Innovation and security go hand in hand

August 2024 Facilities & Building Management, Security Services & Risk Management

In a world where the demand for tech innovation is matched only by the acceleration of cybersecurity threats, businesses face the challenge of balancing new product development and robust security measures.

Kevin Halkerd, Risk and Compliance Manager, and Andrea Carr, Head of Research and Development at Proptech specialist e4, say this balance is not just a goal, but the cornerstone of their strategic approach.

How can businesses balance the need for innovation without compromising on security? Part of the answer is stepping outside the dichotomy altogether. “It is so important to have both. You cannot have one without the other. A business that does not innovate will quickly fall behind its competitors, and one without security simply will not survive,” says Carr.

“Fortunately, this perspective is fast becoming the consensus in the industry,” says Halkerd. “At CISO conferences, the prevailing message is clear: Security must be baked into the innovation plan itself. This approach ensures that security considerations are part of the developmental process from the start, and not as an afterthought.”

Striking the right balance early

Early engagement of security teams in the innovation process should form part of the strategy from day one. “To encourage and facilitate the testing of new technologies within our organisation, we invite proposals for new tech and evaluate them alongside other similar technologies. Our goal is to create a safe space for experimentation, exploring specific use cases. Before finalising any technology, we involve e4’s security team to thoroughly investigate and identify any hidden risks. This ensures that any technology we integrate is secure and appropriate for our systems. If security is brought in only at the end of an R&D; process, it is already too late,” Carr explains.

“There are so many benefits to this approach,” agrees Halkerd. “By taking this kind of proactive approach in the past we have been able to shift a selected technology from an open-source technology to a closed source technology within a day. This is not viewed as unusual or problematic; we have had to pivot technologies within 24 hours before, changing an entire production environment to a completely different architecture or service provider due to risk factors. This flexibility in avoiding long-term technology lock-ins makes organisations much stronger and can form part of ordinary security measures as well as the overall approach to innovation.”

Security leading innovation

“In fact, it is possible for security considerations to become the driving force behind innovation,” says Halkerd. Security is often at the bleeding edge of innovation discussions. Successful AI strategies, for instance, frequently emerge from security companies that leverage advanced technologies to enhance their capabilities. This forward-thinking approach not only protects the company, but also sets the stage for new technological advancements.

First to market vs. first to get it right

Balancing the need to be first to market with the imperative to get it right is a nuanced challenge. “Introducing something new is difficult. Customers are understandably cautious about trusting technology to do what humans have done in the past. However, once we have one client signed up and running an enhancement we have developed successfully, with data to prove its effectiveness, others soon follow suit,” notes Carr. “The challenge then shifts to having the resources to implement it across all clients concurrently. The key is to get something 80% implemented and working efficiently, and then quickly finalise the remaining 20% to stay ahead of competitors who might be able to achieve 100%.”

It is about finding a middle ground. VCs are often the first lead market, and their perspective is entirely different from established long-term businesses. When leveraging your existing customer base, especially blue-chip clients, you want to bring them something refined and polished. More mature businesses do not necessarily need to be the first to innovate, but do want to see technologies being integrated into their offering.

Managing emerging technology

Adopting emerging technologies like AI requires careful consideration of data security. Once again, involving security teams early in the process serves as an essential guardrail, ensuring that risks are identified and resolved before implementation. “At the simplest level, before adopting any new technology, ensure you understand how securely it manages data. If you do not know the answer, do not proceed,” says Carr.

As with many emerging technologies, it is not as much about the technology itself as it is about the data behind it. AI is going to be a significant game changer for business. “How do you balance security and the need for innovation in that respect,” asks Halkerd. “The key is data operations. Data needs to be in a clean, usable format. If organisations can focus on that, deliver against that; then it is possible to abstract the data safely and sensitively while keeping in mind regulations in South Africa, like the Protection of Personal Information Act (PoPIA).”

By involving security teams early in the process, maintaining transparency, and fostering a culture of continuous improvement, robust security can enhance, rather than hinder, innovation – whether it is AI or the next big innovation on the horizon.


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

From the Editor's desk: Security goes mainstream
Technews Publishing News & Events
      Welcome to SMART Security’s SMART Mining & Industrial Security Handbook 2026. While the world is focused on cybersecurity and AI, physical security has become a board-level concern across South Africa’s ...

Read more...
Global security in 2026
Editor's Choice News & Events Security Services & Risk Management Industrial (Industry) Mining (Industry)
The World Security Report 2026 states: “In a world of increasing volatility, physical security has evolved. It is no longer just a defensive measure; it is a critical driver of corporate value.”

Read more...
Who is to blame for autonomous mistakes?
Editor's Choice Security Services & Risk Management Industrial (Industry) Mining (Industry)
Most supply agreements for AI-integrated equipment still closely resemble plant hire contracts from ten years ago: bilateral, human-focused, and silent on who bears the risk when a machine makes a decision on its own.

Read more...
Industry perspective on industrial cybersecurity
Technews Publishing News & Events Infrastructure Industrial (Industry)
The Industrial Security Harmonization Group has released a joint industry perspective highlighting a critical truth in industrial cybersecurity: secure communication is not determined by protocols alone, but by how they are deployed and managed in real-world environments.

Read more...
The control room problem that nobody wants to talk about
Technews Publishing Editor's Choice
WhatsApp has become the unofficial backbone of security communications across the mining and industrial sectors, but it was never designed to be a security tool.

Read more...
Controlling access for people and vehicles
IDEMIA STid Security Technews Publishing Editor's Choice Access Control & Identity Management Asset Management Industrial (Industry) Mining (Industry)
When it comes to access control, the security requirements of mines and the industrial sector are similar, requiring a layered approach that combines physical barriers, digital authentication, and continuous monitoring to protect personnel, assets, and operational continuity.

Read more...
The post-Q1 security checklist
Asset Management Security Services & Risk Management
By this time of year, employees have changed jobs or roles, suppliers may have changed, and devices have moved between offices, homes, and sites. This is the right time for businesses to run a practical post-Q1 security check.

Read more...
PoPIA turns its attention to gated access
News & Events Security Services & Risk Management
The Information Regulator has gazetted its proposed Code of Conduct for the processing of personal information at gated access points. At 65 pages long, the code signals a significant shift in how personal information is collected and managed at entry points.

Read more...
Unifying building information into a sea of insight
Schneider Electric South Africa Facilities & Building Management
Modern, integrated building management solutions bring data from multiple sources and dispersed locations like HVAC, lighting, access control, lifts, generators, field devices, energy and water meters into a single ‘pane of glass’.

Read more...
Your company is already breached, you just do not know it yet
Information Security Security Services & Risk Management
Attackers are no longer relying on sophisticated exploits to break-in. Instead, they are systematically targeting weak credentials, misconfigured systems, and exposed devices stemming from preventable gaps such as identity weaknesses and poor visibility across digital environments.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.