Cybersecurity Is a People Problem – in discussion with Ariston Global
Most boards still treat cybersecurity as a line item on the IT budget. That assumption is increasingly out of step with how breaches actually happen, since the weakest point in most organisations isn’t a server, it’s a person clicking the wrong link at the wrong moment. Closing that gap means rethinking who in the business is actually responsible for security.
In this episode of Meet the Management, Marc Ashton speaks with Suran Moodley, Group Managing Executive at Ariston Global, about why cybersecurity needs to be treated as an operational and governance issue rather than a purely technical one, and what it takes to build a workforce that defends the business instead of exposing it.

About the guest
Suran Moodley is the Group Managing Executive at Ariston Global, a strategist and solutions architect with over two and a half decades of experience across business strategy, organisational capability and governance. He holds an MBA from Henley Business School in the UK, alongside an Honours degree in Industrial Psychology and a postgraduate qualification in Personnel Management, and is registered with the Institute of People Management, the South African Board for People Practices, and the Institute of Directors South Africa.
Suran has built a reputation for tackling complex, cross-functional business problems, having worked extensively as an Executive and Board Member across mature businesses, start-ups and turnarounds, both locally and internationally. He is also a regular contributor of business commentary to South African publications including Business Brief, where his recent writing has challenged conventional thinking on operational risk, governance and the role people play in protecting a company’s value.
Why this conversation matters
Cybersecurity spend in South Africa has climbed steadily, yet breaches keep happening, and the reason is rarely a missing firewall or an outdated antivirus license. Phishing, social engineering and simple human error remain behind the overwhelming majority of successful attacks, which means the technology a business buys can only ever protect part of its exposure. The rest depends on whether the person opening an email, approving a payment or plugging in a USB stick knows what to look out for.
That puts the responsibility somewhere boards aren’t always comfortable placing it: with culture, training and everyday behaviour, not just with the IT department’s budget. A breach driven by human error still produces the same operational disruption, financial cost and reputational damage as one driven by a technical failure, but the fix looks completely different, and it isn’t one a software upgrade can deliver on its own.
This conversation matters because it reframes cybersecurity as a leadership question rather than a technical one. If the greatest vulnerability sits with people, then building resilience has to start with how a business trains, informs and holds its workforce accountable, which is a very different mandate to the one most security budgets are built around.
In this episode
This is a conversation about where real cyber risk actually lives inside a business, and what closing that gap requires. It covers:
- why cybersecurity has outgrown its reputation as a purely IT or software problem
- the human behaviours that most commonly open the door to a breach
- the operational, financial and reputational fallout businesses face when those gaps are exploited
- what it actually takes to build a “human firewall” across a workforce
- where leadership and board-level accountability fit into a company’s security posture
- practical first steps for businesses that have under-invested in the human side of cybersecurity
Watch the full episode to hear Suran Moodley unpack why cybersecurity has to be treated as a whole-of-business issue, and how Ariston Global thinks about turning a company’s people into its strongest line of defence.

About Ariston Global
Ariston Global is a strategy and advisory firm offering accounting, tax, human resources, payroll and compliance services to businesses across South Africa and internationally, alongside recruitment, marketing and brand identity work. The firm was founded as Ariston Financial Services in Durban before a strategic collaboration with Suran Moodley saw it rebranded as Ariston Global, expanding its footprint to include a London office and a broader advisory mandate spanning corporate finance, governance and organisational capability.
The firm positions itself around using technology, including AI-driven tools, to help businesses optimise their operations while keeping people at the centre of how that technology gets adopted, which is the same thinking behind its view on cybersecurity. Ariston Global has built its reputation working closely with South African SMEs, helping them professionalise their operations and manage risk in ways that are usually reserved for much larger corporates.


