Cybersecurity remains one of the biggest challenges that tech leaders grapple with on a daily basis. While companies continue to invest in technology to make their systems robust, Bank of Kigali’s CIO Eveque Mutabaruka, Del Monte’s head of IT Kennedy Njenga and Nairobi Water’s head of IT Jimmy Thuo believe that none of this counts for much if the person sitting behind the keyboard does not understand the risks they are exposed to every single day.
One of the challenges that Nairobi Water’s head of IT Jimmy Thuo has had to deal with is constant attacks on the company’s online portal that clients use to apply for water connection.
"Clients try to make an application, but the system is unavailable. We realised somebody was launching denial-of-service attacks. We secure our website because it is also a target. You don't want to wake up and find the website defaced," Jimmy says.
While the company fixed the issue by investing in firewalls, data encryption, restricted web access, antivirus software and endpoint security across its network, Jimmy still worries about viruses and malware that can be injected into the system internally.
A dangerous culture of complacency
For Eveque Mutabaruka, cybersecurity has been the defining challenge of his career, and the danger, he says, rarely comes from the sophistication of an attack. It comes from complacency among staff members.
"Even starting from IT guys, you don't see that sense of urgency and ownership to feel like, okay, something is wrong here. You need to keep reminding them that a small unpatched server can actually make the whole bank collapse," he explains.
This lack of urgency is troubling enough on its own, but Eveque believes emerging technologies are making the stakes higher still. Bank of Kigali has already begun embedding artificial intelligence into parts of its operations, a move that brings efficiency but also fresh uncertainty.
"We're all now using AI, but it comes with a lot of uncertainty and risks, exposing the bank more," he says.
His comments point to the uncomfortable truth that new tools add a layer of complexity for people who were already struggling to keep pace with the basics.
Confidence without comprehension
Of the three tech leaders, Kennedy Njenga of Del Monte frames the human factor most bluntly.
"Behaviour affects cybersecurity operations because it is humans who actually execute the tasks that lead to security risks being exploited. It is a user who clicks on a link or opens an attachment without thinking, and suddenly the whole organisation is exposed,” he says.
What worries Kennedy is not simply a shortage of technology, but a shortage of understanding about the technology already in place. In his work, he has repeatedly encountered users who mistake a smoothly running system for a secure one, unaware of what is actually happening beneath the surface.
"You find there is quite a disconnect. People feel very confident about the systems they have in place, but once you start looking under the hood, you realise there are so many issues to do with security and setup that need attention, and users do not know about them,” he says.
Kennedy also believes that HR and finance teams are the most vulnerable because of the sensitivity of the data they handle. As a result, solving cybersecurity issues must be an organisation wide responsibility and not just a preserve of those in the IT department. He also advocates for frequent training and awareness sessions that are tailored to the different people in an organisation.
“There has to be a structured approach. You must define the technology and how people are trained. Executives need one kind of training, finance another, HR another. And then you keep reminding them, even if it is just short emails, so the risk stays at the front of their minds,” he says.





