Cybersecurity is not failing because of bad technology; it is failing because of bad leadership

Avatar
Cybersecurity is not failing because of bad technology; it is failing because of bad leadership
Fikun Aluko

The LSE Interdisciplinary Research Conference at the London School of Economics in 2023 gathered researchers, economists, policymakers, and practitioners under the theme “People and Change.” The claim I presented there was one the industry has spent a decade avoiding: cybersecurity fails not because the tools are inadequate, but because the leadership is.

Three years on, the global data has vindicated this.

The Verizon 2026 Data Breach Investigations Report found the human element present in 62% of confirmed breaches, up from 60% [2]. IBM’s 2026 Cost of a Data Breach Report is blunter: only 37% of breached organisations encrypted sensitive data both at rest and in transit [1]. Encryption is 30 years old, commoditised, and shipped by default in most enterprise platforms. Its absence cannot be blamed on tooling. The WEF’s Global Cybersecurity Outlook 2026 makes the divide plain: 46% of small organisations report insufficient cyber expertise, against 29% of large ones [3].

Cybersecurity is not failing because of bad technology; it is failing because of bad leadership by Fikun Aluko

None of those figures measures leadership directly. Verizon counts workforce behaviour, IBM counts controls, the WEF counts labour supply. What binds them is who decided. Someone chose not to encrypt. Someone chose not to fund the expertise. Three datasets, one upstream variable. The industry’s answer has been more tools, more frameworks, more audits.

That is precisely the wrong answer. My LSE research showed why.

What the Research Found

The study drew on 2-phase in-depth interviews with cybersecurity CTOs, security leads, and managers serving SMEs across Lagos, analysed through Transformational Leadership Theory across 4 dimensions: idealised influence, inspirational motivation, individual consideration, and intellectual stimulation. It asked what determines whether an organisation manages cybersecurity effectively. The setting was Lagos. The pattern is not.

The answer was consistent. Effective cybersecurity was not determined by infrastructure sophistication. It was determined by whether the person leading security had the technical competence to command credibility with their team and the standing to command boardroom attention above, simultaneously. Technical leaders who cannot translate risk into business consequence never win the board mandate security programmes require. Leaders who influence upward but lack technical depth lose their teams.

Beneath that hiring problem was something more serious. Security culture was entirely top-down, and at the top, security was absent. Investment came after regulatory pressure or after an attack, never before. Board-level representation was rare to non-existent. World Bank estimates put SMEs at roughly 90% of businesses and over half of employment worldwide. A systemic weakness in how they govern security is an economy-level exposure.

The Finding Boards Are Not Discussing

The most underweighted finding is the link between leadership quality, talent retention, and insider risk. Dissatisfied practitioners, those who felt underinvested in or without a credible future, were identified as a primary vector of insider threat: not through sabotage, but through carelessness, credential misuse, and exfiltration tied to departure. Organisations without succession planning faced compounding exposure when their lead practitioner left, a vulnerability the research called key-man risk.

Leaders who invested genuinely in their teams built the opposite: what the research called an alumni effect, staff who stayed longer, built institutional knowledge, and remained allies when they left. In a market where nearly half of small organisations already report insufficient expertise [3], becoming a place security talent chooses to stay is a security investment.

What a Decade of Practice Taught Me

The same pattern has kept reasserting itself across a decade of practice. At 21st Century Technologies, deploying Check Point next-generation firewalls, managing McAfee endpoint security across the enterprise estate, and running vulnerability assessments through Nessus and AlienVault, we achieved a high compliance rate and a marked improvement in threat detection and response. The gains held where security had visibility at leadership level. Where it was absent, they eroded quietly, not because the technology failed, but because the conditions that make technology effective had never been built.

The same held other roles, where I led the implementation of integrated risk control frameworks aligned to ISMS, SOC 2, and other global standards. The frameworks were always technically implementable. Also true as a consultant, designing and delivering enterprise cybersecurity strategies for clients. What varied was whether the governance conditions existed to sustain them. My Chevening research on Privacy-Enhancing Technologies pointed the same way. Executive sponsorship was the differentiator.

Cybersecurity is not failing because of bad technology; it is failing because of bad leadership by Fikun Aluko

But here’s the objection that cuts hardest: many breaches aren’t leadership failures at all. Zero-days exist. Verizon’s 2026 data found third-party involvement in nearly half of all breaches, and no board resolution prevents a compromised vendor token [2]. That relocates the argument rather than weakening it. Once prevention fails, almost everything determining cost is a leadership variable: whether the response plan was rehearsed, whether the vendor was tiered, who had authority to halt operations at 2am. Detection is technical. Duration is governance.

Research and practice brought me to the same conclusion from different directions. Leadership is not a precondition for cybersecurity effectiveness. It is the precondition.

Why This Matters More in 2026

In 2026, this is a precondition for survival. The WEF found 47% of organisations now identify AI-powered adversarial advances as their primary security concern [4], although this has fallen to 29% [3] in the recent report yet it is still a huge challenge . IBM puts a price on it: one in four malicious breaches were AI-enabled, a 56% rise in a single year, at an average of $6 million [1]. These threats succeed most in the organisations the LSE research described as most vulnerable: where security culture is reactive, employees are not cultivated as a first line of defence, and the security leader lacks standing to build vigilance.

The defence against a deepfake instruction to transfer funds is not a better algorithm. It is an employee invested sufficiently to feel ownership over the organisation’s security: someone who knows that questioning an unusual request is expected, not insubordinate. That employee is built by leadership, or not at all.

The Conversation That Is Overdue

Three questions will tell a board more than any dashboard. Who is accountable for security outcomes, by name, and what happens if it fails? When did we last fund a security decision before an incident or an auditor required it? If our lead practitioner resigned tomorrow, how long before we noticed?

The industry has spent decades upgrading tools in an arms race with attackers. It has not spent equivalent energy on whether those tools are deployed by people who care, governed by leaders who understand the stakes, and sustained by organisations where talent wants to remain.

That variable is leadership. My LSE research named it. The global data is consistent with it. The question for every board and every CEO is not whether the organisation has the right technology. It is whether it has the right conditions for that technology to matter.

Most do not. That is the conversation that is overdue.

Cybersecurity is not failing because of bad technology; it is failing because of bad leadership by Fikun Aluko

Fikun Aluko is a cybersecurity leader and technology leader with over a decade of experience across enterprise security, risk governance, and digital innovation in the EMEA region. A Chevening Scholar and Fellow of the African Leadership Initiative, he presented the research behind this article at the London School of Economics, where he holds a Master’s in Management of Information Systems and Digital Innovation. He also holds a Master’s in Systems Engineering from the University of Lagos and a B.Tech in Computer Engineering from Ladoke Akintola University of Technology, and is certified as CISM, CRISC, and ISO 27001 Lead Implementer among other global credentials. He is the founder of Hikestack, speaks at conferences, and advises organisations on cybersecurity governance and AI adoption across EMEA.

alukofikunayomi@gmail.com | https://www.linkedin.com/in/aluko-fikunayomi/

Read also: Talksign wants to simplify sign language for deaf people with its AI solution


Technext Newsletter

Get the best of Africa’s daily tech to your inbox – first thing every morning.
Join the community now!

Register for Technext Coinference 2023, the Largest blockchain and DeFi Gathering in Africa.

Technext Newsletter

Get the best of Africa’s daily tech to your inbox – first thing every morning.
Join the community now!