer little protection once an employee pastes something into a chat window.
"Even in those classifications, you have no control over what a user will share with AI. The one thing I really need right now as a CIO is regulation on AI," he says.
The cybersecurity issue
Further, Robert believes that AI has also complicated the cybersecurity landscape.
"While I apply AI to protect my infrastructure, there's a guy out there who is applying AI to find how best they can attack me," he says.
It's a world away from the threats he remembers from his student days where viruses could only spread as fast as someone could carry it from one flash disk to the next and there was some semblance of control.
At Mulwana, which spans three separate businesses, Robert has leaned on cloud-based, preconfigured systems partly because they let him monitor security posture across all three from a single view rather than running independent infrastructure for each.
"I can have them in a bird's eye view instead of running three different data centres," he says.





