October is Cybersecurity Month, a timely reminder that the weakest link in many security chains is not a missing patch or a misconfigured firewall but the human element. Employees, intentionally or not, cause most cyber incidents through lost devices, weak passwords, falling for phishing, misuse of privileged access, or unsafe use of cloud services. If organisations want to manage employee‑related cyber risk effectively, HR and IT must move from separate silos to a single, coordinated frontline. This is as much about people and processes as it is about technology.

At the centre of the partnership should be a shared understanding of risk and of the organisation’s tolerance for it. HR brings expertise in people, policy, employment law and culture; IT brings technical controls, threat intelligence and incident response capabilities. Together they can identify roles that carry elevated cyber risk, finance and payroll, procurement, senior executives, developers, data scientists and anyone with privileged access to critical systems, define the behaviours that matter, and agree how to measure and mitigate those risks. That starts with a clear policy framework that sets expectations for secure behaviour, acceptable use, data handling, remote work and bring‑your‑own‑device arrangements. Policies alone do not solve anything, but when HR owns the policy lifecycle, drafting in consultation with IT, embedding it into contracts and handbooks, and ensuring legal compliance, and IT translates policy into enforceable controls, the result is coherent and enforceable.

Recruitment and screening are a practical early junction for HR and IT. For roles with privileged access to systems or sensitive data, screening should go beyond standard CV checks to include identity verification, criminal‑record checks where lawful and necessary, credit checks for financially sensitive roles, verification of qualifications and technical certifications, and practical skills tests or work samples that show a candidate can do the job. Psychometric or integrity assessments can add insight into attitudes towards rules and honesty, but these should be validated, used proportionately and interpreted by qualified practitioners to avoid unfair exclusion.

IT can specify the access levels and competencies needed for a role, while HR ensures that screening is fair, consistent and compliant with privacy laws such as POPIA; candidates must be informed and give consent where required and data must be retained only as lawfully permitted. Onboarding should be a joint process: HR introduces the employee to organisational culture and obligations while IT ensures secure provisioning of accounts, least‑privilege access, multi‑factor authentication and device encryption before any sensitive access is granted.

Training and awareness are another area that requires joint stewardship. Well-designed security awareness is not a once‑off checkbox or a box‑ticking compliance course. HR should own the learning calendar and the behavioural reinforcement mechanisms, probation check‑ins, performance objectives, and consequences for breaches, while IT supplies relevant, role‑specific content, live threat examples, phishing simulations and the metrics to show where additional coaching is needed. The most effective programmes align learning outcomes with job roles: the finance team needs anti‑fraud and invoice‑security training; sales needs secure handling of customer data on mobile devices; developers need secure coding practices. By connecting learning outcomes to performance reviews and career progression, HR can ensure that training is incentivised and taken seriously.

Access lifecycle management is a critical control where HR and IT must be tightly integrated. HR should trigger account provisioning, role changes and offboarding workflows based on contracts, promotions or terminations. IT must consume those signals in a timely, auditable way, revoking access when employment ends or when duties change. Delays in deprovisioning are a common cause of insider risk and data leakage. Automated workflows that tie HR systems (such as the HRIS) to identity and access management tools reduce human error and ensure that access aligns with the employee’s current role. For senior or high‑risk roles, periodic re‑certification of access rights should be a formal process agreed between HR and IT, and conditional access, staged privileges pending successful screening or probationary assessment,  is an effective control that links screening outcomes to real‑world access.

Monitoring and investigating suspected misuse requires delicate balancing between security needs and employee privacy. HR knows employment law, disciplinary procedures, and the need for fairness; IT knows what unusual activity looks like and how to collect technical evidence. Together they should agree on a lawful, transparent monitoring policy that is communicated to employees, and an investigation playbook that preserves evidentiary integrity while ensuring fair process. Where monitoring reveals misconduct, HR handles disciplinary steps; where monitoring reveals a security incident, IT leads containment and remediation, and both work together on communications and consequences.

Incident response and recovery also benefit from pre‑agreed roles. A security incident with employee involvement demands both technical containment and people management: interviews, support for potentially affected staff, and clear communication about responsibilities and next steps. HR can help manage employee wellbeing, internal messaging, and legal obligations while IT focuses on technical eradication and forensic analysis. Practising incident response through joint tabletop exercises builds muscle memory and ensures both teams know how to act when an incident happens.

Governance and metrics matter. Boards and senior leadership need clear reporting on employee‑related cyber risk: number of phishing clicks, time to deprovision accounts, completion rates for mandatory training, number of privileged access reviews completed, and results of background checks for critical roles. HR and IT should agree on a dashboard that measures both compliance and behaviour, and they should review it together regularly. Regular audits and post‑incident reviews provide opportunities for continuous improvement.

Employee‑related cyber risk is not a technical problem alone. It is a people problem that requires HR and IT to speak the same language, share responsibilities, and design processes that are lawful, proportionate and focused on behaviour. October’s Cybersecurity Month is a timely prompt to review how these functions work together: check that policies are current and communicated, that onboarding and offboarding workflows are automated, that training is meaningful and role‑based, that screening is targeted, lawful and linked to access decisions, and that monitoring and incident response procedures protect both the organisation and its people.

When HR and IT collaborate effectively, organisations not only reduce risk but also build a culture where security is part of how work is done, not an extra burden imposed from the outside.