In 2022, a major government-owned pension fund suffered a cyberattack. The kind that makes you sweat in places you didn’t know had pores.

It started with a routine system upgrade outsourced to a vendor with a shiny brochure and even shinier promises. The IT manager approved it. The head of procurement signed off. No one involved had asked when the last penetration test was done. Or how user access would be monitored post-upgrade. A week later, the attackers walked in through an open port like burglars through an unlocked door accessed over 20,000 contributor records, including national ID data, salary histories, and nominee information.

The breach was only discovered six weeks later when a board member’s data surfaced on the dark web.

Now the hunt began not for the hackers, but for someone to blame.

The CEO blamed the Head of IT. The CIO blamed the vendor. The vendor blamed the outdated firewall. The compliance officer said, “I wasn’t consulted.” The chair asked legal counsel, “Can we say we were unaware?”

This is what happens when you don’t use RACI a simple yet surgical tool for clarifying roles in any initiative.

advanced divider

"Cybersecurity isn't just a tech issue. It's a governance one. And when it blows up, the accountability trail shouldn’t start with, “I thought..” It should start with, “I owned this.” ”

Tweet
advanced divider

Let’s rewind.

RACI stands for Responsible, Accountable, Consulted, and Informed. In this case:

  1. The Head of IT was Responsible for implementing the system securely. That’s action-based.
  2. The CEO was Accountable for ensuring that risk management especially cyber was embedded into operations. You can’t outsource this. It’s the seat’s weight.
  3. The Compliance Officer and Head of Risk should have been Consulted before changes to the information systems were made.
  4. The Board and External Auditor should have been Informed of all material system architecture shifts.

But nobody followed the map.

Everyone was driving blind. And here’s the kicker had a simple RACI matrix been applied before the upgrade, the breach likely wouldn’t have happened. Or if it did, the organization would have detected it faster, contained it better, and responded without chaos.

Instead, regulators pounced. Contributors withdrew funds. The media feasted. Trust evaporated.

Leadership tool: RACI Heatmap for Cyber Events. At the start of every ICT-related initiative, define who is doing the work (Responsible), who owns the final outcome (Accountable), who needs to give input (Consulted), and who should stay in the loop (Informed). Then audit that map quarterly.

Cybersecurity isn’t just a tech issue. It’s a governance one. And when it blows up, the accountability trail shouldn’t start with, “I thought..” It should start with, “I owned this.”

In that pension fund case, the board eventually fired the CEO. Not because he clicked a bad link. But because he never asked the right questions.

Cyber risk is a boardroom issue. Not an IT department memo. Don’t wait to learn that the hard way.